Clear risk question
Will spoofing be rejected?
SPF and DMARC are not presented as jargon. You see whether unauthorised senders are merely monitored or actively blocked.
Free 60-second check
Criminals can imitate your company’s visible sender address. Check whether SPF and DMARC detect and reject that spoofing—with a clear next step instead of DNS jargon.
A score alone is worthless. MX Audit identifies the business-relevant gap and turns it into a safe sequence for Microsoft 365, Google Workspace, or your detected provider.
Clear risk question
SPF and DMARC are not presented as jargon. You see whether unauthorised senders are merely monitored or actively blocked.
Concrete plan
You get a safe sequence—not a generic DNS record: monitor, verify real senders, then enforce protection in controlled steps.
No trust required
No login, email address, or analytics cookies. The DNS lookup runs directly in your browser.
Build a current DMARC record, verify a real message header, simulate enforcement impact locally, then use six concise implementation guides for Microsoft 365, Google Workspace, or any provider.
Audit up to 10 domains privately, rank the remediation queue, and export one client-ready CSV.
Build a safe staged policy with reporting, external-address checks, and no obsolete pct tag—locally and without signup.
Paste the receiver's full header and read SPF, DKIM, DMARC, signing domains, and selector locally—without uploading the message.
Analyze XML, GZIP, or ZIP aggregate reports locally and find sending sources that still fail DMARC alignment before changing DNS.
Inventory senders, monitor reports, and move from observation to enforcement in controlled steps.
Step by step →02 · AnalysisRead aggregate reports, identify legitimate sources, and prioritise real authentication failures.
Report fields explained →03 · TroubleshootingAvoid multiple records, forgotten senders, and the hard limit of ten DNS lookups.
SPF checklist →The business damage starts before the inbox
An attacker does not need to compromise your mailbox to make a message look like company email. Weak sender policies make it easier to abuse your domain for phishing and fraudulent payment requests.
Switzerland’s National Cyber Security Centre recorded 6,299 phishing reports in the second half of 2025—17% more than a year earlier. Gmail also requires authentication, including DMARC for bulk senders.
No. The domain check and prioritised three-step plan are free. An external monitoring platform only becomes useful when you continuously analyse DMARC reports and tighten protection.
No. The check reads publicly available DNS records only. It never accesses mailboxes, servers, or accounts.
Not without a known selector or sample message. DKIM therefore does not affect the automatic score.
No. Your browser queries Cloudflare’s DNS resolver directly. MX Audit receives neither the domain nor the result and stores no scans.
Not currently. The link goes to DMARCTrust without compensation. Any future partner link will be clearly disclosed beside it.