Stop criminals sending email as your domain

SPF, DKIM and DMARC tell the world which servers may send email for your domain and what to do with everything else. Without them, anyone can send an invoice that looks like it came from you.

The three records, in plain English

  • SPF lists the services allowed to send email for your domain, such as Microsoft 365, Google Workspace or your newsletter tool
  • DKIM adds a signature to each message so receivers can tell it really came from you and wasn't altered
  • DMARC tells receivers what to do when a message fails those checks, and where to send reports

How TenantWard sets them up

The free check reads your records and explains what's missing. Connect your DNS host, Cloudflare, GoDaddy or Amazon Route 53, and TenantWard publishes the fix for you: an SPF record that includes the senders you use, DKIM for Microsoft 365 read straight from Exchange, and DMARC rolled out in stages from monitoring to quarantine to reject.

Each DNS change saves the previous value first and can be undone with one click. A daily snapshot alerts you if MX, NS, SPF, DKIM or DMARC records change unexpectedly.

Why it matters now

Google and Yahoo require bulk senders to authenticate their email, and Microsoft has introduced similar rules for Outlook.com. Even if you don't send in bulk, missing DMARC makes it easy to spoof your domain in payment fraud.

Questions

Is the email security check free?
Yes. Checking a domain's SPF, DKIM, DMARC, certificate and registration is free with no account. Monitoring one domain weekly is free for good.
Will DMARC stop my legitimate email being delivered?
Not if it's rolled out in stages. TenantWard starts at p=none to collect reports, then moves to quarantine and reject only once your real senders pass.

See where your company stands

Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.