Email security
Authentication, visibility, and drift control for your domain.
Most breaches start with email. We give SMB teams the same visibility Fortune 500 security teams pay six figures for — no operator required.
Start here
One scan, eight checks, three resolvers — no account.
Email security scan
FreeSPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI, and DNSSEC across three resolvers in about 15 seconds. PDF report on request.
Open tool →Email authentication
Build, validate, and harden the four DNS records that decide whether mailbox providers trust your sender domain.
SPF record builder
FreePick the services you send from. We assemble the TXT record and count DNS lookups so you don't blow the RFC-7208 10-lookup limit.
Open tool →SPF lookup analyzer
FreeAlready have an SPF record? We resolve the whole include/redirect tree and count the real number of DNS lookups — the one that breaks mail when it crosses 10.
Open tool →DMARC record generator
FreeBuild a v=DMARC1 record with the right policy and reporting address, plus a guided rollout from monitor (p=none) to full enforcement (p=reject).
Open tool →DMARC record validator
FreePaste your DMARC TXT record. Per-tag grading + plain-English fixes. No DNS lookup — bring your own record.
Open tool →DMARC report analyzer
FreePaste a daily aggregate (rua=) XML report. Get a per-source breakdown, alignment rate, and a verdict on whether it's safe to move to p=quarantine or p=reject. Runs in your browser.
Open tool →DKIM record validator
FreePaste your DKIM TXT record. Tag-by-tag grading, key-size estimate, and revocation detection. No DNS lookup — bring your own record.
Open tool →Email header analyzer
FreeGot a suspicious email? Paste its raw headers to trace every server it passed through, read the SPF/DKIM/DMARC verdicts, and surface spoofing tells. Runs in your browser — nothing uploaded.
Open tool →Blocklist (DNSBL) checker
FreeEmails landing in spam? Enter your domain; we resolve its mail IPs and query Spamhaus, SpamCop, SORBS, URIBL and more. Honest three-state results — listed, not-listed, or 'could not check' (never a false all-clear).
Open tool →DMARC visibility
PaidIngest aggregate reports from your rua= mailbox. Per-source alignment, untrusted-sender flags, guided path from p=none → p=reject.
Open tool →BIMI check
FreeResolve your BIMI DNS record, fetch the SVG, and flag Gmail-blocking issues: size, content-type, missing VMC, DMARC enforcement.
Open tool →Transport security
MTA-STS and TLS-RPT — the records that tell sending MTAs to enforce TLS for your domain and to report failures back to you.
MTA-STS policy builder
FreePick your MX hosts and a mode (enforce / testing / none). Emits the policy file you host at mta-sts.<domain>/.well-known/mta-sts.txt plus the DNS TXT record.
Open tool →TLS-RPT builder + validator
FreeSubscribe to daily TLS/MTA-STS/DANE failure reports from sending MTAs. Two tabs: build a fresh TXT record, or paste one for tag-by-tag grading.
Open tool →Operations
Always-on monitoring once you've cleaned your records up.
Continuous monitoring
PaidDaily (Starter) or 6-hour (Pro) rescans with field-level drift detection. Email, Slack, and webhook alerts the moment anything changes.
Open tool →