← oxone.ca
Free · nothing to install

Can anyone spoof your business email?

Most small businesses fail this and nobody has ever told them. Type your domain. In a few seconds you'll know whether a stranger can send an email that lands in your customer's inbox looking exactly like it came from you — the trick behind almost every fake-invoice scam.

The lookups happen in your browser and go straight to public DNS resolvers. The domain you type is never sent to us, and nothing is stored.

Having SPF is not the same as being protected.

This is the part almost everyone gets wrong, including a lot of IT providers. SPF authenticates the envelope sender — the hidden address a receiving server sees during delivery. The From: line you actually read in Mail or Outlook is a completely different field, and SPF says nothing about it.

So a forger can pass your SPF check perfectly, using their own domain in the envelope, while writing [email protected] in the From: line. Only DMARC ties the two fields together and tells the receiving server what to do when they disagree. That is why this page's verdict is driven by your DMARC policy and not by whether SPF exists.

Asked and answered.

Why does this matter for a small business?

Invoice fraud. Someone emails your customer, as you, with new banking details — or emails your bookkeeper, as the owner, asking for a transfer. It costs nothing to attempt and it works because the mail genuinely arrives looking like yours.

Should I go straight to p=reject?

No, and any tool that tells you to is going to break your mail. Start at p=none with a reporting address, read a few weeks of reports to find every service that legitimately sends as you — invoicing, newsletters, the booking system, your CRM — and authorise those first. Then tighten.

You said you can't see my domain. Really?

Really. There is no server involved: the page asks Cloudflare's and Google's public DNS resolvers directly from your browser. You can watch it in the Network tab. Nothing is logged because there is nowhere for it to be logged to.

What about DKIM — why is it vaguer than the rest?

Because DKIM keys live at a name only you know: selector._domainkey.yourdomain. There is no way to list them from outside, so this page tries the two dozen selector names the common providers use. Finding none is not proof you have no DKIM.

Want it fixed rather than explained?

We do this for Calgary businesses, in an afternoon, and you keep the records — no subscription, no lock-in. If your check came back red, that is the whole job.

Book a call →
© 2026 Ox One Consulting Inc. · Calgary, Alberta The long version → · oxone.ca