Email security check: can someone send email as you?
Fake invoices and payment-change requests start with email that looks like it came from you or your vendor. Enter your domain to grade your DMARC, SPF and DKIM, find lookalike domains registered by someone else, and see how your Microsoft 365 sign-in is set up.
What your domain tells an attacker
DMARC tells receiving mail servers what to do with email that fakes your domain. At p=reject, servers that follow it refuse the fake. At p=none, they deliver it and send you a report. SPF lists the servers allowed to send as you, and DKIM signs your mail so receivers can prove it is genuine.
DMARC cannot stop a domain that only looks like yours. We try more than a hundred common lookalikes, such as a missing letter, swapped letters, rn for m or a different ending, and flag the ones that are registered and set up to send and receive email.
Everything comes from public DNS, domain registry and Microsoft sign-in records, the same outside view attackers and cyber insurers have. We do not send email, sign in or touch your systems. We keep the domain checked and the time, and nothing else unless you ask for the report.
What it cannot see: whether MFA is enforced for everyone, mailbox forwarding and hidden inbox rules, risky app consents, and who holds admin rights. That takes a read-only look inside your Microsoft 365 tenant.
Email security questions, answered
What is a good DMARC policy?
p=reject, covering all mail, with a rua address so you receive reports. Most organizations get there in stages: p=none to see who sends as them, then p=quarantine, then p=reject.
If our DMARC is set to reject, are we safe from email fraud?
Safe from exact spoofing, not from lookalikes or real account takeovers. Attackers register a domain one letter off, or take over a real mailbox at your company or a vendor and send from it. A call-back on a known number before any change to payment details is the control that works.
Why does it say DKIM could not be confirmed?
DKIM keys sit under a name, called a selector, that only your email provider knows. We check the common ones. If yours uses a custom name, ask whoever runs your email to confirm signing is on.
Are lookalike domains always malicious?
No. Some are your own defensive registrations and some are parked by domain investors. The ones that can receive email and were registered recently deserve a closer look. We leave out domains that share your name servers or were registered alongside yours.
Do you store what I check?
We keep the domain you checked and the time, so we can see how the tool is used. If you ask for the report, we also receive your contact details and the results.
Does this check send email or touch our systems?
No. It reads public DNS, registry and Microsoft sign-in records only. Nothing is sent to the domain you check.
Cloudskope is a security-only advisory firm based in Dallas, Texas. We run forensic audits of Microsoft 365 and Azure, cyber due diligence for deals, and a fixed-fee six-day assessment and remediation program for firms and their portfolio companies. We are independent of your IT provider and compliance consultant, and we work alongside both.
Since May 1, 2026, our forensic audits have prevented $2.2M in wire fraud, none of it flagged first by the client's IT team, managed service provider, bank or security tools.
Sources
Opened and checked on October 1, 2026.
.png)