SPF
We check whether an SPF record exists, whether it includes obvious providers and whether the all mechanism is strict or soft.
A focused check for the three core email authentication controls that reduce domain spoofing, phishing and fake invoice risk.
SPF tells receivers which servers may send mail for your domain. DKIM helps prove that messages were signed by an approved sender. DMARC tells receivers what to do when SPF or DKIM does not align. Together, they make domain spoofing harder and give your business better evidence when investigating phishing or fake invoice messages.
We check whether an SPF record exists, whether it includes obvious providers and whether the all mechanism is strict or soft.
We check common selectors and any selector values you provide from your email provider.
We check whether DMARC exists, whether it is p=none, quarantine or reject, and whether reporting is configured.
We explain why changing DMARC too aggressively before confirming senders can break legitimate mail.
This check is for a business owner, domain administrator or IT provider who needs a written view of one business email domain before making DNS changes. Provide the email domain, known mail provider and any DKIM selector supplied by that provider. You receive record evidence, a plain-English risk explanation and prioritised recommendations in the Starter PDF report.
For the wider record set, see the email domain security review.
Example record summary: "SPF: present; DKIM: selector not verified from supplied information; DMARC: monitoring policy. Priority: medium. Next step: obtain the active DKIM selector from the provider, confirm all legitimate senders and review DMARC reports before enforcement."
ScanLens can review records and recommend wording, but the final DNS change must be made in the account that controls your domain DNS. For DKIM, the correct selector normally comes from your mail provider.
The Starter review covers one business, one public website and one email domain, including SPF, DKIM and DMARC evidence. Delivery is within 2-3 business days after complete information and scope confirmation.
Choose Business Protection if you want the technical check plus a staff workflow for suspicious emails and fake invoices.
No. The standard review does not include DNS access or implementation. Recommendations can be passed to the person who controls the domain.
No. The report is a time-specific public-record review and not a guarantee against phishing, impersonation or delivery problems.
It is included in the £99 Starter review. Prices shown are the total prices. No VAT is currently charged.
Yes. Use the Business enquiry form and send only the public selector name, domain and provider, not credentials.