Skip to content

Language

SuomiEnglish

Appearance

Email protection test

Enter a domain and see in a minute whether someone can send mail in your name and whether your own mail gets through. Free, no sign-in.

Test a domain

Advanced: DKIM selector

Common selectors are tried automatically. Enter a name only if the signature uses another one.

The test reads only the domain's public DNS records and sends no email. The tested domain, time and score are stored with us. The result stays cached for an hour; after changes, press Test again.

What does the test check?

Email protection is three public rules your domain tells receivers. The test reads them and says what they mean for you.

  • Receiving. Which service receives your mail, for example Microsoft 365 or Google Workspace. That is how the instructions can be written for your service in particular.
  • Allowed senders (SPF). States which services may send mail in your name. If your own email service is missing from the list, your own messages look like forgeries.
  • Signature (DKIM). Your messages get an electronic signature that shows the receiver the message was not altered in transit.
  • Handling of forgeries (DMARC). Tells receivers what to do with a message that claims to come from you but fails the checks: reject it, move it to spam or let it through.

Why does this matter?

A forged invoice or phishing message in your company's name hits your customers and partners. The same rules also decide whether your own messages reach the inbox or the spam folder. Microsoft and Google require these protections from senders, and gaps show directly in delivery.

What does the test not see?

The test reads only the domain's public DNS records. It sends no email and cannot see which folder your messages land in at the recipient. A signature is found only if its name is one of the common ones or your service's own. The test also does not know which other services send mail in your name, so the rules should not be tightened before those are reviewed.

What happens to the data?

The test makes the DNS queries from our own server in Cloudflare's EU network. The tested domain, time and score are stored with us so we can see which domains are tested. If you order the report by email, your address is used only to send the report, and a copy comes to us. The details are in the privacy notice.

Security moment

Well then. It said “don't press”, and you pressed anyway. 😉

No worries — curiosity is human. That's exactly what security attacks count on: the most tempting link is the one you're not supposed to open. While you're here, let's see whether you can tell a genuine message from a scam. You'll get four messages, and the clock is running.

Back to top