Before a criminal sends a fake invoice or tries to take over a mailbox, they do their homework. And almost all of that homework happens in public. Your domain name, the records that tell the world who may send email as you, your website's security settings, and the domains that look like yours are all visible to anyone who knows where to look.

We work with businesses all around Houston and the Gulf Coast, and the first thing we do with a new client is look at them the way an attacker would: from the outside, with no passwords and no inside access. We've now turned the core of that review into a free email and domain security check anyone can run from our website in under a minute.

What we found when we ran it on ourselves

Before putting the check in front of anyone else, we pointed it at our own domain. It's humbling to report, but it found real things:

  • A look-alike domain. Someone registered a name one letter off ours earlier this year, and it's set up to send and receive email. That's exactly the kind of domain used to send a convincing fake invoice.
  • A half-configured email protection. We had records in place for a feature that forces other mail servers to use encryption when delivering to us, but the policy file behind them had stopped working. It looked protected without actually being protected.
  • An older, shorter email signing key that was due to be replaced with a stronger one.
  • Leftover DNS records pointing at services we stopped using years ago.

None of these were emergencies, and all of them are fixed or being fixed. But every one of them was invisible from the inside and obvious from the outside. That's the point of looking.

What the free check looks at

The check reads only public information. It doesn't log in to anything, guess passwords, or probe your systems. In about 15 seconds it covers four areas.

1. Can someone send email that looks like it came from you?

Email was designed decades ago without any built-in way to prove who sent a message. Three records fix that: SPF lists the services allowed to send your mail, DKIM adds a digital signature, and DMARC tells receiving mail servers what to do with messages that fail those checks.

If DMARC is missing, or set to "monitor only," anyone can send email that appears to come from your exact address. That's how a message "from the owner" asking the bookkeeper to rush a payment gets through. Our guide to DMARC compliance explains the records in more detail, and our email record checker shows exactly what's published for your domain.

2. Is your domain safe from being hijacked or lost?

Your domain is the key to your email and your website at the same time. The check confirms that your domain is locked against transfer (so it can't be moved to another registrar with a forged request), shows when it expires, and checks whether you've limited which certificate authorities can issue security certificates in your name.

An expired or stolen domain takes email and the website down together. It's one of the most disruptive things that can happen to a small business, and one of the easiest to prevent.

3. Does your website protect your visitors?

The check confirms your website uses current encryption, sends visitors to the secure version of the site automatically, and includes the browser protections that stop your pages being quietly downgraded on public Wi-Fi or embedded in someone else's site.

4. Has anyone registered a name that looks like yours?

We generate over a hundred variations of your domain (swapped letters, missing letters, look-alike characters and other endings like .net or .co) and check which ones are registered and able to handle email. A look-alike that was registered recently and can send mail deserves attention. It doesn't prove anyone is planning fraud, but it's worth your accounts payable team knowing about it.

How to read your result

You'll get a letter grade, a score out of 100, and a short list of the issues that matter most, each with a plain-English explanation of why it matters. You'll also see what's already working, because most businesses have more right than wrong.

A few tips:

  • A missing or monitor-only DMARC record is the most common high-priority finding we see. It's also one of the most valuable to fix, but it should be done in stages so you don't block your own invoices or newsletters.
  • An unlocked domain is usually a two-minute fix in your registrar account. Turn on the lock and make sure that account has multi-factor sign-in.
  • A look-alike domain usually isn't something you can take down. The practical response is to block it in your email filtering and tell the people who approve payments.

What an outside check can't see

A public check has limits, and we'd rather be honest about them. It can't tell you whether every employee uses multi-factor sign-in, whether a mailbox is quietly forwarding mail to an outside address, or which third-party apps have been given access to your email and files. Those are the things that turn a phishing email into a real loss.

Our full security report adds every subdomain and exposed service we can find from public records, and, with your permission, a read-only review of the sign-in and mail settings inside your email account. We walk through it with you on a call, in plain English, with a prioritized list of what to fix first.

Run your free check

It takes less than a minute: run the free email and domain security check. If anything in your results raises questions, or you'd like the full report, schedule a free discovery call and we'll go through it together.