RedScore.ai

Free DMARC checker

Check DMARC policy on your domain before spoofed mail lands

See whether your domain enforces email authentication or only monitors abuse.

DMARC at p=none still lets spoofed messages through. RedScore checks public DMARC, SPF, and related email auth signals on your domain in about 60 seconds. Go to /lookup and enter the domain you send mail from.

Scan your domain

Free scan · No signup · Results in ~60 seconds · Opens /lookup

example-corp.com

✓ scan complete · grade D · 4 issues

42/ 100
Grade D

AI summary

DMARC enforcement is missing, which leaves spoofing open. SPF is too permissive. Several key web security headers are absent.

FAILDMARC enforcement
FAILSPF policy strength
WARNWeb headers & TLS hardening
WARNCookie secure flag
PASSGoogle Safe Browsing

Why DMARC matters

Spoofed email is a public DNS problem buyers notice

Questionnaires and deliverability checks often start with DMARC and SPF posture. RedScore shows whether your domain is monitoring only or actually enforcing policy.

Built for email operators

DMARC inside a full email security pass

One scan covers DMARC enforcement, SPF strength, DKIM signals, and the rest of your public footprint.

DMARC policy check

See whether policy is none, quarantine, or reject from public records.

SPF alignment context

SPF strength and lookup-limit signals on the same domain.

Fix-first guidance

Plain English on what failed and what to change in DNS.

Full domain context

Email auth grades sit alongside DNS, TLS, and headers in one RedScore.

What you get

DMARC and email auth grades in one report

You get email category grades, a 0-100 RedScore, and a prioritized fix list across ten public security areas.

C62DNS & Domain Security
D48Email Security
B75Infrastructure Hygiene
C68Web Application Security
F32Cookie & Privacy Hygiene
D45Technology Fingerprinting
B78Public Exposure
A91Certificate & PKI Health
B82Brand & Domain Reputation
C55Third-Party Risk Surface
63/ 100
Grade C

63 / 100

Grade C

example-corp.com

AI summary

Cookie settings are weak and server headers reveal stack details. Email spoofing is plausible with incomplete SPF and DMARC.

Email auth gaps
Header hardening
Certificate hygiene

What RedScore checks today

Public email authentication signals

  • DMARC record presence and policy enforcement
  • DMARC subdomain policy and aggregate reporting signals
  • SPF record presence and policy strength
  • DKIM selector discovery and validation signals
  • MX and null-MX hygiene on the domain

What this does not replace

This is not mailbox deliverability testing or a full phishing simulation. It checks public DNS email authentication records visible from the outside.

After the free scan

Claim your domain for full email findings

Anonymous scans show safe summary grades. Claim the domain to unlock record-level DMARC and SPF detail plus scheduled rescans.

  • Full email authentication finding detail
  • Scheduled scans and change alerts
  • Prove fixes before the next questionnaire

FAQ

Common questions

Check DMARC on your domain

Free scan · No signup · ~60 seconds

Scan your domain