Skip to content
Signet

Message check

Send us a message. We’ll tell you what receivers saw.

Real cryptographic verification against the actual signature, SPF evaluated against the IP that connected, and DMARC alignment. Not an inference from your DNS. The result of an actual delivery.

How it works

  1. 01

    We generate a one-time address

    Nobody else can send to it, and it expires after use.

  2. 02

    Send a message to it

    From the system you want to test: your mail server, your CRM, your invoicing tool.

  3. 03

    Results appear here

    Usually within a few seconds of the message arriving.

What this catches that a DNS check cannot

A DNS check proves your configuration is plausible. Sending an actual message proves it works.

Messages modified in transit
If a gateway rewrites links or a mailing list appends a footer, the body hash breaks while the signature stays valid. We show which one failed, because they mean completely different things.
The l= tag
A signature covering only the first N bytes of the body lets an attacker append content and keep a valid signature. It is invisible to a DNS check.
Alignment, not just authentication
A DKIM signature can verify perfectly and still do nothing for DMARC, because the signing domain does not match the From header.
Display-name spoofing
Most clients show only the display name, which is where an address that is not yours can hide.