Is Someone Spoofing Your Email Domain Right Now?

Every day your domain goes unprotected, scammers can send fake emails that look like they came from you — putting your reputation, your clients, and your inbox deliverability at risk. Run our free DMARC domain scanner below to see exactly where you stand.

You Shouldn't Have to Be an Email Security Expert to Stay Safe

DMARC, SPF, DKIM, and BIMI are the technical safeguards that stop attackers from impersonating your domain. Most business owners don't have time to dig through DNS records to find out if they're actually configured — or configured correctly.

We've Guided Businesses Like Yours Since 2002

Innovative Network Solutions has spent over two decades helping growing, multi-location businesses lock down their IT — including email security. We know exactly what a healthy domain configuration looks like, and we can show you where yours stands in seconds.

How Our DMARC Domain Scanner Works

1

Enter your domain below

2

We scan your DMARC, SPF, DKIM & BIMI records

3

Get a clear risk score — and a plan to close any gaps

What SPF, DKIM, DMARC & BIMI Actually Do

These four records work together in your domain's DNS settings to prove that email claiming to be from you is actually from you.

SPF (Sender Policy Framework)

SPF publishes a list of mail servers authorized to send email on behalf of your domain. When a receiving mail server gets a message, it checks whether the sending server is on that list.

DKIM (DomainKeys Identified Mail)

DKIM attaches a digital signature to outgoing email, generated from a private key only your mail system holds. Receiving servers verify that signature against a public key published in your DNS, confirming the message wasn't altered in transit and came from an authorized sender.

DMARC (Domain-based Message Authentication, Reporting & Conformance)

DMARC ties SPF and DKIM together. It tells receiving mail servers what to do when a message fails those checks - monitor it, quarantine it, or reject it outright - and sends you reports so you can see who's sending mail using your domain. Learn more from Cloudflare's DMARC record explainer.

BIMI (Brand Indicators for Message Identification)

BIMI lets your verified logo appear next to your emails in supporting inboxes. It requires a properly enforced DMARC policy first, which is why it's usually the last piece businesses configure.

How These Records Work Together

SPF and DKIM are independent authentication checks. DMARC sits on top of both, telling receiving servers what to do when a message fails one or both checks, and how strictly to enforce that decision. A domain with SPF and DKIM but no DMARC policy has authentication in place but no enforcement, meaning spoofed email can still land in inboxes.

What Your Scan Results Mean

Pass: The record is published and configured correctly for that check.

Warning: A record exists but is incomplete, weakly configured (for example, a DMARC policy set to monitoring only instead of quarantine or reject), or missing a reporting address.

Fail: The record is missing entirely, or misconfigured in a way that leaves the domain open to spoofing.

Common Configuration Problems We See

  • DMARC published but set to a monitor-only policy, so nothing is actually blocked
  • SPF records that exceed the 10 DNS lookup limit, causing the check to fail silently
  • DKIM keys that were never rotated or were removed when switching email providers
  • Multiple SPF records for the same domain, which invalidates the check
  • No DMARC aggregate reporting address, so misuse of the domain goes unnoticed

How to Fix What the Scanner Finds

Most gaps are fixed by updating DNS TXT records: publishing or correcting an SPF record, enabling DKIM signing in your email platform (Microsoft 365, Google Workspace, and similar), and publishing a DMARC record that moves from monitoring to enforcement over time as you confirm legitimate senders are passing. Our Security & Compliance team can handle this end-to-end if you'd rather not manage DNS changes yourself.

Privacy & How We Handle Your Scan Data

This tool only looks up publicly published DNS records for the domain you enter, the same records any mail server on the internet can already query. It does not access your email inbox, files, or any internal systems, and scan results are not sold to third parties.

Scanner Limitations

This scan reflects your DNS configuration at the moment you run it. It does not simulate real-world mail delivery, test enforcement behavior at every receiving mail provider, or catch every phishing technique, some of which don't rely on domain spoofing at all. Treat a passing scan as a strong foundation, not a complete security program.

Frequently Asked Questions

Do I need SPF, DKIM, and DMARC if I already use Microsoft 365 or Google Workspace?

Yes. Microsoft 365 and Google Workspace give you the tools to publish these records, but they don't configure DMARC enforcement for you by default. Most businesses on these platforms still have gaps until someone sets DMARC policy explicitly.

Will turning on DMARC enforcement block my own emails?

It can, if legitimate sending sources like a marketing platform or CRM aren't included in your SPF record or DKIM-signed. That's why we recommend moving from a monitoring policy to enforcement gradually, reviewing DMARC reports along the way.

What's a good first step if my scan shows failures?

Start with SPF and DKIM, since DMARC enforcement depends on both being in place. Once those pass consistently, publish a DMARC record in monitoring mode before moving to quarantine or reject.

Is BIMI worth setting up?

BIMI is optional and mainly a brand-visibility benefit. It won't stop spoofing on its own and is worth doing once your DMARC policy is enforced, not before.

Don't Wait for a Spoofed Email to Cost You a Client

An unprotected domain doesn't just risk phishing attacks against your own team — it lets attackers impersonate you to your clients and partners, damaging trust you've spent years building.

Get the Confidence of Knowing Your Domain Is Locked Down

If your scan reveals gaps, our team can help you close them — so no one else can hide behind your good name.