email-check / a security scan
a free tool by Creative Baguette
Free email impersonation check

Can someone send an email pretending to be you?

Enter your work email. In about ten seconds you'll see whether someone can forge an email from your exact address. It comes down to one door, open or closed.

No sign-up We don't send any email Public records only
What a faked email from you looks like
Inbox — 1 newexample
Y
Your business name
accounts@yourbusiness.com.au
9:41
Updated account details

Hi Sarah, we've changed banks. Please use the new account below, not the one on the invoice. Same amount.

!Sent by a scammer, not by you, to switch the payment into their own account. On most domains, nothing stops it reaching people's inboxes.

What the scan reads

three public records, resolved over DoH
SPF
Who is allowed to send

A list of the services permitted to send mail using your domain. Wrong or too loose, and anyone qualifies.

DKIM
Proof the mail is really yours

A signature on every message you send. Without it, a receiving server has nothing to verify against.

DMARC
The instruction to reject

The rule that tells every mail server what to do with a forgery. This is the one that does the blocking.

How it works
01
You enter your work address
No password, no sign-up, no access to your mailbox.
02
We read three public records
The same ones every mail server on the internet already sees.
03
You get a plain-English answer
Whether the door is open, what's missing, and what closing it involves.
[privacy] We only read your domain's public records, the same ones every mail server already sees. We don't send any email, log into anything, or touch your systems. We use your address to send your result, and follow up only if you ask us to.

The questions people ask

What does "someone can fake your email" actually mean?

Email was built in a way that never checks the "from" line. Anyone can write your address on a message, the same way anyone can write your return address on an envelope. Three settings on your domain (SPF, DKIM and DMARC) work together to tell receiving mail servers to reject messages that aren't really from you. They can't just be flipped on, though. They have to be configured to match every service that legitimately sends email for you, tested against real mail, and then tightened in stages so you don't end up blocking your own invoices and newsletters. Get any of that wrong and you either stay exposed or break your own email. That's the part worth getting right.

Why does this matter for my business?

The most common version is a fake invoice. A scammer sends one of your customers an email that looks like it came from you, saying your bank details have changed. Your customer pays the new account. It's your name on the email, and it's a very hard conversation afterwards. Closing this makes that specific trick a lot harder.

Is this check safe? Are you doing anything to my domain?

No. This tool only reads your domain's public records, the same information every mail server can already see. It doesn't send any email, log into anything, or touch your systems. It just checks whether the settings that stop impersonation are switched on.

If I fix this, am I completely protected from fraud?

No, and anyone who says otherwise is overselling. This checks and fixes whether someone can use your exact address. It doesn't stop a scammer registering a look-alike domain, or a mailbox that's been hacked. It reduces the chance, it doesn't remove it. It's one important door, closed and watched.