See your domain's security posture in seconds
A free, instant scan covering email authentication, blacklist status, SSL, DNS security, and browser-facing headers — with a downloadable PDF report.
11 checks, one report
No signup. No email required. Results and a PDF report in seconds.
MX Records
Confirms your domain can actually receive mail, with failover.
SPF
Stops attackers sending phishing mail that looks like it's from you.
DKIM
Cryptographically proves your outgoing mail wasn't tampered with.
DMARC
Tells mail servers what to do with spoofed mail, and reports abuse back to you.
BIMI
Shows your verified logo next to your email in supporting inboxes.
Blacklist
Checks if your mail servers are already flagged as spam sources.
MTA-STS
Forces inbound mail over an encrypted, verified connection.
TLSRPT
Surfaces TLS delivery failures you'd otherwise never see.
DNSSEC
Stops DNS spoofing and cache-poisoning attacks.
SSL/TLS
Confirms your certificate is valid and not about to expire.
Security Headers
Checks browser-enforced protections against clickjacking and injection.
How it works
-
1
Enter your domain
No signup, no email address needed.
-
2
We run 11 checks
Email authentication, blacklist status, SSL, DNS security, and headers — all in a few seconds.
-
3
Get your results
See what's working, what's not, and download a PDF report to share or keep on file.
Why this matters
Since 2024, Google and Yahoo have required SPF, DKIM, and DMARC for anyone sending bulk email — even from a personal or small business domain. Most businesses don't find out they're non-compliant until mail starts silently disappearing into spam folders, or someone spoofs their domain to send phishing email under their name.