Free check · no signup
For most domains the answer is yes, and the owner has no idea. Enter your domain and we will show you what the public internet already knows about it — in plain English, on this page, free.
DNS records, public certificate logs, and one ordinary visit to your homepage — the same things any visitor’s browser sees. Nothing is scanned, probed, or logged into.
The full result appears on screen. An email address is only asked for afterwards, if you want a copy to forward.
Most checks come back in under five. The slowest are the public certificate logs, which are occasionally grumpy.
What it checks
None of this requires access to your systems, which is exactly why an attacker can see it too.
Questions
DMARC published in monitoring mode — "p=none". The record exists, so most tools and most IT providers report it as done, but it explicitly instructs receiving mail servers to take no action on messages that fail. Spoofed email from the domain still lands in the inbox. We see it on the clear majority of domains we check.
Those protect mail coming in to you. This is about mail going out with your name on it — an invoice sent to your customer, or a wire request sent to your bookkeeper, from an address that looks exactly like yours. Your own filtering never sees it, because it never touches your systems.
Technically yes, and we rate-limit it for that reason. Everything it reads is public — the same records any mail server consults a thousand times a day. It is a lookup, not a scan.
No. Call us and we will tell you what to change even if you have your own IT person do it. Most of these are an afternoon of work for someone who knows the order to do them in — the order being the part that matters, since tightening email authentication carelessly stops real invoices from being delivered.
Rather just talk to someone? (781) 680-5432 · Mon–Fri, 8 AM–5 PM ET · get a call back →