If a domain publishes no DMARC policy, or publishes p=none, anyone can send mail that looks like it came from that domain. This checker answers that question first: given the live policy, can someone spoof you? Then it shows the rest of the stack so you can see what else is missing.
Public assessments are free. No account. The full 0–100 stack is included below the focused result.
Figures from the July 2026 Top-1M study.
In practice, yes if there is no DMARC record or the policy is p=none. Receivers then have no instruction to refuse forged From: mail. p=quarantine and p=reject are the policies that change that, with reject the one that actually blocks.
No. SPF authorizes sending hosts, but it does not bind the visible From: header by itself, and it breaks on forwarding. DMARC is the policy that ties SPF and DKIM to the domain users see and tells receivers what to do on failure.
The same definition as the July 2026 Top-1M study: mail-enabled domains with no DMARC record or an explicit p=none. That was 70.9% of mail-enabled domains in that corpus. This page leads with that verdict, then still shows the full 0–100 stack.
Scoring rules are on the methodology page. The homepage still has the full product, including the live Pulse.