Skip to main content
Apollo IT Services

Domain Scanner

Check whether your domain is protected against email spoofing and impersonation. This tool reads your live DNS and grades your SPF, DKIM, DMARC and MX records, with the specific record you need to add if something is missing.

  • Reads live DNS, nothing stored
  • Runs entirely in your browser
  • Works on any domain

Enter a domain name, not an email address. Nothing you type is sent to Apollo IT Services.

What this checks, and why each one matters

Email security is not a single switch. It is four DNS records that work together to stop someone forging mail from your domain. A gap in any one of them is the gap an attacker uses.

SPF

Sender Policy Framework

Lists which mail servers are allowed to send email using your domain. Without it, anyone can put your domain in the From line and most receivers will accept it.

DKIM

DomainKeys Identified Mail

Adds a cryptographic signature to every message you send, so the receiving server can confirm it genuinely came from you and was not altered along the way.

DMARC

Domain-based Message Authentication

Tells receivers what to do when SPF or DKIM fails, and sends you reports on who is sending mail as your domain. The most commonly missing of the four.

MX

Mail Exchange

Routes incoming mail to your provider. If these are wrong or absent, you are not receiving email at all, and the other three records have nothing to protect.

Fixing the gaps, in the order that makes sense

If your scan came back with warnings, work through these in order. Each one is a DNS change you make at whoever hosts your domain.

  1. 1

    Publish an SPF record

    One TXT record at your root domain. Your provider gives you the value: Microsoft 365 uses v=spf1 include:spf.protection.outlook.com -all, Google Workspace uses v=spf1 include:_spf.google.com -all. Add any third parties that send on your behalf before you finish with -all. Publish exactly one SPF record; two is a failure, not a backup.

  2. 2

    Turn on DKIM signing at your provider

    You do not write DKIM by hand. Your mail provider generates the key pair and gives you the DNS records to publish. In Microsoft 365 it is under Defender, Email & collaboration, Policies & rules, DKIM. In Google Workspace it is Apps, Google Workspace, Gmail, Authenticate email. Publish the records they give you, then enable signing.

  3. 3

    Start DMARC at p=none and watch

    Add a TXT record at _dmarc.yourdomain.com reading v=DMARC1; p=none; rua=mailto:you@yourdomain.com. At p=none nothing is blocked; you are only collecting reports so you can see every system sending as your domain before you start enforcing.

  4. 4

    Move to quarantine, then reject

    Once the reports show only legitimate senders passing, tighten to p=quarantine and finally p=reject. This is the step most organisations never take, and it is the one that actually stops impersonation. Do not skip straight to reject on a domain you have not been monitoring.

Common questions

The scan says my DKIM was not found. Is it broken?

Not necessarily. DKIM selectors are arbitrary names chosen by your provider, and there is no way to list them from outside. This tool probes the selectors that Microsoft 365, Google Workspace and the common marketing platforms use. If yours uses a custom selector, it will not be found even though it is working correctly. Check for a signature in the headers of a message you have actually sent before treating it as a problem.

Why does my SPF record pass but still show a warning?

An SPF record ending in ~all is a soft fail, which asks receivers to accept suspicious mail and flag it. Ending in -all is a hard fail and tells them to reject it. Soft fail is a reasonable place to start while you confirm every legitimate sender is listed, but it is not the finished state.

Is DMARC at p=none doing anything?

It is not blocking anything, which is the point at first. It gives you reporting, and reporting is what tells you which of your systems would break if you started enforcing. Domains that sit at p=none for years are collecting data nobody reads, and are no more protected than a domain with no DMARC at all.

Does this send my domain anywhere?

The lookups run in your browser against public DNS resolvers operated by Cloudflare and Google, the same records anyone on the internet can already query. Nothing is stored, logged, or sent to Apollo IT Services.

Found gaps you would rather not fix yourself?

Email authentication is fiddly to get right and easy to break in ways you only discover when invoices stop arriving. We do this for businesses across Northwest Arkansas and Austin.

Talk to us about it