Evidence-based. Not a questionnaire. Only the domain you enter leaves your browser, as a DNS query to Cloudflare's public resolver.
All checks run in your browser or on your machine. The email check sends only the domain you enter, as DNS-over-HTTPS queries to Cloudflare's public resolver. No telemetry, no cookies, no accounts.
Tier A
Email Security Check
Enter your domain. We'll check SPF, DMARC, and DKIM configuration using public DNS lookups. Nothing is sent to our servers — the queries go directly to DNS.
SPF Record
Specifies which mail servers can send email on behalf of your domain.
Checking...
DMARC Policy
Tells receivers what to do with unauthenticated email. p=reject is the goal.
Checking...
DMARC Enforcement
p=none means monitoring only. p=quarantine or p=reject means enforcing.
Checking...
MX Records
Mail exchange servers for your domain.
Checking...
Tier B
Command Checks
Run a command on your machine, paste the output below. The page interprets it locally in your browser — nothing is sent anywhere.
MFA Exception Count
How many users are excluded from Conditional Access MFA policies? Each exception is an attack surface.
Default is 20MB — overwrites in hours on a busy server. Should be 1GB+ (1073741824 bytes).
wevtutil gl Security | findstr maxSize
Results
Your Score
—
Complete checks above to see your score
Breakdown
What this score means: This checks a handful of the most critical settings from the Configuration Drift playbook — the ones that show up in 59-84% of real breaches. It's not comprehensive. Run CISA ScubaGear for a full M365 assessment, or PingCastle for Active Directory.