SPF, DKIM, and DMARC checker for client domains
Pentestr checks whether client domains have the email security records needed to reduce spoofing and phishing risk.
Agencies, MSPs, and technical teams managing client domains and DNS.
Email authentication records are often skipped during website launches, migrations, and DNS changes.
A quick view of SPF, DKIM, and DMARC posture alongside the website security report.
Website launches often touch email risk
A new domain, DNS migration, or client handoff can leave email records weak or missing, even when the website itself looks finished.
Make DNS security visible
SPF, DKIM, and DMARC checks give agencies and MSPs a simple way to discuss domain spoofing risk with clients.
Bundle email posture with website checks
Pentestr includes email security next to TLS, headers, exposed services, WAF, and CVE findings so the client gets one external report.
What Pentestr checks
Questions
Does Pentestr validate all possible DKIM selectors?
Pentestr checks common DKIM selectors and reports what it can validate from public DNS.
Why check email records in a website security scan?
Clients often treat the domain, website, and email identity as one trust surface. Weak email records can enable spoofing even if the website is healthy.