Live DNS check · same engine as the full SecLens score

Email spoofing check

If a domain publishes no DMARC policy, or publishes p=none, anyone can send mail that looks like it came from that domain. This checker answers that question first: given the live policy, can someone spoof you? Then it shows the rest of the stack so you can see what else is missing.

Public assessments are free. No account. The full 0–100 stack is included below the focused result.

70.9%
of mail-enabled Top-1M domains are spoofable
29.0%
enforce quarantine or reject

Figures from the July 2026 Top-1M study.

FAQ

Common questions

Can someone spoof my domain?

In practice, yes if there is no DMARC record or the policy is p=none. Receivers then have no instruction to refuse forged From: mail. p=quarantine and p=reject are the policies that change that, with reject the one that actually blocks.

Is SPF enough to stop spoofing?

No. SPF authorizes sending hosts, but it does not bind the visible From: header by itself, and it breaks on forwarding. DMARC is the policy that ties SPF and DKIM to the domain users see and tells receivers what to do on failure.

What does SecLens treat as spoofable?

The same definition as the July 2026 Top-1M study: mail-enabled domains with no DMARC record or an explicit p=none. That was 70.9% of mail-enabled domains in that corpus. This page leads with that verdict, then still shows the full 0–100 stack.

Scoring rules are on the methodology page. The homepage still has the full product, including the live Pulse.