Skip to content
Solvex Space

Cybersecurity · free, no signup

SPF/DKIM/DMARC Spoof Checker

Read the public SPF, DKIM and DMARC records for a domain you own and find out whether attackers could impersonate it — sending spoofed or fake emails that appear to come from your company — with guidance to close every gap.

Authorized, defensive use only. Check assets you own or lawfully public data. This tool is educational and never provides another party's private data.

Reads the public SPF, DMARC and DKIM records for a domain and reports whether a receiver is actually instructed to reject forged mail. Only public DNS is read — nothing is sent to the domain, and no mail is generated.

A domain you own, manage or are authorized to assess.

DKIM selectors cannot be discovered from DNS. Common ones are always tried; add yours to check them too.

What happens to what you enter

  • The analysis runs on Solvex servers. What is recorded afterwards is a SHA-256 hash of your input and a coarse summary of the outcome — never the input itself, and never a result you could be identified from.
  • Tools that read public sources (certificate logs, DNS, a public chain) contact those sources from our servers through a fetcher that refuses private and internal addresses.
  • An email address is stored only where a tool offers to send you a report and you choose to give one.

Limits: ten runs of this tool per minute from one address, and three signed reports per minute. Past that the tool says so and tells you when to try again.

When a free check is not enough

This tool reads what is public and reports what it can see. The Email Security Hardening (SPF/DKIM/DMARC) engagement is the authorized, specialist-led version: signed scope, findings proven by hand, a signed report, and a retest.

Explore Email Security Hardening (SPF/DKIM/DMARC)
SPF/DKIM/DMARC Spoof Checker — Solvex Space