⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Back to all articles
Email Security8 min read

How to Tell If Someone Is Spoofing Your Domain Right Now

One of the most unsettling things I tell business owners is that someone might be impersonating their business via email right now, and they’d have no idea. Here’s how to check, right now, using free tools.

Step 1: Check Your DMARC Record

Go to MXToolbox (mxtoolbox.com) and use the DMARC lookup tool. If the lookup returns “No DMARC record found,” your domain has no protection. Anyone can spoof it. If it says p=none, you’re in monitoring mode. Only p=quarantine or p=reject provides enforcement.

Step 2: Check Your SPF Record

Run an SPF lookup. A missing or misconfigured SPF record is an open door for spoofing. Check it includes all services that legitimately send email for your domain, and ends in -all (hard fail) rather than ~all (soft fail).

Step 3: Check Your DKIM Configuration

In the Microsoft Defender portal, navigate to Email Authentication Settings → DKIM. If DKIM shows as disabled, your emails are not being cryptographically signed.

Step 4: Review DMARC Aggregate Reports

If you have DMARC configured with a reporting address, use a free DMARC reporting tool to parse the XML. Look for email sources you don’t recognise. That’s a sign your domain may be being spoofed.

Step 5: Check Breach and Abuse Databases

Google Postmaster Tools and abuse.ch can give you intelligence about your domain’s sending reputation and whether it has been associated with spam or phishing campaigns.

What to Do If You Find a Problem

  • Ensure SPF is correctly configured with all legitimate sending sources
  • Enable and verify DKIM in Microsoft 365
  • Publish a DMARC record if one doesn’t exist
  • Review aggregate reports to identify illegitimate sources
  • Progress to DMARC enforcement (p=quarantine then p=reject)

Want a professional review of your email authentication?

or call 0403 401 250