Free Security Tool
Free Domain Security Report Card
Enter a business domain to check its public email authentication, email transport, and website security settings. Get an A-to-F diagnostic grade and a plain-language breakdown of what needs attention.
Check your domain's public security settings
The report card checks SPF, DKIM, DMARC, MX, DNSSEC, MTA-STS, TLS reporting, HTTPS, your TLS certificate, and selected website security headers. For a deeper email-only view, use the SPF, DKIM, and DMARC checker.
- Free to use
- No account required
- No login or mailbox access
- No settings are changed
Based on the public checks included in this tool. This is not a full security audit or certification.
Wolferdawg IT Consulting can verify the findings, prioritize the changes, and help improve your email and website security without rushing risky configuration changes.
Send a copy to your inbox. The submitted contact information, domain, grade, score, and report results are also sent to Wolferdawg IT Consulting and may be retained for direct follow-up about your results and related services. You will not be added to a newsletter or bulk marketing list.
How to read your domain security report
The letter grade summarizes the public checks in three areas. Use the detailed rows to understand what raised or lowered the score instead of relying on the letter alone.
| Report area | What it checks | What the result can tell you |
|---|---|---|
| Email authentication | SPF, DKIM, DMARC, and MX records | Whether expected public records were found and whether the reported configuration meets the tool's checks. |
| Email transport protection | DNSSEC, MTA-STS, and TLS reporting | Whether the domain publishes protections that help secure DNS answers and mail transport. |
| Website security | HTTPS, the public TLS certificate, and selected HTTP security headers | Whether the public website presents the protections included in this scan. |
Pass means the check met this tool's criteria. Needs attention identifies a failed or concerning result. Recommended identifies an improvement that may strengthen the public configuration.
What to address first
- Confirm every finding before making a change. Automated checks can miss custom DKIM selectors and cannot see internal configuration.
- Correct expired certificates or broken HTTPS. These problems can affect website trust and secure connections.
- Fix SPF and enable DKIM for approved email senders. Include Microsoft 365, website forms, invoicing systems, and marketing platforms that send using your domain.
- Publish DMARC with reporting. Begin with p=none, review legitimate senders, and correct alignment problems.
- Move DMARC gradually toward enforcement. Test p=quarantine before p=reject so legitimate email is not blocked unexpectedly.
- Add the remaining transport and website protections. Prioritize them according to the report and how your business uses the domain.
Want help reviewing your domain security report?
Wolferdawg IT Consulting can verify the findings, identify approved email senders, and build a safe remediation plan for your email and website configuration.
Book a 30-minute reviewHow this domain security checker works
The scanner sends the submitted domain to Wolferdawg's report-card endpoint. The endpoint checks public DNS records and information returned by the public website, then returns the individual findings, pillar scores, weights, overall score, and letter grade shown in the report.
Privacy and limitations
Running the scan does not require your name or email. The tool does not sign in to a mailbox, read messages, or change DNS or website settings. The submitted domain is used by the report-card endpoint to generate the results.
If you choose to email the report, the name, business name, and email address you provide, along with the domain, grade, score, and complete report results, are submitted to forms.wolferdawg.io. The report is sent to the supplied address and copied to hello@wolferdawg.io. By requesting the report, you agree that Wolferdawg IT Consulting may retain your contact information and report results and contact you directly about your results and related services. You will not be added to a newsletter or bulk marketing list.
A missing DKIM result can mean the sending platform uses a custom selector. The website checks cover selected public controls and do not replace a vulnerability scan or penetration test. The report does not test passwords, multifactor authentication, computers, software updates, backups, internal networks, or employee security practices.
The A-to-F result is a Wolferdawg diagnostic grade based on the included public checks. It is not a security certification or a guarantee against compromise, spoofing, or delivery problems. Microsoft recommends moving DMARC gradually from p=none to p=quarantine and then p=reject after legitimate senders have been verified. Read Microsoft's DMARC guidance. For website header guidance, see the OWASP Secure Headers Project.
Reviewed by Dieter Wolf, founder of Wolferdawg IT Consulting
27+ years in IT and cybersecurity. Last updated August 25, 2026.
Frequently asked questions about domain security
Plain answers about SPF, DKIM, DMARC, email spoofing, and what your domain security grade means.
What does the domain security report card check?
The report card checks public email authentication records, including SPF, DKIM, DMARC, and MX, email transport protections such as DNSSEC, MTA-STS, and TLS reporting, and website protections such as HTTPS, the TLS certificate, and selected security headers. It combines those checks into a Wolferdawg diagnostic grade from A to F.
Is it safe to check my domain, and what information is used?
The scan reads public DNS records and information returned by your public website. It does not sign in, request a password, read email, or change domain settings. The submitted domain is sent to Wolferdawg's report-card endpoint to generate the results. Name and email are requested only if you choose to email the report.
What does my domain security grade mean?
The A-to-F grade summarizes the public checks included in this tool. A higher grade means more of those checks passed. It is a diagnostic result, not a security certification, penetration test, vulnerability scan, or guarantee that the business cannot be compromised.
What is the difference between SPF, DKIM, and DMARC?
SPF lists approved sending systems. DKIM adds a digital signature that lets receiving systems verify a message and detect changes. DMARC checks whether SPF or DKIM aligns with the domain shown in the From address and publishes a requested policy for messages that fail.
What do DMARC policies of none, quarantine, and reject mean?
A p=none policy requests no DMARC-specific action and is used for monitoring. A p=quarantine policy asks receiving systems to treat failing messages as suspicious. A p=reject policy asks them to reject failing messages. The receiving system controls the final treatment, so DMARC should be moved toward enforcement gradually after legitimate senders are verified.
Can someone spoof my business domain?
The visible From address in an email can be forged. SPF, DKIM, and DMARC help receiving systems identify messages that are not properly authenticated or aligned. An enforced DMARC policy reduces direct domain-spoofing risk, but it does not stop lookalike domains, compromised legitimate accounts, or every form of impersonation.
Does a missing DKIM result prove DKIM is disabled?
No. DKIM records use selector names chosen by each sending platform. The report card checks common selectors, but a provider may use a custom selector that the automated scan cannot discover. Confirm a missing result inside the sending platform before changing DNS.
What does the report card not test?
The report card does not test passwords, multifactor authentication, endpoint protection, software updates, backups, internal network security, employee security awareness, or vulnerabilities that are not visible through the included public checks. It also cannot guarantee email delivery or prove that every legitimate sender passes DMARC.
Want a plain-English explanation of every term on your report card? Read the domain security glossary.