How it works
Three steps, no setup, and nothing installed on your systems.
How it works
-
Check your domain
Type in your company domain. Nothing to install, no account, no access to your systems needed.
-
Read what we found in plain English
Every finding says what we saw, why it matters, and what to look at. The exact settings are there too if you or your IT provider want them.
-
Keep watching it
Settings drift as your company adds tools and changes providers. Monitoring tells you when something important changes instead of you finding out later.
What actually happens when you run a check
Your domain publishes a set of public settings that any mail server on the internet can read. That is how email works. When a message arrives claiming to be from your company, the receiving server reads those settings to decide whether to believe it.
We read exactly the same public settings, in the same way a receiving mail server would, and compare them against the published rules that define how they are supposed to look. Then we explain what we found. We do not connect to your mail servers, we do not send test messages, and we do not need any access to your systems.
What we look at
| What it does | What it answers | Technical name |
|---|---|---|
| Sending identity | Which services are allowed to send email using your domain? | SPF |
| Message authenticity | Can receiving servers verify a message really came from your systems? | DKIM |
| Impersonation protection | What happens when someone sends email pretending to be your company? | DMARC |
| Mail routing | Where does email sent to your domain get delivered? | MX |
| Secure incoming delivery | Do you require other servers to use an encrypted connection when sending you mail? | MTA-STS |
| Delivery problem reports | Will you be told when another server fails to reach you securely? | TLS-RPT |
How to read the report
The top of the report says in one sentence how things look overall. Below that, each area gets its own card with a plain summary, anything that needs attention, and a technical details section you can open if you want the raw records.
Findings are sorted by how much they matter. A serious problem means a protection is not working at all rather than working weakly. A recommendation is something worth tidying up when convenient. Every finding links to the document that defines the rule, so you or your IT provider can check our reading of it rather than taking our word for it.
Then what?
Fix what needs fixing, either yourself or with whoever manages your DNS. We cannot make those changes for you and we never ask for access to do it. After that, the useful question is not whether the setup is right today but whether it will still be right in three months, which is what monitoring is for. Monitoring is not built yet, so for now the answer is to check again after any change to your email tools or DNS.