Skip to content
Chinron
Free tool · no signup

Can someone send email pretending to be you?

Paste your domain. We check your public SPF, DMARC, DKIM and mail records the same way a spammer would, and tell you exactly what to publish to close the gap.

Free, instant, and runs in your browser — we don't see your domain unless you ask us to send a report.

Why this matters

SPF and DMARC are the two DNS records that tell other mail servers which systems are allowed to send email as your domain, and what to do with anything that isn't. Most domains that get impersonated in phishing don't have anything wrong with their security software — they simply never published these records, or published them in monitor-only mode.

Because it's public DNS, anyone can check it — including whoever is about to send a phishing email pretending to be your finance team. This tool runs the same check they would, so you see it first.

The check happens entirely in your browser against Cloudflare's public DNS resolver. We don't log which domain you typed, and nothing is sent to us unless you choose to request the report below your result.

DNS records are one gap. Untrained staff are the bigger one.

Chinron trains your team to catch the phishing emails that get through anyway — simulated campaigns, human risk scoring, and training content localised to your industry and region.

Book a demo