Skip to content

Free tools

Business Email Trust Check

Review passive public email and domain signals without supplying an email address, password, or mailbox access.

Passive public DNS check

Check the domain's public email-trust signals

Enter a business domain only. No email address, mailbox access, password, or message content is required.

Domain names only. Paths, ports, credentials, internal hosts, and IP addresses are rejected.

Check one provider-confirmed selector at a time. Replace it to test another confirmed sending service.

Results are not gated by email. The domain and findings are not attached to browser analytics events.

What this tool checks

  • - Mail exchange (MX) presence
  • - SPF presence, multiple-record concerns, obvious syntax, and overly permissive all mechanisms
  • - DMARC policy, percentage, and aggregate-reporting destination presence
  • - MTA-STS DNS marker, canonical HTTPS policy syntax, mode, and current MX applicability
  • - TLS-RPT public DNS configuration
  • - DNSSEC DS-record visibility
  • - DKIM only when a known selector is supplied

Scope and limitations

  • - No mailbox, message, credential, private system, port, or login access
  • - No universal DKIM discovery; selectors need provider confirmation
  • - A valid MTA-STS policy does not prove every sender supports it or that transport reports are reviewed
  • - No guarantee of deliverability, spoofing prevention, or protection
  • - No overall cyber-risk rating, compliance determination, or active testing
  • - Public DNS can be stale, delegated, split, or temporarily unavailable

Privacy and methodology

The tool sends the normalized public domain to CyberBit's same-origin API for bounded public DNS lookups. When a valid MTA-STS marker is found, the server may make one bounded request to the fixed canonical policy file at the domain's public mta-sts hostname. It does not accept a visitor-supplied URL or follow redirects. The existing resolver can use Google Public DNS over HTTPS as a fallback when local DNS resolution fails, so Google may receive the queried public domain in that case. The canonical policy host receives a standard HTTPS request and may retain ordinary access logs. The tool does not ask for an email address or attach the domain or findings to browser analytics events. No port scanning, exploitation, brute force, credential checks, message access, or mailbox access occurs.