Pentestr
Security check

SPF, DKIM, and DMARC checker for client domains

Pentestr checks whether client domains have the email security records needed to reduce spoofing and phishing risk.

Audience

Agencies, MSPs, and technical teams managing client domains and DNS.

Pain

Email authentication records are often skipped during website launches, migrations, and DNS changes.

Outcome

A quick view of SPF, DKIM, and DMARC posture alongside the website security report.

Website launches often touch email risk

A new domain, DNS migration, or client handoff can leave email records weak or missing, even when the website itself looks finished.

Make DNS security visible

SPF, DKIM, and DMARC checks give agencies and MSPs a simple way to discuss domain spoofing risk with clients.

Bundle email posture with website checks

Pentestr includes email security next to TLS, headers, exposed services, WAF, and CVE findings so the client gets one external report.

What Pentestr checks

SPF TXT record
DMARC policy
Common DKIM selectors
Domain-level email spoofing issues
Remediation notes

Questions

Does Pentestr validate all possible DKIM selectors?

Pentestr checks common DKIM selectors and reports what it can validate from public DNS.

Why check email records in a website security scan?

Clients often treat the domain, website, and email identity as one trust surface. Weak email records can enable spoofing even if the website is healthy.

Subscribe on