Can someone send email as your domain? Two commands will tell you
Most domains are still wide open to spoofing, and the owners have no idea. You can check yours in about thirty seconds with dig, and you don't need to be the person who runs the mail server to do it.
Your DNS records are public. So you can check any domain's spoofing protection without logging into anything, including a supplier's or a customer's.
Here are the two commands.
1. The SPF record
dig TXT example.com +short
Look for the line starting v=spf1. You'll get something like:
"v=spf1 include:_spf.google.com include:sendgrid.net ~all"
The bit that matters is at the end:
-allmeans "if it's not from one of these servers, reject it". This is what you want.~allis a soft fail. It means "probably not us, but deliver it anyway". Most domains sit here.?allmeans nothing at all. Neutral.- No
v=spf1line? You have no SPF record.
2. The DMARC record
dig TXT _dmarc.example.com +short
This is the one that actually counts. You'll get something like:
"v=DMARC1; p=none; rua=mailto:[email protected]"
Read the p= value:
p=reject— forged mail gets thrown away before anyone sees it. This is the goal.p=quarantine— it goes to spam. Fine, not great.p=none— nothing happens. You get reports, and the mail still lands in the inbox.- No record at all — nobody is even checking.
On Windows without dig, use:
nslookup -type=TXT _dmarc.example.com
What you're likely to find
p=none.
That's the honest answer for a huge number of domains, including plenty of ones that should know better. It's where everyone starts, because you turn DMARC on in monitoring mode first so you can find all your forgotten senders before you break them. The invoicing tool, the CRM, the old marketing platform nobody has logged into for two years.
Then the reports come in, fixing the stragglers never makes it onto anyone's sprint, and the domain just stays there. Instrumented, not protected.
If that's you, the work isn't hard. It's mostly boring: read the aggregate reports, find everything sending as you, get each one signing properly, then move to p=quarantine and watch for a couple of weeks before going to p=reject.
Why DKIM isn't in this list
You can't check DKIM from outside without knowing the selector, which is a string the sender picks. It shows up in the headers of mail they've already sent, as s=something, and then you can look up something._domainkey.example.com.
So if you want to check your own DKIM, send yourself a message and read its headers. There's no generic lookup.
One thing worth being clear about
None of this stops someone registering examp1e.com or example.com.billing-update.co and sending from that. Those are different domains. They'll set up their own perfect SPF and DMARC, and every check will pass, because every check will be true.
Domain authentication stops people forging your domain. It does nothing about people registering one that looks like it. Those are two separate problems and only one of them is yours to fix with DNS.
If you want to see how all of this reads on a real message, you can paste one into the phishing email analyzer and it'll lay out what each check concluded. And if you want the longer version of why a passing check is so often about a domain you weren't looking at, that's here.