Email security check
Email security configuration check
Without SPF, DKIM and DMARC configured correctly, anyone can send email that appears to come from your domain — a common way attackers impersonate real businesses. Wraith checks all three.
$9.00 one-time · no subscription
SPF — who is allowed to send mail for you
Sender Policy Framework lists the mail servers authorized to send email on your domain’s behalf. Wraith checks that a valid SPF record exists and is correctly formed — a broken or missing record means receiving mail servers have no basis to trust mail claiming to be from you.
DKIM — proving a message wasn’t altered
DomainKeys Identified Mail signs outgoing messages so a receiving server can verify they weren’t tampered with in transit and genuinely came from your infrastructure. Wraith checks for a published DKIM record.
DMARC — telling receivers what to do
Domain-based Message Authentication ties SPF and DKIM together and tells receiving mail servers what to do with a message that fails both — quarantine it, reject it, or do nothing. Wraith checks whether a DMARC record is published and how it’s configured.
A plain-language result, not a raw record dump
The report explains what each finding means for your domain specifically and what to change — not just whether a record technically parses.
