Find out who is sending email as your domain
A free check of SPF, DKIM, DMARC, BIMI and MTA-STS — and, once reports are flowing, a list of every source sending mail as you. No tenant access required.
What you get back
- Your posture, record by record — what SPF actually authorises, whether DKIM is signing, what your DMARC policy does today, and whether MTA-STS and BIMI are in play.
- Whether you can be spoofed right now, stated plainly rather than as a score.
Most domains sit at
p=none, which monitors and blocks nothing. - Every sender using your domain — from real DMARC aggregate reports once collection is running. Legitimate services you had forgotten about, and anyone else.
- A staged path to enforcement that will not drop the mail your business depends on, which is the actual reason most DMARC projects stall at monitoring.
The easiest one to start with
It needs no access to your tenant. Email authentication is published in public DNS, so the first pass costs you nothing but the domain name. The sender inventory needs a mailbox to receive DMARC reports — we will tell you exactly how to point them at it.
Why now
Major mailbox providers now require DMARC for bulk senders, inbox brand indicators require
enforcement, and business email compromise remains among the most expensive attacks in circulation.
Reaching p=reject is the proven defence; doing it without breaking legitimate mail is
the hard part, and it is what this is designed around.
If you want it continuously
That is MailTrust — across one domain or every domain your clients own, writing the DNS records itself for supported providers rather than handing you a ticket for another team.
Check my domain
Send the domain name. A person replies, usually the same working day.
If your mail client did not open
Some browsers and webmail setups cannot hand off to a mail app. Nothing is lost — copy the message below and send it to jeff@jeffops.com.
Request sent
It landed. You will get a reply from a person, usually the same working day.