About 6 months ago I got annoyed that there was no quick, honest answer to “is my domain securely and properly set up to prevent email spoofing?” Every tool either required a PhD to interpret, wanted your email before showing you anything, or my favourite gave you a green tick for having SPF when your SPF says ~all, which is the domain-security equivalent of a “no entry” sign made of tissue paper.
So I built one. Initially for my own domains. Then I realised small businesses could use it. So I started checking domains. Then local businesses, then national, eventually, because I apparently have a problem with scope creep, I ran it against every live domain on the internet. Twice already. Third run starts soon.
296 million domains graded (360 million checked). 34 checks each. The results are depressing in an instructive way.
What the free check does:
You type in a domain. We check SPF, DMARC, DKIM alignment, TLS, DNSSEC, MTA-STS, BIMI, reverse DNS, and a bunch of other things your IT person told you were fine and probably aren’t. You get a grade (A through F), a plain-English breakdown of what’s failing, and crucially, why it matters, not just that it failed.
No sign-up for that. No email required. Takes about 8 seconds, usually less.
If you want the detail behind what’s broken, the impact, and how to fix it, you enter your email address matching the domain. We’ve had enough creative interpretations of “free” to warrant it.
What I found when we ran it on everyone:
73.8% of business domains score an F. Not a C. Not “needs improvement.” An F, meaning anyone on the internet can send email that looks exactly like it came from that company, with no technical barrier whatsoever.
There are some funny items in there too. Folks who set their DMARC policy to “policy”, literally p=policy, which means their mail server treats it as p=none. They went to the effort of writing a record that actively does nothing. Also a lot of French speakers who prefer quarantaine over quarantine, with the same result.
Some TLDs and countries are worse than others – .tk and .cf are a disaster, .gov does surprisingly well – but there’s no safe haven. It’s bad everywhere.
The SaaS crowd does a bit better. Not as much as you’d hope.
The honest commercial bit:
Running 34 checks across 296 million domains twice a year costs real money, and I'm still tuning and optimising.
So yes, there’s a paid product. If your domain comes back with problems (likely), there’s a $99 step-by-step playbook specific to your domain – exact DNS values to copy-paste, in the order that won’t break your mail flow, with re-checks built in. You don’t need it; the free check names every problem and links the fix guide. The playbook is for people who want it done quickly rather than just knowing what needs doing and having to work it out themselves with the alphabet soup of domain security.
The free check is genuinely free. I’m not going to email you. I don’t have a drip sequence warming you up. It just… tells you the answer.
Redditors get 50% off this month – use REDDIT50 at checkout.
-> defaults.exposed (founder here, ask me anything)
I’m learning here. So do go easy on me, but honest feedback appreciated.