Email Security Check
Can Criminals Send Email as You?
Type your work email address or website to check the settings that stop criminals sending email that looks like it came from your business. Plain-English results in seconds, no sign-up.
- Instant result
- No sign-up
- Plain-English fixes

of cybercrime reports from businesses in 2024-25 were email compromise (ASD Annual Cyber Threat Report).
Check your email security in seconds
We read the public email settings for your business (SPF, DKIM and DMARC) and explain what they mean, and what to fix.
Instant resultNo sign-upPlain-English results
The check runs in your browser and reads your public email settings through Cloudflare's public lookup service (DNS), with Google's as a backup. Anyone can see these settings. SEQ IT doesn't see or store the address you check unless you send it to us.
This check reads public email settings only. It doesn't look inside your mailboxes, passwords or devices. Reviewed October 2026.
Three records that protect your name
Each one does a different job. You need all three working together.
Your approved senders list
A list of the services allowed to send email for your domain: Microsoft 365 or Google Workspace, plus things like your accounting software, website forms and newsletters.
A digital signature on every email
A digital signature added to every email you send, so the receiving server can check it really came from you and wasn’t changed on the way.
Rules for fake email
Tells receiving servers what to do with email that fails SPF and DKIM: deliver it, send it to junk or reject it. It also sends you reports on who is using your name.
Fake invoices start with a believable email
Email compromise was the most common cybercrime businesses reported to the ASD in 2024-25, at 19% of reports, and business email compromise fraud with a financial loss made up another 15%. The ASD puts the average self-reported cost of a cybercrime at $56,600 for a small business.
When a criminal can send email that really does come from your domain, your clients and suppliers have no reason to doubt it. A fake invoice or a “new bank details” request from your own address is far more convincing than one from a random account.
SPF, DKIM and DMARC close that door for your exact domain. They don’t stop lookalike domains, such as an extra letter or a different ending, or an attacker who has stolen a real password. That is why we pair them with phishing filtering, multi-factor authentication and staff training.
- Accounting and bookkeeping firms
- Law firms and conveyancers handling settlements
- Real estate agencies holding deposits
- Any business that sends invoices by email
Results not all green?
We can fix SPF, DKIM and DMARC without blocking your real email, and keep watching the reports afterwards.
What your results mean
Nothing tells other mail servers what to do with email pretending to be from you, and nobody sees reports.
Fake email is still delivered, but you get reports about it.
DMARC is set to quarantine or reject. This is where you want to be.
Other mail servers can’t check which services may send for you.
Any server is allowed, or the record gives no instruction.
Your email isn’t carrying a signature for your own domain.
From exposed to enforced, without losing real email
Jumping straight to reject can block your own invoices and newsletters. We get there in order.
Find every sender
We list every service that sends email as you, from Microsoft 365 or Google Workspace to accounting software, CRMs and website forms.
Fix SPF and DKIM
One clean SPF record, and DKIM signing switched on for every service that supports it.
Monitor with DMARC
DMARC starts at p=none with reporting, so we can see anything we missed before blocking it.
Move to reject
Once the reports are clean, we move to quarantine and then reject, and keep monitoring as part of your security service.
Email security: common questions
What is SPF, DKIM and DMARC?
They are three DNS records that protect your domain from being used in fake email. SPF lists the services allowed to send as you, DKIM adds a signature that proves an email is genuine, and DMARC tells receiving servers what to do with email that fails those checks.
Is DMARC p=none enough?
No. p=none only collects reports, so email pretending to be from you is still delivered. It is the right place to start while you find all your real senders, but the goal is p=quarantine and then p=reject.
Will DMARC stop all phishing?
No. It stops criminals sending email from your exact domain. It doesn’t stop lookalike domains or attackers using a stolen password. Phishing filtering, multi-factor authentication and staff training cover those.
Do Microsoft 365 and Google Workspace set this up for us?
Not fully. Both ask you to add an SPF record when your domain is set up, but DKIM signing for your own domain has to be switched on, and DMARC has to be added and tuned by whoever manages your DNS.
Is the check safe? What happens to my domain?
The check only reads public DNS records, the same information any mail server sees. It runs in your browser through Cloudflare’s public DNS service, with Google’s as a backup. We don’t see or store the domain unless you send it to us.
Why does the check say DKIM was not checked?
DKIM records sit under a name chosen by your email provider, called a selector. We check the ones Microsoft 365 and Google Workspace use. If your email runs through another provider, ask us and we’ll check it properly.
Can fixing DMARC break our email?
It can if you move to reject before every real sender is set up, which is why we start with reporting and move in stages. Done in order, your genuine email keeps flowing while fakes are blocked.
More ways to protect your email
Cyber security services
Phishing filtering, sign-in monitoring and EDR, managed for you.
Microsoft 365 support
Secure setup and support for Microsoft 365.
Google Workspace support
Secure setup and support for Google Workspace.
Accounting and finance IT
Protection for firms that send invoices and handle payments.
Free cyber security assessment
Your email, accounts, devices and backups checked.
Stop criminals sending email as you
Send us your result, or just your domain. We’ll check your email security properly and tell you what it takes to fix it.
- SPF, DKIM and DMARC set up in the right order
- Your genuine email keeps flowing
- Ongoing monitoring of the DMARC reports
Prefer to talk? Call 1300 619 750, Monday to Friday.
If you used the check, your result is already in the message box. We’ll get back to you within one business day.
