Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
By problem · Email anyone can fake

Stop strangers sending email in your name

Your domain publishes records that tell every mail server what to do with a message that claims to be from you. Many firms publish none, or one that blocks nothing. We read yours from outside and say in plain words whether a forged message is refused or delivered.

Attackers use AI to find openings. We use it to find yours first, and a person checks every finding before your assessment is released.

Read-only, from outsideNothing tested or logged intoReviewed by a person
What we check for thisRead-only
DMARC
Whether you publish one, and whether it rejects, quarantines or only monitors
SPF
Which servers may send as you, and whether the rest are refused
DKIM
Whether a signing key answers at the common names
MTA-STS
Whether mail sent to you must arrive encrypted
Reviewed by a person before release. Every finding carries a check anyone can run.
01 · What we check

Three settings decide whether a forged message gets through.

AI now lets every phishing email be written for the person who opens it. Your DMARC record decides whether one sent in your name is delivered.

01
No DMARC record

Receiving mail servers are given no instruction, so a message that fakes your address is judged on its own and often delivered.

02
Monitor only

A DMARC record set to p=none only watches: it blocks nothing. It is the first step, not the finished setting.

03
A soft SPF ending

An SPF record ending in ~all asks receivers to accept and mark a message from an unlisted server, not to refuse it.

04
Closed in one click

In the paid assessment, forged email is closed from your assessment page: DMARC is raised in stages you confirm, from monitor to quarantine to reject, with a re-check between each step. Where we cannot write to your DNS host, you get the exact records to paste.

02 · What we measured

Measured on 19 September 2026.

8 in 10
Professional firms cannot stop a stranger sending email in their name.

Measured across the firms we have assessed in Canada and the United States, not a national census. The method is in the study.

03 · What we read

The outside view, in plain words.

Your DMARC record
The policy your domain publishes. Check it yourself: look up _dmarc followed by your domain with any free DNS lookup.
Your SPF record
The servers allowed to send as you, and how the record ends. Check it yourself: look up the TXT records on your domain.
Nothing changes on its own
No stage of the fix is applied without your confirmation, and nothing steps up by itself.
What it cannot see
Your inbox, or whether a forged message has already been sent. We log into nothing and send nothing in your name.
How we are different

Next to the people you already work with.

Your IT provider

Keeps your systems running and does the fixes. We give them an independent list to act on, with the check that proves each fix. We are paid by no one who sells the fixes, so every finding is independent.

A penetration test

Tries to break in and needs access. We read only what is already public, from outside, and log into nothing.

Your insurer's scan

Feeds your premium and eligibility. We show you the same outside view first, in plain words, so you walk into renewal knowing the answers.

For your firm

Find out whether a forged message in your name is refused or delivered.

The External Exposure Check: your outside reading, with what we found and a check you can run yourself. No access, nothing tested.

Check my firm