Free email security check
Can someone send email pretending to be you?
Enter your domain. In a few seconds you will see whether your email is protected from being faked, graded A to F, plus any lookalike domains someone could use to fool your clients. It checks SPF, DKIM and DMARC. No email needed.
Reading your public DNS records
Reads public DNS records only, the same ones every mail server reads. Nothing is changed and nothing is stored.
Example result
- DMARCMonitoring only
- SPFIn place
- DKIMNot switched on
- MTA-STS and TLS reportsNot set
- Lookalike domains3 registered
01Your result
Get the fix list
The exact DNS records to add or change, in the order to do them, written so whoever manages your domain can copy them in. Plus every lookalike domain we found.
Send me the fix list
It appears on this page as soon as you send the form. Your result comes to us too, so a technical consultant can talk it through if you want.
The form did not load. A browser extension may be blocking it. Email sales@austintechnology.com.au or call 1300 787 429.
Your fix list is below
Thanks. Save it as a PDF from the print button, or send the page link to whoever manages your DNS.
Your fix list
02How the grade works
Six settings, weighted by what stops a fake
Each is a public DNS record. Together they decide whether an email claiming to be from you gets delivered, sent to junk or refused.
DMARC40 points
The setting that tells other mail servers what to do with email that fails the checks: deliver it, send it to junk, or refuse it. Most of the grade, because it is what actually stops a fake.
SPF25 points
The list of servers allowed to send email as your domain. It breaks if it needs more than 10 DNS lookups, which happens as businesses add services.
DKIM20 points
A signature on every email you send, so the receiver can tell it came from you and was not changed on the way.
MTA-STS5 points
Makes email sent to you travel over an encrypted connection, so it cannot be read or redirected in transit.
TLS reports5 points
Daily reports from other mail providers about any encryption problems delivering to you.
DNSSEC5 points
Signs your DNS records, so the answers about where your email goes cannot be forged.
Grades: A 90 and over, B 75 to 89, C 55 to 74, D 35 to 54, F under 35. A domain that sends and receives no email only needs SPF and DMARC set to block everything.
03Why it matters
Email is where most business fraud starts
A fake invoice or a change of bank details from a name your client trusts is the most common way Australian businesses lose money to cybercrime. If your domain has no DMARC policy, a scammer does not need to break into anything to send that email as you.
The fix is mostly DNS settings your IT provider can change in an afternoon, then a few weeks of watching reports before you move to the strictest setting.
- 34%of cybercrime reports from Australian businesses in 2024 to 2025 were email compromise, with or without a financial loss.
- $56,600average self-reported cost per cybercrime report for a small business, up 14%.
- 72%of 15,665 Australian domains monitored had no effective DMARC protection in November 2025.
Sources: ASD Annual Cyber Threat Report 2024 to 2025; DmarcDkim.com, Australia, November 2025.
04Questions
About the email check
What people ask before and after running it. Anything else, call 1300 787 429.
01What does the email security check look at?
It reads the public DNS records that control email for your domain: SPF, DKIM, DMARC, MTA-STS, TLS reporting and DNSSEC, and works out your email platform from your MX records. Then it checks which names that look like yours are registered and can receive email.
02Is it safe to run on our domain?
Yes. It only reads records that every mail server in the world reads when you send it an email. It does not log in to anything, send email or change any setting.
03What happens to the domain I enter?
We look it up in public DNS through Cloudflare's resolver and keep the result for 15 minutes so a repeat check is quick. We keep no record of who checked what. If you ask for the fix list, the domain and the result come to us with your details through the form, so a technical consultant can help if you want.
04Why does it say DKIM was not found when we have it?
DKIM keys sit under a name the email provider chooses, and there is no way to list them. We try the names Microsoft 365, Google Workspace and the common sending services use. If your provider uses another name, the check cannot see it, which is why it shows an amber Not found.
05What is a lookalike domain and should we buy them?
A lookalike is a name one letter or one ending away from yours, such as a swapped letter or .com instead of .com.au. Scammers register them to send fake invoices that look like they came from you or a supplier. You cannot buy them all. The useful steps are to confirm bank detail changes by phone, register the closest .com.au and .au versions, and watch for new ones.
06If we get an A, are we safe from email scams?
An A means nobody can send email that passes as your exact domain. It does not stop email from lookalike domains, a supplier whose mailbox has been taken over, or a staff member whose password is stolen. Those need filtering, MFA and staff who know what to look for, which is what our email security service covers.
07How long does fixing it take?
Most fixes are DNS changes that take under an hour. Moving DMARC to reject takes a few weeks, because you watch the reports first to make sure none of your own services, such as your accounting software or website forms, get blocked.
Related services and tools
05Next step
Want it fixed for you?
Our team sets up SPF, DKIM and DMARC, watches the reports and moves you to reject without blocking your own email. It is part of our email security service.