Email Security Check For Any Domain
See whether anyone could send email that looks like it came from your domain — and what records close the gap.
Free, no account. Passive checks only — the same requests a browser or DNS lookup makes.
What This Checks
- An SPF record, and whether it ends in a strict policy
- A DMARC record, and whether it quarantines or rejects spoofed mail
- DNSSEC signing of the domain's records
- A CAA record limiting which authorities can issue certificates
Why It Matters
Without SPF and an enforcing DMARC policy, a stranger can send password-reset or invoice emails that appear to come from your domain. Mail providers increasingly reject or junk mail from domains that lack them.
These records are public DNS entries, so this check reads exactly what an attacker (or a spam filter) can read.
Check Every Deploy, Not Just Today
ZipLoom runs this check automatically on every deploy, alongside a dependency vulnerability audit — and can scan your source code on demand or on every commit.
Scan Your App FreeMore Free Checks
Security Headers Check · Is Your Source Code Public? Source Map Check · CORS Checker For Your API