Email security

Make your email domain harder to impersonate.

Understand who can send email using your domain, spot gaps in authentication and plan improvements without disrupting legitimate messages.

Four records, different jobs.

Email authentication helps receiving systems assess messages claiming to come from your domain. It works alongside secure accounts, filtering and staff awareness.

SPF: authorised sending sources

Sender Policy Framework identifies which mail servers may send for a domain used in the message's envelope sender. Include legitimate services, such as your mail platform and approved sending applications.

DKIM: a verifiable signature

DomainKeys Identified Mail adds a digital signature. Receiving systems use a public DNS key to check that signed parts of the message have not changed and identify the signing domain.

DMARC: alignment, policy and reports

DMARC checks whether a passing SPF or DKIM result aligns with the domain people see in the From address. It lets you request handling of failures and receive reports to investigate sending sources.

BIMI: your brand in supported inboxes

Brand Indicators for Message Identification can support logo display where the mailbox provider accepts it. Authentication, logo and certificate requirements vary by provider. A BIMI record does not guarantee display or make a message safe.

Free domain check

Start with your public email records.

Enter a domain such as example.co.uk, not an email address or password. The checker gives an initial view, not a complete audit or a guarantee of delivery.

BIMI checking is not enabled in this tool. We can discuss BIMI separately. DKIM discovery can also depend on the selectors a checker knows, so a missing result needs investigation.

Choose whether to load this external tool

EasyDMARC provides this checker. It receives the information you submit and technical browser information. Its own cookies and analytics may run when you allow external security tools, even if CompTech analytics is off.

The checker is off until you allow External security tools in Cookie settings.

Ask CompTech for help instead

Improve protection without losing legitimate mail.

CompTech can help review your sending services and plan changes around the organisation's actual email use. Scope, access and any ongoing monitoring are agreed separately.

Find every sender

Include Microsoft 365, newsletters, finance systems, website forms and other approved platforms. Establish who owns each service and its DNS configuration.

Validate before enforcement

Review reports and test legitimate mail. Correct SPF, DKIM and alignment before moving towards quarantine or rejection. Avoid copying DNS records without checking their effect.

Keep the position current

Review new suppliers, domain changes and authentication failures. A passing check today does not cover every future message or service change.

Authentication does not stop every phishing email, lookalike domain or compromised account. Combine it with wider cyber security, Microsoft 365 protection and staff awareness.

Check a suspicious link

Need help understanding the results?

Tell us your domain and which services send email for your organisation. We can help identify the next practical step.