Free 60-second check

Does your domain stop fake invoices?

Criminals can imitate your company’s visible sender address. Check whether SPF and DMARC detect and reject that spoofing—with a clear next step instead of DNS jargon.

Instant resultPDF auditNo loginNo storage
Spoofing risk60 SEC.
You receiveDeep SPF/DMARC audit + 3 next steps + PDF

Public DNS data only. Your browser queries Cloudflare directly; MX Audit never receives or stores your domain.

01 Enter domain02 Find the gap03 Understand priority04 Fix it safely
What you know after 60 seconds

No traffic light without an answer.

A score alone is worthless. MX Audit identifies the business-relevant gap and turns it into a safe sequence for Microsoft 365, Google Workspace, or your detected provider.

02

Concrete plan

Three prioritised steps

You get a safe sequence—not a generic DNS record: monitor, verify real senders, then enforce protection in controlled steps.

03

No trust required

0 stored scans

No login, email address, or analytics cookies. The DNS lookup runs directly in your browser.

Check my domain now
Practical guides

From DNS signal to safe implementation.

Build a current DMARC record, verify a real message header, simulate enforcement impact locally, then use six concise implementation guides for Microsoft 365, Google Workspace, or any provider.

New · MSP preflight

Need to compare several client domains?

Audit up to 10 domains privately, rank the remediation queue, and export one client-ready CSV.

Check portfolio
New · RFC 9989 tool

Need the exact DMARC DNS record?

Build a safe staged policy with reporting, external-address checks, and no obsolete pct tag—locally and without signup.

Build record
New · Free tool

Did a real message pass DKIM and DMARC?

Paste the receiver's full header and read SPF, DKIM, DMARC, signing domains, and selector locally—without uploading the message.

Analyze header
Free report tool

What would p=reject affect today?

Analyze XML, GZIP, or ZIP aggregate reports locally and find sending sources that still fail DMARC alignment before changing DNS.

Simulate impact

The business damage starts before the inbox

Customers check the logo. Mail servers check SPF, DKIM, and DMARC.

An attacker does not need to compromise your mailbox to make a message look like company email. Weak sender policies make it easier to abuse your domain for phishing and fraudulent payment requests.

Switzerland’s National Cyber Security Centre recorded 6,299 phishing reports in the second half of 2025—17% more than a year earlier. Gmail also requires authentication, including DMARC for bulk senders.

Quick answers
Does this check cost CHF 50?

No. The domain check and prioritised three-step plan are free. An external monitoring platform only becomes useful when you continuously analyse DMARC reports and tighten protection.

Is this a penetration test?

No. The check reads publicly available DNS records only. It never accesses mailboxes, servers, or accounts.

Can it fully check DKIM?

Not without a known selector or sample message. DKIM therefore does not affect the automatic score.

Is my domain stored?

No. Your browser queries Cloudflare’s DNS resolver directly. MX Audit receives neither the domain nor the result and stores no scans.

Does MX Audit earn from the external link?

Not currently. The link goes to DMARCTrust without compensation. Any future partner link will be clearly disclosed beside it.