DMARC · TLS-RPT · BIMI · SPF · MTA-STS
Know who's sending email as your domain.
Spoofhound turns the DMARC and TLS reports your domains already generate into a clear picture: who's sending legitimately, who's spoofing you, and exactly what to do next — all the way to full enforcement.
No card, no agents, nothing to install — just DNS.
Anyone can put your domain in the From line.
Until DMARC is enforced, receivers deliver mail that merely claims to be you. The reports that reveal this — DMARC aggregate, forensic, and SMTP TLS reports — arrive as zipped XML and JSON that nobody reads. Spoofhound reads them for you, every day, and only speaks up when something needs a decision.
What the reports reveal
- ✓ Legitimate senders passing authentication
- → Forwarders breaking SPF in transit (normal, explained)
- ✗ Unknown sources spoofing your domain right now
- ✗ Mail servers silently failing to negotiate TLS
Fight back against Business Email Compromise
Understand where Spoofhound fits in the fight against business email compromise
DMARC enforcement closes the exact-domain forgery route — the cheapest one for an attacker, and the only one you can shut completely — and shows you spoofing attempts as they happen. The page is honest about what that does and doesn't stop, and what to layer on top.
Read the honest pageEverything in one place
Monitoring that tells you what to do,
not just what happened.
Triage-first dashboard
Open to a queue of things needing attention — not a wall of charts. Every alarm ships with a runbook line: what it means and what to do about it.
Spoofing detection
New sending sources are baselined automatically; a brand-new IP failing alignment — the classic spoofing signature — pages you the same day.
Enforcement wizard
The codified path from p=none to p=reject: a 98% aligned-pass gate over a rolling window, plus an "all sources explained" check, with a staged recommendation.
TLS-RPT health scores
Every domain graded A–F on its mail-transport security: MTA-STS mode as receivers observed it, DANE evidence, and failure rates with severity tiers.
Hosted BIMI & MTA-STS
We host the files senders and mailbox providers actually fetch — your BIMI logo, validated against the SVG profile, and your MTA-STS policy, with its certificate issued and renewed for you. You publish one DNS record.
Alerts with a lifecycle
Alarm → reminder → resolved, with suppression so a known problem doesn't page you daily — plus a Monday digest of the week that actually reads well.
Senders and DKIM, inventoried
Every sending identity seen in your reports, classified legitimate, forwarder, misconfigured or malicious — and every DKIM selector signing your mail, so you can tell your own signature from a provider's.
Send-only domains understood
A domain with no MX — or a null MX — is never nagged about TLS-RPT or MTA-STS, which cannot apply to it. Mail flow is shown per domain, so a parked or send-only name is judged on what it actually does.
Sign-in worth trusting
Passkeys — fingerprint, face or PIN — plus authenticator apps, with no password to phish or reuse. Account admins can see and manage the sign-in methods their members hold.
Business email compromise, honestly
DMARC enforcement closes the exact-domain forgery route — the cheapest one for an attacker, and the only one you can shut completely — and shows you spoofing attempts as they happen. What it does and doesn't stop: the honest page.
AI analysis, bring your own model
A ranked action plan for each domain, written by the AI model you choose — on your own key and your own provider agreement. Every claim must cite Spoofhound's own computed facts, and Spoofhound never touches DNS. The models it works with.
Live DNS at a glance
Hover any DNS record anywhere in the dashboard to see what it resolves to right now, rather than what it looked like at the last overnight check.
How it works
Live in three DNS records.
Pick a region, verify your domain
Your account is created in the jurisdiction you choose. Then publish one TXT record to prove ownership — a domain belongs to exactly one account, always.
Point your reports at us
The Setup page shows your current DMARC and TLS-RPT records with your region's report addresses appended — copy, paste, done. Runs happily alongside any existing report processor.
Get answers, not XML
Reports typically start within a day. Dashboards fill, alarms guard, and the wizard tells you when you're ready to enforce.
Already have history with another processor? Upload your old report emails and files — Spoofhound backfills months of data in minutes.
AI analysis · bring your own model
An action plan, written by the model you choose.
Turn it on per domain and Spoofhound turns everything it already knows — your reports, alarms, DNS records and scores — into a ranked plan: what to do, in what order, and what looks alarming but is safe to ignore. On your own AI provider account and key, under your own agreement and spend limits — or with no key at all.
Anthropic
Claude Sonnet 5 and Claude Haiku 4.5.
OpenAI
GPT-5.6 Terra and GPT-5.6 Luna.
Gemini 3.7 Flash and Gemini 3.5 Flash-Lite.
Kimi
Kimi K2.6 and Kimi K2.5, by Moonshot AI.
OpenRouter
One key, their whole catalogue — access to 500+ models from every major lab.
Built in, no key needed
Open models running on Cloudflare's own AI infrastructure — GPT-OSS 120B and Llama 3.3 70B — if you'd rather not bring a provider account at all.
Guardrails, not vibes
- ✓ Every claim must cite facts Spoofhound computed itself — anything the model can't back up is discarded before you see it.
- ✓ Every proposed DNS record is re-checked by the same parsers the rest of the product trusts, before it's shown.
- ✓ Spoofhound never changes DNS. You get a copyable record, nothing more.
- ✓ Your key is stored encrypted and write-only — shown as its last four characters, never readable back.
- ✓ Nightly re-analysis skips domains where nothing changed, so no money is spent on no news. Every run records what it cost.
Where your data lives
Pick your jurisdiction. It stays there.
Spoofhound runs as separate, self-contained deployments — one per jurisdiction. Your account lives on exactly one of them, and its reports never leave it.
Separate, not partitioned
Each jurisdiction is its own deployment with its own database, its own dashboard address and its own report inbox. Not one system with a country column — nothing is shared between them and nothing replicates across.
No central directory, by design
There is deliberately no global index of who is hosted where. Building one would mean holding a record of every EU customer outside the EU — the exact thing the split exists to prevent — so when you sign in, you tell us your region rather than us looking you up.
Available now
EU1 · European Union
For domains that need their report data to stay inside the EU.
ROW1 · Rest of world
For everyone with no EU residency requirement.
Need a specific jurisdiction we don't run yet? Say so when you sign up — it is how we decide which to build next, and an instance can move to its own region once one is available there.
No signup needed
Nine free tools, right now.
Before you're a customer, use these to check your own setup — or a domain you're curious about.
Website security scanner
Scan any site's HTTPS, security headers, CSP, cookies, exposed files, DNSSEC, CAA and security.txt out of 100.
HTTP security header check
See a site's live HTTP response headers and a plain-English read on the security-relevant ones.
Domain spoofing & branding check
Score any domain's SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, VMC and logo setup out of 100.
Email send test
Test an SMTP server or a sending API with a live, streamed conversation and a clear pass/fail.
Inbox test
Get a one-time address, send it a test email, and see its authentication status and deliverability score.
DMARC record check
DMARCbis analysis of any record — deprecated tags, policy gaps and unverified report destinations, all explained.
SPF record check
Walk a whole SPF include chain and see its RFC 7208 lookup count, void lookups and permerrors.
Email header analyser
Drop in an email for its authentication results, alignment and full delivery path — parsed in your browser, never uploaded.
DNS lookup
Look up any A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, SRV or DS record and see what it resolves to right now.