Free domain check

Can someone send email pretending to be you?

Ten seconds, nothing to install, no signup.

We only read public settings. Nothing touches your mailbox.

The state of things

How exposed are domains today?

Most companies have never told Gmail, Outlook and the rest what to do with a fake email in their name. That is not a rare oversight, it is the norm.

88.2%

chance that someone can send email in a random company's name right now

How well 1.4 million domains are protected
  • 11.8% Protected: fakes are refused
  • 20.3% Partly: fakes go to spam, or only some are stopped
  • 67.9% Not protected: fakes are delivered

37.9%

have never set up any protection at all

28.9%

set it up, then told it to do nothing

70.9%

of domains in the EU are not protected

15.0%

of German domains refuse fakes, third best in the EU

The share of protected domains grew by only 1.6 points in the last six months. At that pace, most stay open for years.

Source: email protection data across 1,414,314 domains, September 2026, updated daily by DmarcDkim.com.

Questions about email impersonation

Short answers to what people ask before they check their domain.

What is email impersonation?

Email impersonation is when someone sends an email that appears to come from you or your company, using your name or your domain in the sender address. The most common form is domain spoofing: the attacker puts your exact domain in the From field. It is the starting point for fake invoices, payroll changes and CEO fraud, because the recipient sees a sender they already trust.

How can someone send email from my domain?

Email was designed without sender verification, so any mail server can write any address in the From field. Unless your domain publishes SPF, DKIM and a DMARC policy that tells receivers to reject unauthenticated mail, Gmail, Outlook and other providers have no instruction to stop a forged message and deliver it as if it came from you.

What is the difference between domain spoofing and a lookalike domain?

Spoofing uses your real domain in the sender address and is stopped by a DMARC policy of quarantine or reject. A lookalike domain is a separately registered domain that resembles yours, such as a swapped letter or a different ending. DMARC does not cover lookalikes; those need monitoring and takedowns. This check tests whether your exact domain can be spoofed.

How do I check whether my domain can be impersonated?

Enter your domain in the checker above. It reads the three public DNS records every receiving mail system reads before trusting a message from you: SPF, DKIM and DMARC. Your domain is protected against spoofing when SPF and DKIM are set up and the DMARC policy is quarantine or reject. With p=none or no DMARC record at all, forged mail in your name is delivered.

Is my domain protected if I already have SPF?

No. SPF and DKIM only mark a message as passed or failed; they do not tell the receiver what to do with a failure. Only DMARC does that. A domain with SPF but no DMARC policy, or with DMARC set to p=none, can still be spoofed. Over 70% of domains are in that state.

Why do my legitimate emails land in spam?

Usually because one of your sending tools is not listed in your SPF record or does not sign with DKIM, so receivers cannot tell it from a forgery. Since 2024, Gmail and Yahoo require DMARC for bulk senders and filter mail that fails authentication. Covering every tool you send from is what moves your invoices and newsletters back into the inbox.

What are DMARC reports and why do they matter?

DMARC reports are delivery feedback that Gmail, Microsoft and other receivers send to the address in your DMARC record. They list which servers sent mail in your name and whether it passed authentication. They are the only way to see forgery attempts, and to find your own tools that fail before you switch to reject. Without a reporting address, rejections happen and nobody is told.

How long does it take to protect a domain against impersonation?

Publishing the records takes minutes. Reaching an enforced policy safely usually takes a few weeks: you collect reports, add every legitimate sender to SPF and DKIM, then move DMARC from none to quarantine to reject. Jumping straight to reject without that step blocks your own mail.

Does this check change anything on my domain or store my data?

No. The check performs public DNS lookups, the same ones any mail server does when it receives a message from you. Nothing is changed and nothing is installed. There is no signup; an email address is only asked for if you want the full report sent to you.