Email authentication check — SPF, DKIM and DMARC

Email authentication is the control that decides whether somebody else can send mail that appears to come from your domain. It is three records, none of them are hard to publish, and a very large number of domains still publish none of them or publish one in a mode that enforces nothing.

What this page checks

The common failure is a domain with SPF and DKIM configured, a DMARC record sitting at p=none since the day it was published, and nobody reading the reports — which is functionally the same as having no policy while looking like having one.

How it runs

This page is an interactive demonstration of the check rather than a live assessment of your estate — it shows the shape of the finding and how it is presented. For a real, continuous answer across every asset you own, the same check runs inside Maphra.

Where this sits in Maphra

Email authentication is one of the standing checks in Maphra's comprehensive security analysis, run across every asset it discovers rather than the primary domain somebody remembered to test. Parked and secondary domains are the ones that get spoofed, precisely because nobody configures policy on a domain that does not send mail. That connects directly to brand monitoring: look-alike domains and impersonating applications are an attack path against your customers that never touches your infrastructure, and Maphra watches for both.

Questions

Is p=none enough?
It publishes a policy and collects reports, but it instructs receivers to do nothing when authentication fails. It is a useful first step on the way to quarantine or reject, not a destination.
Do domains that never send email need these records?
Especially those. A domain with no mail flow and no policy is the easiest one to spoof, because nothing legitimate will ever break by abusing it.

A one-off check tells you about one asset today. Maphra runs this continuously across everything it discovers, and a walkthrough uses your own domain rather than a sample.