Free tool · Email security

Email Security Check
Can Criminals Send Email as You?

Type your work email address or website to check the settings that stop criminals sending email that looks like it came from your business. Plain-English results in seconds, no sign-up.

  • Instant result
  • No sign-up
  • Plain-English fixes
SEQ IT helpdesk technician on a support call
19%

of cybercrime reports from businesses in 2024-25 were email compromise (ASD Annual Cyber Threat Report).

The check

Check your email security in seconds

We read the public email settings for your business (SPF, DKIM and DMARC) and explain what they mean, and what to fix.

What we check

Three records that protect your name

Each one does a different job. You need all three working together.

SPF

Your approved senders list

A list of the services allowed to send email for your domain: Microsoft 365 or Google Workspace, plus things like your accounting software, website forms and newsletters.

DKIM

A digital signature on every email

A digital signature added to every email you send, so the receiving server can check it really came from you and wasn’t changed on the way.

DMARC

Rules for fake email

Tells receiving servers what to do with email that fails SPF and DKIM: deliver it, send it to junk or reject it. It also sends you reports on who is using your name.

Why it matters

Fake invoices start with a believable email

Email compromise was the most common cybercrime businesses reported to the ASD in 2024-25, at 19% of reports, and business email compromise fraud with a financial loss made up another 15%. The ASD puts the average self-reported cost of a cybercrime at $56,600 for a small business.

When a criminal can send email that really does come from your domain, your clients and suppliers have no reason to doubt it. A fake invoice or a “new bank details” request from your own address is far more convincing than one from a random account.

SPF, DKIM and DMARC close that door for your exact domain. They don’t stop lookalike domains, such as an extra letter or a different ending, or an attacker who has stolen a real password. That is why we pair them with phishing filtering, multi-factor authentication and staff training.

Who is most at risk
  • Accounting and bookkeeping firms
  • Law firms and conveyancers handling settlements
  • Real estate agencies holding deposits
  • Any business that sends invoices by email

Results not all green?

We can fix SPF, DKIM and DMARC without blocking your real email, and keep watching the reports afterwards.

Reading your results

What your results mean

Result
What it means
What to do
No rules for fake email (no DMARC)

Nothing tells other mail servers what to do with email pretending to be from you, and nobody sees reports.

Add DMARC with reporting
Watching, but not blocking (DMARC p=none)

Fake email is still delivered, but you get reports about it.

Move to junk, then reject
Fake email goes to junk or is blocked

DMARC is set to quarantine or reject. This is where you want to be.

Keep watching the reports
No approved senders list, or two of them (SPF)

Other mail servers can’t check which services may send for you.

Publish one complete SPF record
The list lets anyone send, or says nothing (+all or ?all)

Any server is allowed, or the record gives no instruction.

End with ~all or -all
No email signature found (DKIM)

Your email isn’t carrying a signature for your own domain.

Turn DKIM on in Microsoft 365 or Google Workspace
How we fix it

From exposed to enforced, without losing real email

Jumping straight to reject can block your own invoices and newsletters. We get there in order.

01
Discover

Find every sender

We list every service that sends email as you, from Microsoft 365 or Google Workspace to accounting software, CRMs and website forms.

02
Set up

Fix SPF and DKIM

One clean SPF record, and DKIM signing switched on for every service that supports it.

03
Watch

Monitor with DMARC

DMARC starts at p=none with reporting, so we can see anything we missed before blocking it.

04
Enforce

Move to reject

Once the reports are clean, we move to quarantine and then reject, and keep monitoring as part of your security service.

FAQ

Email security: common questions

They are three DNS records that protect your domain from being used in fake email. SPF lists the services allowed to send as you, DKIM adds a signature that proves an email is genuine, and DMARC tells receiving servers what to do with email that fails those checks.

No. p=none only collects reports, so email pretending to be from you is still delivered. It is the right place to start while you find all your real senders, but the goal is p=quarantine and then p=reject.

No. It stops criminals sending email from your exact domain. It doesn’t stop lookalike domains or attackers using a stolen password. Phishing filtering, multi-factor authentication and staff training cover those.

Not fully. Both ask you to add an SPF record when your domain is set up, but DKIM signing for your own domain has to be switched on, and DMARC has to be added and tuned by whoever manages your DNS.

The check only reads public DNS records, the same information any mail server sees. It runs in your browser through Cloudflare’s public DNS service, with Google’s as a backup. We don’t see or store the domain unless you send it to us.

DKIM records sit under a name chosen by your email provider, called a selector. We check the ones Microsoft 365 and Google Workspace use. If your email runs through another provider, ask us and we’ll check it properly.

It can if you move to reject before every real sender is set up, which is why we start with reporting and move in stages. Done in order, your genuine email keeps flowing while fakes are blocked.

Get started

Stop criminals sending email as you

Send us your result, or just your domain. We’ll check your email security properly and tell you what it takes to fix it.

  • SPF, DKIM and DMARC set up in the right order
  • Your genuine email keeps flowing
  • Ongoing monitoring of the DMARC reports

Prefer to talk? Call 1300 619 750, Monday to Friday.

Request your free assessment

If you used the check, your result is already in the message box. We’ll get back to you within one business day.