Мазмұнға өту
24/7 жедел ден қою желісі
kk
Қызметтер
Шешімдер
Зерттеулер
Компания
ҚұралдарTrust Center

Email Security Analyzer

Spoofed email is the most common route for phishing and invoice fraud. With SPF, DKIM and DMARC set up correctly, attackers largely lose the ability to send mail that appears to come from your domain.

Бұл мазмұн қазір тек ағылшын тілінде қолжетімді.

Queries are not stored. The tools use public information only; client-side tools never send your data anywhere.

What this tool checks

  • MX records and null MX
  • SPF record, default rule (-all/~all) and the 10-lookup limit
  • DMARC policy (none/quarantine/reject), coverage and reporting
  • DKIM key under common selectors
  • MTA-STS, TLS-RPT and BIMI

How to use it

  1. 01

    Enter the domain from your email address (example.com for [email protected]).

  2. 02

    Press Analyze.

  3. 03

    Fix the red rows first; the DMARC policy and SPF default rule usually make the biggest difference.

Technical details

SPF lookup limit

RFC 7208 allows at most 10 DNS lookups while evaluating SPF. The tool follows include and redirect chains like a real receiver and counts the total.

Moving to DMARC enforcement safely

Start with p=none and watch the rua reports; once every legitimate sending source aligns with SPF or DKIM, move to quarantine and then reject.

DKIM and selectors

DKIM keys are published under a selector name and can't be listed. The tool tries the selectors of common providers; not finding one doesn't prove DKIM is missing.

Frequently asked questions

Is DMARC p=none enough?

No. p=none only reports; spoofed mail is still delivered. Once your reports are clean, move to quarantine or reject.

Should I use ~all or -all?

With DMARC enforced, ~all is a common and safe choice. Without DMARC, -all sends a clearer signal. Either way, make sure every sending service is included in SPF.

What about domains that never send email?

Publish an SPF record of “v=spf1 -all”, a DMARC policy of “p=reject” and a null MX record. Then the domain can't be used for spoofing.

I use Google Workspace or Microsoft 365 — do I need anything else?

Yes. Add the provider's SPF include, enable DKIM in the admin console and create the DMARC record yourself; these are not fully configured by default.