Can Someone Impersonate Your Business by Email?
Check your business domain for common email authentication problems including DMARC, SPF and DKIM. The free check takes seconds and does not require access to your Microsoft 365 or Google Workspace environment.
Check Your Domain
Run the public domain check first. It does not require access to your business systems.
What did the check find?
These are explanatory states only. The scanner output is the source of any domain-specific finding.
- Protection missing — Your domain may be easier to impersonate because important email authentication controls are missing or incomplete.
- Protection present but not enforcing — DMARC may exist but only be monitoring email rather than instructing receiving systems to quarantine or reject messages that fail authentication.
- Authentication looks healthy — Good. That does not mean your entire email environment is secure. DMARC, SPF and DKIM address specific email authentication risks rather than replacing MFA, anti-phishing protection, endpoint security or user awareness.
Email fraud doesn't always require someone to hack your mailbox
Criminals may attempt to impersonate a business by sending messages that appear to come from its domain. SPF, DKIM and DMARC help receiving email systems determine whether messages claiming to come from the domain are legitimate.
Correctly configured email authentication can help reduce opportunities for direct-domain impersonation, provide visibility into systems sending email using the domain, protect domain reputation, identify forgotten or unauthorised sending services, and support reliable email authentication and delivery.
These controls address specific email-authentication risks. They do not prevent all phishing or spoofing, guarantee inbox delivery, replace Microsoft 365 security or anti-spam systems, or make a business fully secure.
SPF, DKIM and DMARC in plain English
- SPF
- Defines which systems are authorised to send email for a domain.
- DKIM
- Adds a cryptographic signature that helps receiving systems verify that an authorised system sent the message and that relevant message content has not been altered in transit.
- DMARC
- Uses SPF and DKIM results together with domain alignment and tells receiving systems how the domain owner wants failed messages handled. It can also provide reporting that helps identify legitimate and unauthorised senders.
Found something worth investigating?
- Free Domain Check — The scanner identifies publicly visible email-authentication configuration.
- Email & Domain Security Review — Altitude reviews what is actually sending email for the organisation and examines relevant SPF, DKIM, DMARC, Microsoft 365 or Google Workspace configuration and applicable third-party senders.
- Prioritised Remediation — We explain what needs changing, what does not, and any risk associated with moving towards stronger enforcement.
- Managed Monitoring — Where ongoing monitoring is justified, Altitude can monitor authentication reporting and configuration rather than assuming that today's setup will remain correct indefinitely.
Need the configuration reviewed?
The Email Authentication & Sending Architecture Review examines the sending services, DNS, Microsoft 365 or Google Workspace configuration and the safe path to any changes.
Talk to Altitude About the Results
If the scan identifies something you want independently reviewed, send us the domain and we'll help you understand what the result actually means before recommending any changes.
Talk to Altitude About the Results