Free email security scorecard
Five signals in a single A-to-F grade.
One overall A-to-F grade for a domain’s email security, in a single analysis: SPF, DKIM, DMARC, BIMI, MTA-STS and DNSSEC combined, with a per-dimension breakdown and a link to each dedicated checker.
- Free
- No account
- Instant result
- Public data only
Analyze a domain
How it works
- 1
Enter a domain
Enter the domain to analyze. No account, no proof of ownership: the analysis reads only public data.
- 2
The six signals are read
The checker reads the public records for SPF, DKIM, DMARC, BIMI, MTA-STS and DNSSEC, and fetches the standardized public policies.
- 3
Instant grade
An A-to-F grade and the per-dimension detail appear on screen. A free account then lets you monitor changes over time.
Why one overall grade
Email security is a chain: SPF and DKIM feed DMARC, MTA-STS protects transport, BIMI rewards the brand once the chain is complete. A single grade shows where the domain stands and what to fix first — then each dimension links to its dedicated checker for the details and the steps to take.
p=none caps the grade
Without an enforced DMARC policy, spoofing of the visible “From” header isn't blocked: the grade stays capped.
Configuring isn't protecting
Publishing SPF and DKIM without an enforced DMARC protects nothing on the visible sender — the posture stays weak.
One weak link drops the chain
A single missing or misconfigured signal pulls the whole posture down, however good the others are.
One grade that aggregates the whole email posture
The scorecard brings together the six signals of a domain’s email security: SPF and DKIM (message authentication), DMARC (the policy that ties them together and decides the fate of unauthenticated mail), BIMI (the brand logo in the inbox) , MTA-STS (inbound transport encryption) and DNSSEC (the signature on the DNS zone where all the others are published). The grade reflects EFFECTIVE protection against spoofing, not the amount of configuration published: without an enforced DMARC policy (“quarantine” or “reject”), SPF and DKIM do not protect the visible sender — so the grade stays low until DMARC is hardened.
Worth remembering — DMARC enforcement weighs the most: at “p=none”, the grade is capped. Moving to “quarantine” then “reject” is the number-one lever to raise it.
How the grade is computed
The checker reads the public DNS records of the six signals and fetches the standardized public policy files (MTA-STS) through a guarded fetch (anti-SSRF, bounded body). It derives a posture score, converted into an A-to-F grade. DMARC enforcement weighs the most: at “p=none” the grade is capped, because only an enforced DMARC blocks spoofing of the visible “From” header. It reads only public data — nothing is modified.
Frequently asked questions
- What does the grade measure?
- Effective protection against spoofing, not the volume of configuration. It is driven mainly by DMARC enforcement: SPF and DKIM without an enforced DMARC do not protect the visible “From” header. A or B = solid, C = to reinforce, D or F = exposed.
- Does the scorecard change anything?
- No. The checker reads only public data: DNS records and standardized policy files meant to be fetched. Nothing is modified.
- Where to start to improve the grade?
- With DMARC enforcement: moving the policy from “none” to “quarantine” then “reject” is the biggest lever. Each dimension of the result links to its dedicated checker for the details.
The domain's email posture, graded
Grade my domainFree and instant — reads public DNS, no account required.
