The domains anyone can forge email from
Around 84% of domains have no enforcing DMARC — the DNS record that tells the world “reject email that isn’t really from me.” Without it (or with the monitor-only p=none), anyone can send email that looks exactly like it came from the domain: phishing its customers, invoicing its finance team, impersonating its brand. We measure this passively over public DNS — no mail sent, nothing connected to.
What the radar is seeing
Why this matters
SPF and DKIM aren’t enough on their own — only an enforcing DMARC policy stops someone forging the visible From: address your recipients actually see:
- • Business Email Compromise & invoice fraud — attackers email your finance team or customers as you, and the messages land in the inbox.
- • Phishing that passes every visual check — the sender domain is genuinely yours; there’s nothing for a user to spot.
- • Even domains that send no email are at risk — a parked or product domain with no DMARC can still be impersonated.
The fix is free and DNS-only: publish a DMARC record and move it to p=reject.
By TLD — where it's worst
- .com669,182 spoofable of 802,971 (83%)
- .ph106,335 spoofable of 106,453 (100%)
- .xyz65,509 spoofable of 67,943 (96%)
- .net57,616 spoofable of 66,391 (87%)
- .org55,860 spoofable of 65,082 (86%)
- .de48,647 spoofable of 55,809 (87%)
- .dev35,030 spoofable of 36,210 (97%)
- .uk34,383 spoofable of 42,468 (81%)
- .br23,604 spoofable of 27,539 (86%)
- .top19,002 spoofable of 22,912 (83%)
- .ru18,703 spoofable of 20,197 (93%)
- .to15,860 spoofable of 15,888 (100%)
Are you exposed?
Check whether your domain can be spoofed — a free, passive look at your SPF/DMARC posture and the rest of your internet-facing surface, no signup.
Check your exposure →How it works
How do you check this without sending email?
Purely from public DNS. We resolve the domain’s TXT record for SPF, its _dmarc TXT record for DMARC, and its MX records — the same lookups any mail server makes. We never send mail, connect to anything, or log in.
When do you call a domain “spoofable”?
When there is no DMARC record, or DMARC is set to p=none (monitor-only, no enforcement). Those are the cases where forged mail is actually delivered. p=quarantine we count as partial; p=reject as fully protected.
Why don't you list the spoofable domains?
Publishing them would be a ready-made target list for phishers. We keep domain names private for responsible disclosure to the owners and publish only aggregate counts. Use the scanner above to check your own domain.
EchelonGraph-<Radar>/1.0 (+echelongraph.io/responsible-disclosure; [email protected]) and a From: [email protected] header. It is a single, minimal check — we never log in, exploit, or read your data. Confirming an MCP endpoint or an exposed datastore needs a protocol-level exchange rather than a plain GET; on Redis our client names itself so the connection is identifiable in your own CLIENT LIST. Who we are, exactly what each check sends, and how to opt out → Genuine requests also carry a signed receipt you can validate at /verify-scan.