grc-scan
← Back to homeFree · no sign-up

Can criminals send email pretending to be you?

Enter your domain to check the email-authentication records (SPF, DMARC, DKIM) that decide whether someone can forge messages from your address — a common first step in invoice fraud and phishing. You'll get a plain-English traffic-light verdict and exactly what to fix. It only reads public DNS records; nothing is sent or stored.

Look after clients' domains?

Run this for every client you support — spoofable domains are a common, avoidable risk that leads to fake-invoice fraud. When you want the fuller picture for a domain, the free posture scan grades headers, HTTPS and reputation too.

This tool reads public DNS records (SPF, DMARC, DKIM, BIMI) and is for awareness purposes only. DKIM is probed at common selectors, so a “not found” result isn't proof it's absent. Always confirm changes with your email provider before and after editing DNS.