Anyone can send an email that looks like it comes from your company.
The Email Source Map checks the tools that already send as you, like your invoicing, CRM and newsletter, so you can stop the fakes without stopping your own invoices.
See the Email Source MapHow it works
- 1
Send one test email from each tool
Your invoicing software, your CRM, your newsletter, your booking system. Nothing to install, no access to your accounts.
- 2
See which ones pass
Green or red for each tool, exactly as the receiving side sees it.
- 3
Fix the red ones
You get the next step for each one that fails, matched to your DNS host and your tool.
We never touch your DNS. One payment, no subscription.
For your IT person
"But we have SPF." Why that is not enough
- SPF checks a hidden return address, not the From line your client sees. A fake can pass SPF on the sender's own domain and still put your domain in that From line.
- DMARC is the rule that looks at that visible From line and ties it to SPF or DKIM.
- While that rule says p=none, the fake is still let through. p=quarantine or p=reject is what tells Gmail and Microsoft to junk it or refuse it.
"We have SPF" means the guest list exists. It does not mean nobody can pretend to be us.
Why not switch DMARC to reject tonight? Because your invoicing tool, CRM, newsletter and booking system also send as you. Block before you know that list, and your own mail is refused, with nothing in your mailbox to tell you. The Source Map gives you that list, tool by tool, for the tools you test.
We never see your mailbox. We only see the test messages you send us and your DNS, which is already public.
The full explanation: your domain has an SPF record, and anyone can still send as you →