Email Security Score

Score your domain's DMARC, SPF, DKIM, and BIMI in one free check.

--

No Score Just Yet

Your score will appear here once you submit a company email address or domain.

What is the Email Security score?

The Email Security Score is a metric used to evaluate the strength of your email's defenses against potential security threats. It takes into account factors like sender authentication protocols (SPF, DKIM, DMARC) and domain reputation. A high score indicates robust protection against phishing, spoofing, and unauthorized use of your domain, while a low score highlights vulnerabilities that could expose your emails to security risks.

Email authentication knowledge base

A score of 80 or above is rated "great" on this checker's 0–100 scale and usually means SPF, DKIM, and DMARC are set up correctly. 60–79 is "good" with at least one gap worth closing, 35–59 signals weak protection, and below 35 is critical. Domains that have never set up DMARC usually land in the lower bands on their first check, so a low starting score is normal. The report lists the exact fixes, ranked by impact.

The checker reads your domain's public DNS records and runs individual checks across DMARC, SPF, DKIM, BIMI, MX, MTA-STS, and TLS-RPT. Each check looks for a valid record and a safe configuration, and every finding contributes to the 0–100 total. Missing or failing sender-authentication records (SPF, DKIM, and your DMARC policy) typically pull the score down the most, and the report shows which fixes will lift it the most.

Enter your domain in the checker above. It inspects the public DNS records that control sender authentication (SPF, DKIM, DMARC), transport security (MTA-STS, TLS-RPT), mail routing (MX), and brand indicators (BIMI), then returns a 0–100 score with the specific issues it found. This covers the domain side of email security: whether someone else can convincingly send email as you. Securing an individual mailbox is separate, and comes down to strong passwords and two-factor authentication.

Work through the report from the highest-impact finding down. Publish a valid SPF record and keep it under the 10-DNS-lookup limit, enable DKIM signing for every service that sends as your domain, then publish a DMARC record and move it gradually from p=none to p=quarantine and p=reject as legitimate senders come into alignment. MTA-STS, TLS-RPT, and BIMI add further points. Re-run the check after each DNS change to confirm the fix took effect.

Checking domain security is crucial to protect against cyber threats like phishing, domain spoofing, and unauthorized access. Regular security checks help identify vulnerabilities, ensure compliance with best practices, and maintain the integrity and reputation of the domain. This is essential not only for safeguarding sensitive information but also for preserving user trust and confidence in digital interactions with the domain.

An email security assessment (also called an email security audit) reviews how well a domain resists spoofing, phishing, and interception. It covers sender authentication (SPF, DKIM, and the DMARC policy), transport encryption (MTA-STS, TLS-RPT), mail-server setup (MX records), and brand protection (BIMI). This tool runs the domain-layer assessment automatically from public DNS in seconds. A full organizational audit would add items no DNS scan can see, such as mailbox access controls and user awareness.

An email risk score estimates how exposed a domain is to email-based attack, based on whether SPF, DKIM, and DMARC are missing, misconfigured, or left unenforced. The 0–100 score on this page is that kind of domain-level measure. The same phrase is also used in fraud prevention, where vendors score individual email addresses at signup; that is a different measurement. To understand your own domain's spoofing exposure, the domain-level score is the one to track.

Yes. The check is free, runs online in seconds, and needs no account: enter a domain and you get the full score and findings. You can re-run it as often as you like, for example after each DNS fix. It only reads public DNS records, so it makes no changes to your domain.

Yes. The check works on any domain because it reads public DNS records, so you don't need to own or verify a domain to score it. IT teams typically check their own domains and subdomains, while managed service providers use it to assess client and prospect domains before an email-security conversation. Scoring a domain changes nothing on the domain itself.

Re-run the check after any change to your DNS or sending stack: a new marketing platform, CRM, or helpdesk that sends as your domain, a DNS migration, or a DMARC policy update. For a stable domain, a quarterly check is a sensible floor. A check is a point-in-time snapshot, though. Sending services and DNS records drift, which is why teams that take DMARC seriously monitor aggregate reports continuously instead of relying on occasional scans.