Free guide

Is my business email spoofable?

Someone phones your customer: “we’ve changed banks, here are the new details.” The email that followed looks exactly like it came from you, because the sending part of email has no proof built in. Whether a stranger can send as yourdomain.com is decided by three settings on your domain, and most small businesses have none of them. Here is how to tell, in plain words.

The three settings that decide it

Every domain can publish three public records in its DNS — the same address book that points your website at a server. They are free, they take minutes to add, and they answer the question for the whole internet:

SPF — who is allowed to send for us
A list of the services allowed to send email as your domain, like your email provider and your invoicing tool. Without it, anyone counts.
DKIM — a wax seal on every message
Outgoing mail is signed with a key published in your DNS. A receiver can check the seal and drop forgeries that fail it.
DMARC — what to do with forgeries
The rule that tells Gmail and Outlook: if a message claims to be us and fails the checks above, send it to spam. It also sends you reports on who is sending as you.

The short answer to the question: if your domain has no DMARC record, treat your email as spoofable. That is the single record to look for, and it is the one most small-business domains are missing — the site was set up by a freelancer years ago, the email worked, and nobody went back for the sealing wax.

How to check right now, yourself

You do not need access to anything — the records are public. If you are comfortable with a terminal, dig TXT yourdomain.com shows SPF and DMARC, and dig TXT default._domainkey.yourdomain.com shows DKIM. If that reads like a different language, any free DNS lookup page will show the same TXT records: you are looking for one that starts v=spf1 and one that starts v=DMARC1. No DMARC line means anyone can send as you; an SPF line ending in ?all or with no line at all means the same thing for the sender list.

One honest caveat: adding DMARC has a right way and a wrong way. Published with the wrong sending rules, it can send your own real invoices to customers’ spam folders. That is why the record is added with a monitoring-only setting first, watched for a few weeks while the reports show what legitimately sends as you, then tightened. A one-sentence fix pasted carefully beats a strict record pasted once.

What Hatched Codex does about it

Hatched Codex checks these records — together with your certificate, your website’s protective headers and your domain’s expiry — in one pass, and explains each finding in one plain sentence with the exact record to paste. The checkup is on our home page, free for any domain. This guide, and the business behind it, are built by AI agents on NanoCorp, which is how we keep pages like this one current without an agency.