Domain Scanner
Check whether your domain is protected against email spoofing and impersonation. This tool reads your live DNS and grades your SPF, DKIM, DMARC and MX records, with the specific record you need to add if something is missing.
- Reads live DNS, nothing stored
- Runs entirely in your browser
- Works on any domain
Enter a domain name, not an email address. Nothing you type is sent to Apollo IT Services.
What this checks, and why each one matters
Email security is not a single switch. It is four DNS records that work together to stop someone forging mail from your domain. A gap in any one of them is the gap an attacker uses.
SPF
Sender Policy Framework
Lists which mail servers are allowed to send email using your domain. Without it, anyone can put your domain in the From line and most receivers will accept it.
DKIM
DomainKeys Identified Mail
Adds a cryptographic signature to every message you send, so the receiving server can confirm it genuinely came from you and was not altered along the way.
DMARC
Domain-based Message Authentication
Tells receivers what to do when SPF or DKIM fails, and sends you reports on who is sending mail as your domain. The most commonly missing of the four.
MX
Mail Exchange
Routes incoming mail to your provider. If these are wrong or absent, you are not receiving email at all, and the other three records have nothing to protect.
Fixing the gaps, in the order that makes sense
If your scan came back with warnings, work through these in order. Each one is a DNS change you make at whoever hosts your domain.
- 1
Publish an SPF record
One TXT record at your root domain. Your provider gives you the value: Microsoft 365 uses
v=spf1 include:spf.protection.outlook.com -all, Google Workspace usesv=spf1 include:_spf.google.com -all. Add any third parties that send on your behalf before you finish with-all. Publish exactly one SPF record; two is a failure, not a backup. - 2
Turn on DKIM signing at your provider
You do not write DKIM by hand. Your mail provider generates the key pair and gives you the DNS records to publish. In Microsoft 365 it is under Defender, Email & collaboration, Policies & rules, DKIM. In Google Workspace it is Apps, Google Workspace, Gmail, Authenticate email. Publish the records they give you, then enable signing.
- 3
Start DMARC at p=none and watch
Add a TXT record at
_dmarc.yourdomain.comreadingv=DMARC1; p=none; rua=mailto:you@yourdomain.com. Atp=nonenothing is blocked; you are only collecting reports so you can see every system sending as your domain before you start enforcing. - 4
Move to quarantine, then reject
Once the reports show only legitimate senders passing, tighten to
p=quarantineand finallyp=reject. This is the step most organisations never take, and it is the one that actually stops impersonation. Do not skip straight to reject on a domain you have not been monitoring.
Common questions
The scan says my DKIM was not found. Is it broken?
Not necessarily. DKIM selectors are arbitrary names chosen by your provider, and there is no way to list them from outside. This tool probes the selectors that Microsoft 365, Google Workspace and the common marketing platforms use. If yours uses a custom selector, it will not be found even though it is working correctly. Check for a signature in the headers of a message you have actually sent before treating it as a problem.
Why does my SPF record pass but still show a warning?
An SPF record ending in ~all is a soft fail, which asks receivers to accept
suspicious mail and flag it. Ending in -all is a hard fail and tells them to
reject it. Soft fail is a reasonable place to start while you confirm every legitimate sender is listed,
but it is not the finished state.
Is DMARC at p=none doing anything?
It is not blocking anything, which is the point at first. It gives you reporting, and reporting is what
tells you which of your systems would break if you started enforcing. Domains that sit at
p=none for years are collecting data nobody reads, and are no more protected
than a domain with no DMARC at all.
Does this send my domain anywhere?
The lookups run in your browser against public DNS resolvers operated by Cloudflare and Google, the same records anyone on the internet can already query. Nothing is stored, logged, or sent to Apollo IT Services.
Found gaps you would rather not fix yourself?
Email authentication is fiddly to get right and easy to break in ways you only discover when invoices stop arriving. We do this for businesses across Northwest Arkansas and Austin.