ONDUU / FREE TOOL

Can someone send email pretending to be you?

Enter your domain. This reads the public records that decide whether a stranger can email your customers using your business name — and tells you, in plain English, what to fix.

Reads published DNS only. No signup, no credentials, nothing private.

01 / WHAT THIS READS

Published records only.

Every record checked here is already public. Anyone can look them up, including the people who would spoof your domain. Nothing is stored, no credentials are asked for, and no mailbox is touched.

  • SPF — which servers are allowed to send mail as your domain
  • DKIM — whether your mail is signed, so tampering is detectable
  • DMARC — what receiving servers should do with forged mail, and who gets reports
  • MX — where your mail is delivered, and which provider runs it
A clean result means these four records are published correctly. It does not prove your domain, your mailboxes or your business are secure, and it is not a penetration test or a compliance certificate.

02 / WHY IT MATTERS

The records are the defence.

Over 100 Kenyan parastatal chief executives face disciplinary action over exactly these records. The full story, and what the checker found when it was first pointed at this domain, is in the article.

Over 100 parastatal CEOs face action on email security. Check yours.

YOUR NEXT STEP

Find the three digital weaknesses worth fixing first.

The email records are one layer. A readiness score covers the rest.

Get your digital readiness score