Free Email Security Tool

Free DMARC checker: can someone send email as your organization?

Enter your domain and get a letter grade for SPF, DKIM, DMARC, MTA-STS, and MX in about ten seconds, with a plain-language fix for everything that fails. The full result appears on this page. No email address is required to see it.

Interactive Scorecard

Grade your domain. See what an impostor could get away with.

Most reported nonprofit wire fraud starts with an email that looks like it came from the executive director or a vendor. Whether that email is delivered or blocked depends on a handful of public DNS records that anyone can inspect. This scorecard reads those records for your domain, weights them by how much protection each one provides, and turns the result into a grade your board can understand.

Email Security Scorecard

  • Seven checks run against your public DNS records: SPF, DKIM, DMARC policy, DMARC reporting, MTA-STS with TLS reporting, MX hygiene, and lookalike domains.
  • Results appear here in about ten seconds. Nothing is installed and no mailbox is accessed.
  • No email address is needed to see the full result. A PDF copy is optional.

Enter a domain to begin.

How the Grade Works

Seven checks, weighted by how much they protect you.

Each check maps to a control that stops a specific attack. The points reflect how much of the real-world risk that control removes, which is why DMARC enforcement alone is worth almost a third of the grade.

CheckPointsWhat earns full creditWhat it stops
SPF record15One valid v=spf1 record, ten or fewer DNS lookups, ending in -all or ~all.Servers you never authorized sending mail with your domain in the envelope.
DKIM signing15A published signing key for your mail provider (Microsoft 365, Google Workspace, or a common marketing platform).Messages altered or forged in transit; lets receivers prove the mail is really yours.
DMARC policy30p=quarantine or p=reject applied to 100 percent of mail. p=none earns 10 of 30.Delivery of any message that fails SPF and DKIM while claiming to be from you.
DMARC reporting10A rua= address that resolves, authorized if it lives on another domain.Spoofing campaigns going unnoticed for months.
MTA-STS and TLS-RPT10A valid policy in enforce mode served over HTTPS, plus a TLS-RPT record.Mail to your staff being downgraded to an unencrypted connection and read in transit.
MX hygiene10Every MX host resolves, the provider is identifiable, and nothing points at a parked or abandoned service.Inbound mail routed to a server you no longer control.
Lookalike domains10None of the 20 most likely typo and top-level-domain variants is registered by someone else.Invoice and payroll fraud sent from a domain one letter away from yours.
A90 to 100

Well protected. Keep the reports under review.

B75 to 89

Solid basics with one gap worth closing this quarter.

C55 to 74

Partially protected. Impostors can still use your name.

D35 to 54

Exposed. Most spoofed mail using your domain will be delivered.

F0 to 34

No meaningful protection. The profile of most reported nonprofit wire fraud cases.

Common Questions

DMARC and email security, explained for the people who sign the checks.

What is DMARC, and why does a nonprofit need it?

DMARC is a public DNS record that tells every other mail server what to do with a message claiming to come from your domain when that message fails authentication: deliver it anyway (p=none), send it to spam (p=quarantine), or refuse it (p=reject). Without an enforcing DMARC policy, anyone can send email that displays your executive director's name and address, and most receiving systems will deliver it. Nonprofits are targeted because they move money on trust, publish staff names and roles, and rarely have anyone watching the domain.

We use Microsoft 365 or Google Workspace. Isn't this already handled?

Both platforms authenticate the mail they send for you, but neither publishes your DMARC policy or fixes your SPF record; those live in your domain's DNS, and the defaults leave them missing or set to p=none. Microsoft 365 also leaves DKIM signing off for custom domains until an administrator turns it on. The platform provides the tools, and the tenant owner is responsible for using them, which is why scanning two organizations on the same platform can return an A and an F.

Our DMARC record says p=none. Isn't that enough?

No. p=none is monitoring mode: it asks receivers to send you reports, but instructs them to deliver failing mail exactly as if the record did not exist. It is the right first step because it shows you every service sending as your domain before you block anything. It becomes a problem when organizations stop there, which is where most nonprofits under 75 staff sit today. The scorecard gives p=none 10 of 30 points for that reason.

Will DMARC enforcement block our newsletters and donation receipts?

Only if those tools are not authorized first, and that is exactly what the monitoring period is for. Newsletter platforms, fundraising CRMs, payroll, and ticketing systems each need to be listed in SPF or configured to sign with DKIM as your domain. The DMARC reports collected during two to four weeks at p=none show every one of them, including the vendor nobody remembered. Once each legitimate sender authenticates, moving to p=quarantine and then p=reject blocks impostors without touching real mail.

How long does it take to fix a failing grade, and what does it cost?

For an organization on Microsoft 365 or Google Workspace with two or three outside services sending as its domain, the DNS changes themselves take a few hours of skilled work. The calendar time is the two-to-four-week monitoring period before enforcement, so a D or F becomes an A in roughly six weeks. ETTE includes this work in its Email Security service, and published pricing shows how that fits into a managed plan. An organization with capable internal IT can do the same work using the fix notes on this page.

What is a lookalike domain, and why does the scorecard check for one?

A lookalike is a domain one character away from yours: the .com version of your .org, a swapped letter, or an rn where an m should be. Criminals register them to send invoices and payroll changes that pass every technical check because the mail really does come from the domain it claims. DMARC on your own domain cannot stop that, so the scorecard checks the 20 most likely variants and separates ones that point at your own servers from ones held by someone else. Registering the top few yourself costs less than one fraudulent wire.

Next Step

A failing grade is fixable in about six weeks.

Every check above is a control ETTE runs for nonprofits, associations, and small businesses as part of managed Email Security and GuardRail. Bring your scorecard to a conversation with an advisor and leave with a sequence, a timeline, and a clear read on what your team can do itself.