Find out in seconds. We check the three critical settings that stop criminals from sending fake emails using your company's name — the same trick behind 91% of cyberattacks.
Testing your domain for impersonation vulnerabilities...
Cyvatar configures and monitors your email impersonation protection automatically — so hackers can never send email as your company.
Talk to an Expert →This is exactly what happens when someone impersonates your company — step by step.
They choose your company's email address — ceo@yourcompany.com — and set it as the "From" address. They don't need your password. They don't need access to your account. Just your domain name.
From a random server anywhere in the world, they send an email that looks exactly like it came from you — to your customers, employees, or vendors. It might say "Please wire payment to this new account" or "Click here to reset your password."
Gmail, Outlook, or whatever the recipient uses looks up three records on your domain — SPF, DKIM, and DMARC — to see if the email is really from you.
What happens next depends entirely on whether you have email protection set up.
The recipient has no idea it's not really from you.
The receiving server sees the email is unauthorized and stops it.
The victim thinks your company sent them a phishing email, a fake invoice, or a malware link. Even after they realize it's fake, the trust is broken — and your brand takes the blame for an attack you didn't even know happened.
Everything you need to know about SPF, DKIM, DMARC, and protecting your domain.
v=spf1 -all — no servers are authorizedv=DMARC1; p=reject — reject all unauthenticated emailv=spf1 include:_spf.google.com ~allv=spf1 include:spf.protection.outlook.com ~all-all (hard fail) for strict enforcement or ~all (soft fail) while testing. You can only have one SPF record per domain.selector._domainkey.yourdomain.com. Common selectors include "google", "selector1", "selector2", or "default"._dmarc.yourdomain.com. Start with monitoring mode:v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.comp=quarantine (sends failures to spam) then p=reject (blocks failures entirely). Always include a rua= tag so you receive aggregate reports.