Free SPF and DMARC Checker: Can Someone Spoof Your Email?
SPF, DKIM and DMARC are the three DNS records that decide whether a stranger can send email that looks like it came from your domain. BadgerScan reads all three as part of one free external scan and tells you, in plain English, whether your domain is protected or wide open.
One free scan, no login. This check runs alongside DNS, email, TLS, headers, exposed files and known CVEs.
What this SPF and DMARC checker checks, and why it matters
Email was never designed with built-in proof of who sent it. By default, anyone can put your domain in the From address and send a message that looks like it came from you. SPF, DKIM and DMARC are the three records that close that gap, and our SPF and DMARC checker reads all three so you can see where you stand.
SPF (Sender Policy Framework) is a DNS record that lists which mail servers are allowed to send email for your domain. DKIM (DomainKeys Identified Mail) adds a cryptographic signature so a receiving server can confirm the message was not tampered with and really came from your domain. DMARC ties the two together: it tells receiving servers what to do when a message fails those checks, and it can send you reports about who is sending mail using your name (Cloudflare, What are DMARC, DKIM, and SPF?).
When these records are missing or weak, criminals can spoof your domain to phish your customers, impersonate your team in invoice-fraud scams, or slip past spam filters. This matters most for small businesses, which are disproportionately targeted: in Verizon's 2025 DBIR, ransomware or extortion appeared in 88% of breaches at small and medium businesses, versus 39% at larger organizations (Verizon 2025 DBIR), and a spoofable domain is a common first step in those attacks.
How BadgerScan checks it
This is not a separate tool you run on its own. Email authentication is one part of the single free BadgerScan external scan. When you enter your domain, the scanner does a passive, read-only lookup of your public DNS, the same view any mail server on the internet already has, and pulls back your SPF, DKIM and DMARC records alongside your DNS, TLS certificate, HTTP security headers, exposed files and known CVEs.
For SPF, we read your TXT record and check that it exists, that there is only one, and that it ends in a sensible policy. For DMARC, we look up the record at _dmarc.yourdomain and read the policy you have published. For DKIM, we check for a published signing key on the selectors we can see. We never send test emails, log in to anything, or touch your mail server. It is all read from public records.
Everything lands in one combined report with one plain-English grade and one deduplicated fix-list, so email security sits right next to the rest of your site's exposure instead of in a silo. You can run the free scan now and have your email authentication results in under a minute.
How to read your result
The most important line is your DMARC policy, shown as the p= value. There are three possible settings and they mean very different things:
p=reject is the strong, protective setting: receiving servers are told to throw away any message that fails SPF and DKIM, so spoofed mail does not reach the inbox. p=quarantine is a middle setting that sends failing mail to spam. p=none is monitoring only: it collects reports but tells servers to deliver spoofed mail anyway, so it provides almost no real protection. Many domains sit at p=none for years thinking they are covered when they are not.
If you see no DMARC record at all, your domain has no published policy and is the easiest kind to spoof. A missing or broken SPF record is the same story: without it, receiving servers have no list of approved senders to check against. BadgerScan flags each of these clearly, tells you which state you are in, and rolls the result into your overall grade so you can see how much it is dragging you down.
Common fixes
Most email-authentication problems are fixed by publishing or correcting a few DNS records. Work through these in order:
- Publish an SPF record if you have none. Add a single TXT record that lists every service that sends mail for you (your mail host, marketing platform, CRM, helpdesk) and ends in -all to hard-fail everything else.
- Keep it to one SPF record. Multiple SPF TXT records break SPF entirely. Merge them into a single line.
- Turn on DKIM in your mail provider. Most hosts (Google Workspace, Microsoft 365, and others) generate a signing key and give you a DNS record to publish. Enable it and add the record.
- Publish a DMARC record, then tighten it. Start at p=none with a reporting address to see who is sending as you, then move to p=quarantine and finally p=reject once your legitimate mail is passing.
- Re-scan after each change. DNS can take a little time to propagate. Run the scan again to confirm the records read correctly and your grade improves.
- If invoice fraud or domain impersonation would seriously hurt your business, our team can set this up end to end. See CyberBadger's security services at https://cyberbadger.ca/services/#cybersecurity.
See if your domain can be spoofed
Run the free BadgerScan scan and get your SPF, DKIM and DMARC results, plus your full external security grade, in under a minute. No login, no test emails, just a plain-English read of what attackers can already see.
Run a free security scanFrequently asked questions
What is the difference between SPF, DKIM and DMARC?
SPF lists which servers are allowed to send mail for your domain. DKIM adds a cryptographic signature that proves a message was not altered and came from you. DMARC ties them together and tells receiving servers what to do when a message fails, plus it can send you reports (Cloudflare, What are DMARC, DKIM, and SPF?). You generally want all three.
Is p=none good enough?
No. A DMARC policy of p=none is monitoring only. It collects reports but still tells receiving servers to deliver spoofed mail, so it offers almost no protection. It is a useful first step while you confirm your legitimate senders, but the goal is to move to p=quarantine and then p=reject.
Does the SPF and DMARC checker send test emails or log in to my mail server?
No. The SPF, DKIM and DMARC checks are entirely passive. BadgerScan reads your public DNS records, exactly the view any mail server on the internet already has. It never sends mail, never logs in, and never does active or penetration testing.
Is the email security check separate from the rest of the scan?
No. It is part of the one free BadgerScan external scan. Email authentication is checked alongside DNS, your TLS certificate, HTTP security headers, exposed files and known CVEs, and everything is combined into a single grade and fix-list.
Sources
Related
More from CyberBadger
BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.
Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.