Skip to content
Burger Tech

Free tool · Stay safe

Can scammers fake your business email?

Enter your domain or work email to check the three settings that stop fake email in your name, and get the exact fix. Free, no signup.

Only the part after the @ is checked. Nothing is saved.

  • SPF · DKIM · DMARC
  • Google Workspace · Microsoft 365
  • Exact records to add

This check reads public DNS records and looks for common setups. It can't see inside your email account. For a full review, have an IT professional look at your email settings.

How it works

  1. 01You enter your domain, or your work email and we take the part after the @.
  2. 02We read the domain's public email records, the same ones every inbox reads before it delivers a message.
  3. 03We check three settings: SPF (who may send your email), DKIM (a digital signature) and DMARC (what inboxes do with fakes).
  4. 04You get a verdict, what each setting means in plain English, and the exact record to add for your email provider.

How to stop scammers from faking your business email

By Jhonny Perez
Last checked October 5, 2026

Email was built without a way to prove who sent a message. Anyone can type your address into the "From" line, the same way anyone can write your return address on an envelope. Three DNS records fix that: SPF, DKIM and DMARC. Here's what each does, and the order to set them up.

What the three records do

  • SPF is a list of the servers allowed to send email for your domain, like your email provider, newsletter tool and invoicing app.
  • DKIM adds a hidden digital signature to every email you send. Inboxes check it to confirm the message really came from you and wasn't changed.
  • DMARC tells inboxes what to do when an email claiming to be from you fails both checks: deliver it anyway (p=none), send it to spam (p=quarantine) or reject it (p=reject).

SPF and DKIM help inboxes spot a fake. Only DMARC tells them to stop it. That's why the checker above won't say "Protected" until DMARC is set to quarantine or reject.

Step 1: Set up SPF

Add one TXT record at the root of your domain (often shown as "@" in your DNS settings). Your email provider publishes the exact value:

If other services send email as you, add each one's "include" to the same record. Two rules trip people up: a domain can only have one SPF record, and it can need at most 10 DNS lookups in total (each "include" counts). Break either rule and SPF stops working for everyone.

Step 2: Turn on DKIM

DKIM is switched on inside your email provider, which then gives you a record to add to DNS:

  • Google Workspace: Admin console → Apps → Google Workspace → Gmail → Authenticate email (Google's guide)
  • Microsoft 365: the Microsoft Defender portal's DKIM settings (Microsoft's guide)

Newsletter and marketing tools have their own DKIM setup, usually under "domain authentication" in their settings.

Step 3: Add DMARC in watch mode

Add a TXT record named _dmarc with a policy of none and an address for reports:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com

Nothing gets blocked yet. Instead, inboxes like Gmail and Outlook send daily reports showing every server sending email as your domain. Use them to find services you forgot, and add those to SPF and DKIM.

Step 4: Turn on protection

After 2 to 4 weeks of clean reports, change p=none to p=quarantine, so fakes go to spam. Once that's quiet too, move to p=reject, so fakes are refused outright. This last step is what actually protects your customers and vendors from emails pretending to be you.

You may see older guides use pct= to phase protection in gradually. The updated DMARC standard, RFC 9989, dropped it in 2026, so step from none to quarantine to reject instead.

Got a domain you don't use for email?

Lock it down too. Scammers like unused domains because nobody watches them. Two records do it: an SPF record of v=spf1 -all (no server may send) and a DMARC record of v=DMARC1; p=reject;.

Why this matters now

Since February 2024, Gmail requires every sender to use SPF or DKIM, and businesses sending more than 5,000 emails a day to Gmail need SPF, DKIM and DMARC. Even below that, authenticated email lands in the inbox more often, and a DMARC policy is the one setting that stops invoice scams sent in your name.

Common questions

What are SPF, DKIM and DMARC?

Three DNS records that prove your email is really from you. SPF lists the servers allowed to send it, DKIM adds a digital signature, and DMARC tells inboxes what to do when an email fails both: deliver it, send it to spam, or reject it.

Why does DMARC matter so much?

SPF and DKIM only help inboxes spot a fake. DMARC is what tells them to stop it. Without a DMARC policy of "quarantine" or "reject", most fake emails using your domain still get delivered.

Will turning on DMARC block my real email?

Not if you go step by step. Start with "p=none", which only reports, and use the reports to make sure every service that sends for you (your email, newsletters, invoicing, your website) passes SPF or DKIM. Then move to "p=quarantine" and "p=reject".

Does Gmail require DMARC?

For businesses sending more than 5,000 emails a day to Gmail, yes: since February 2024, Google requires SPF, DKIM and a DMARC record. Every sender needs at least SPF or DKIM. Smaller senders that set up all three get better delivery too.

Why didn't you find my DKIM key?

DKIM keys are stored under a name each email service chooses, and there's no way to list them. We check the names Google, Microsoft and other popular services use. If you use a different one, DKIM may be working fine: your email provider's admin settings will show it.

My domain doesn't send email. Do I need this?

Yes. Scammers like unused domains because nobody's watching them. Two records lock it down: an SPF record of "v=spf1 -all" and a DMARC record of "v=DMARC1; p=reject;". The checker shows you both.

Does "Protected" mean I can't be impersonated?

It means nobody can send email from your exact domain. Scammers can still use a lookalike domain (like yourbusiness-billing.com) or put your name on a free Gmail account, so teach your team to check the sender's full address.

Do you save the domains I check?

No. Your domain is used to look up its public records and isn't stored. If you ask us to email the report, we use your address to send that one email and don't keep it.

Next step

Want it fixed without the guesswork?

Burger Tech sets up SPF, DKIM and DMARC for small businesses, checks every service that sends email for you, and moves you to full protection without losing real email.