MX AuditGuides

Evidence-first email spoofing review

Can attackers send convincing email from your business domain?

An email spoofing audit checks whether SPF, DKIM and DMARC authorize the right senders, align with the visible From domain, and tell receivers what to do with failures. It also separates exact-domain spoofing from lookalike domains, display-name abuse and compromised accounts.

Reviewed: August 10, 2026 · Primary sources below

01

Authorise the domain and inventory legitimate senders

Start with one business domain you own or are authorised to assess. List the primary mailbox platform plus website forms, invoicing tools, CRM, newsletters and every other service that sends with the domain in the visible From address.

02

Evaluate SPF instead of checking only for a TXT record

Confirm there is one SPF policy, trace its include chain, count DNS-triggering lookups and identify every service it authorises. A present record can still fail because of syntax, excessive lookups, an invalid include or an omitted sender.

03

Verify DKIM on representative real messages

Public DNS cannot enumerate unknown DKIM selectors. Use sanitized headers from messages delivered through each legitimate service to confirm the signing domain, selector, signature result and whether the signing domain aligns with the visible From domain.

04

Check DMARC policy, alignment and reporting

Inspect the policy published at _dmarc, then verify whether legitimate messages pass through aligned SPF or aligned DKIM. Aggregate reports help reveal forgotten senders and unauthorized use before enforcement is tightened.

05

Validate failures without sending abuse to third parties

Use owned test mailboxes, sanitized received-message headers and authorized diagnostic tools. Do not send deceptive messages to employees, customers or unrelated recipients. The goal is to verify authentication behavior, not imitate a real phishing campaign.

06

Separate exact-domain spoofing from other impersonation

DMARC addresses unauthorized use of the exact visible From domain. It does not stop lookalike registrations, misleading display names, compromised legitimate accounts or malicious content sent from an authenticated domain. Record those as separate risks.

07

Apply changes through the normal administrator

Produce exact provider-specific SPF, DKIM and DMARC changes, explain the risk of each change, and let the domain administrator apply them. Recheck public DNS and representative headers after propagation before considering the work complete.

Fixed scope · USD 99 founding price

Turn the audit into exact changes for one domain.

The Email Authentication Fix Sprint covers one authorised business domain outside Switzerland, up to three legitimate sending services, exact buyer-applied SPF, DKIM and DMARC changes, one post-change verification and one correction round. No credentials and no inbox-placement guarantee.

See the Fix Sprint

Important

A DMARC pass is not a safety verdict, and an audit cannot guarantee inbox placement.

DMARC validates authorized use of a domain; it does not judge links, attachments, display names or account compromise. Receivers also combine authentication with reputation, content, volume and engagement signals. Treat authentication as one security control and never promise that a technically valid message will reach the inbox.

If you need continuous monitoring

See who really sends in your name.

DMARCTrust is an external platform for DMARC reports, alerts, and sender inventory. Its free evaluation tier is limited to one domain; paid business plans start at $19/month for two domains. The MX Audit score remains independent.

Business plans from $19/mo · free evaluation · no cardTest monitoring free Not a partner link yet: MX Audit currently receives no compensation.
Common questions
Does p=none stop someone from spoofing my domain?

No handling preference is requested by p=none. Receivers can still evaluate DMARC and send reports, but the domain owner is not asking them to quarantine or reject messages that fail validation.

Does DMARC pass mean an email is safe?

No. It means the visible From domain was used with aligned SPF or DKIM. An authenticated account or sending service can still distribute malicious or unwanted content.

Can public DNS prove that DKIM works?

Not by itself. A checker needs a known selector to query a DKIM key, and the decisive evidence is a valid signature on a representative delivered message whose signing domain aligns with the visible From domain.

What does the USD 99 Fix Sprint include?

One authorised business domain, up to three legitimate sending services, exact provider-specific SPF, DKIM and DMARC changes for the buyer to apply, one DNS and sanitized-header verification, and one correction round. It excludes mailbox administration, migrations, warm-up and inbox-placement guarantees.

Primary sources