Can someone send email as you?
Enter your work email. We'll inspect the domain's public SPF and DMARC records and show whether receiving mail systems are told to block impersonation.
- No test email is sent
- No password or mailbox access needed
- Your address is not stored by this checker
SPF
Allowed senders
DMARC
Domain alignment
Policy
Receiver action
What the result actually tells you
Anyone can type a different From address. The important question is whether receiving systems can verify that message and are instructed to block it when verification fails.
SPF
Publishes which servers may send for your domain. We inspect the record's shape; a full SPF result needs a real sending IP and evaluation of include and redirect chains.
DMARC
Requires the authenticated SPF or DKIM identity to align with the domain people see, then publishes a handling policy for failures.
Enforcement
A p=none policy only monitors. Quarantine moves failures toward spam. Reject is the strongest published instruction once legitimate senders are aligned.
Common questions
Does this tool send a spoofed email?
No. It reads the public DNS records for the domain after the @ in your email address. It does not send mail, open your mailbox, or ask for a password.
What does it mean if my email can be spoofed?
It means someone can forge your domain in the visible From address and your published policy may not tell receiving systems to reject it. Whether an individual message lands still depends on the receiving provider.
Are SPF and DMARC enough to secure business email?
They are important controls, but not the whole system. Strong protection also depends on DKIM alignment, accurate sender inventory, mailbox security, monitoring, and correct configuration of every service that sends for your domain.
Can I change DMARC straight to reject?
Not safely in every case. First identify legitimate senders and validate SPF or DKIM alignment. Reject can also disrupt forwarding and mailing lists, so general-purpose email domains should choose enforcement based on monitored traffic rather than treating reject as an automatic end goal.
This is a configuration check, not a penetration test or guarantee. If email delivery is business-critical, review changes with the people who manage your mail platform.