Free tool

Can someone send email as your domain?

Type your agency's domain. In a few seconds you'll see whether a criminal can send email that appears to come from your exact address. Nothing to install, no signup.

The part after the @ in your email address. Public records only.

Why this matters for a title company

Most wire fraud at closings starts with one email: "updated wiring instructions" that look like they came from the title company. If your domain has no enforced DMARC policy, a criminal doesn't need to hack anything to send that email. They can simply put your address in the From line, and most inboxes will deliver it.

The FBI's Internet Crime Complaint Center recorded 24,768 business email compromise complaints and more than $3 billion in losses in its 2025 report. Title and settlement offices are a favorite target because they move large sums on a deadline.

How to read your result

ResultWhat it meansWhat to do
ExposedNo DMARC policy, or a policy set to monitor only (p=none). Forged email from your exact address is delivered.Publish DMARC and move it to enforcement after confirming your legitimate senders.
Partly protectedPolicy is "quarantine", or "reject" applied to only part of your mail. Forgeries usually go to spam.Move to "reject" at 100% so forgeries are refused outright.
ProtectedPolicy is "reject" at 100%. Email forged from your exact domain is refused.Keep monitoring reports, and watch for look-alike domains.

What this check doesn't cover

  • Look-alike domains. A scammer can register a near-copy of your domain, one letter off, and email your clients from it. DMARC can't stop that; monitoring can.
  • Hacked mailboxes. If a staff password is stolen and there's no two-step sign-in, the criminal sends from your real account.
  • Email signing (DKIM) and your website. These need a closer look than a three-record lookup.

The free Exposure Report covers all nine checks and lists the fixes in priority order. For the plain-English background, read DMARC for title companies.

Common questions

What does this check actually look at?

Three public DNS records for your domain: DMARC, which tells other mail servers what to do with email that fails verification; SPF, which lists the services allowed to send for you; and MX, which shows your email provider. Anyone on the internet can read these records.

Is it safe to type my domain here?

Yes. The lookup happens in your own browser against Cloudflare's public DNS service, the same way any mail server would look up your records. We don't log in to anything, test your systems, or store the domain unless you ask for a full report.

My result says protected. Am I safe from wire fraud?

You're protected against one specific attack: email forged from your exact domain. Criminals also register look-alike domains (one letter off) and break into real mailboxes with stolen passwords. The full Exposure Report checks more of that surface.

My result says exposed. How hard is it to fix?

The fix itself is a few DNS records, but turning on enforcement without first confirming every service that legitimately sends your email (your closing software, scanners, marketing tools) can block your own mail. Done carefully, most small offices are locked down in about a week.

Does a p=none policy protect me?

No. p=none means monitor only. You receive reports about forged email, but the forgeries are still delivered. Protection starts at quarantine and is complete at reject.