Is your business email an open door for scammers?
Most Eugene-area businesses have never checked whether their domain can be faked in a phishing email. It takes one look at three DNS records to find out. We’ll show you, free, in under a minute.
Three DNS records decide whether a scammer can pretend to be you.
Who’s allowed to send
Lists which mail servers are permitted to send email on your domain’s behalf.
v=spf1 include:_spf.google.com ~all
Proof it wasn’t altered
Signs outgoing mail with a private key so receiving servers can confirm it’s genuine.
selector._domainkey TXT "v=DKIM1; k=rsa; p=..."
What happens if it fails
Tells receiving servers to reject, quarantine, or allow mail that fails the checks above.
v=DMARC1; p=reject; rua=mailto:you@domain.com
Your verified logo
Once DMARC is enforced, shows your business logo next to your emails in the inbox.
default._bimi TXT "v=BIMI1; l=https://..."
Enter your domain. See exactly where you stand.
The scanner checks your live DNS records and grades your exposure to email spoofing and phishing — the same way an attacker would look at it.
Domain Security Scanner
Powered by EasyDMARCA missing record costs more than a scan.
-
01
Invoice fraud starts in the inbox
Without DMARC enforcement, anyone can send an email that appears to come from your domain — including fake invoices to your own customers.
-
02
Legitimate email gets marked as spam
A misconfigured SPF or DKIM record doesn’t just let bad mail in — it can push your real emails into your customers’ junk folder.
-
03
Insurance and vendors are starting to ask
Cyber insurance renewals and larger clients increasingly want proof of email authentication before they’ll do business with you.
-
04
Fixing it is usually a DNS edit, not a project
Most domains just need the right records added correctly — a short job for someone who does it regularly.
Scan came back with issues?
Everything I.T. will walk through the results with you in plain English and fix your SPF, DKIM, and DMARC records — usually without any downtime.