See what an attacker sees
Over 40 checks across email, web and TLS, DNS, look-alike domains and exposed services. Each finding says what it means for you, in plain English.
OuterMark checks your email, website and DNS from the outside, scores what it finds out of 100 and explains it in plain English. Then we fix it, and keep it fixed.
What you get back
This is a free report for a made-up domain. Yours takes about 30 seconds, and the score appears on this page.
Security score · harbourview.example
Weak
7 findings need attention.
✓ Complete · 40 of 40 checksBy area
DMARC is set to watch only, so a fake invoice from this address would reach the inbox.
TLS 1.0 is still switched on. Browsers dropped it years ago.
A domain one letter away is registered to someone else, with mail switched on.
What OuterMark does
Nothing to install and no access to hand over. OuterMark reads what is already public about your domain: the same things an attacker reads first.
Over 40 checks across email, web and TLS, DNS, look-alike domains and exposed services. Each finding says what it means for you, in plain English.
Managed DMARC takes your domain from watching (p=none) to refusing fakes (p=reject) in approved steps, so real email keeps arriving on the way.
Every service sending email as your domain gets a name: Microsoft 365, your newsletter tool, your accounts software. The ones that fail get step-by-step fixes.
Email impersonation, explained
Anyone can type your domain into the From line of an email. Three DNS records decide whether the receiving server believes them.
A criminal puts your domain in the From line and sends a fake invoice from a server you have never used.
Before delivering, Microsoft 365, Gmail or whoever receives it looks up your SPF, DKIM and DMARC records.
With DMARC at reject, the fake is refused. With DMARC at none it is delivered, and all you get is a report.
Why now
Since February 2024
Gmail and Yahoo require SPF, DKIM and a DMARC record from bulk senders: at Gmail, anyone sending 5,000 or more messages a day.
Sources: Google, email sender guidelines; Yahoo, sender best practices.
Since 5 May 2025
Microsoft requires SPF, DKIM and DMARC from anyone sending 5,000 or more messages a day to Outlook.com, Hotmail and Live. Mail that fails is rejected.
Sources: Microsoft, Outlook's new requirements for high-volume senders; Microsoft, error 550 5.7.515.
31 March 2026
The NCSC retired its free Mail Check and Web Check services and advised organisations to use a commercial product.
Ways in
Flat prices in pounds. Nothing is metered by how much email you send.
Free
A score out of 100 and what it means, in about 30 seconds.
Run free check£50one-off, per domain
Every finding with its fix, in priority order, as a PDF you keep.
What is in it Recommended£99a month
We host your DMARC record and walk it to reject, one approved step at a time.
How it worksQuoted
Every client domain in one console, under your brand. One invoice.
Partner programmeFor MSPs and IT providers
Put a whole book of clients on managed protection with one bulk request. Your clients see a portal that wears your name, logo and colours. Our engineers do the DMARC work behind it.
Our research
We scanned 200 English housing associations on 12 June 2026. Those 79 could have been impersonated in phishing emails sent to their own tenants.
Read the housing reportHonest by design
A check that cannot finish says unknown. Every score says how complete its scan was.
No DMARC policy tightens on its own. Every step waits for an engineer to approve it.
Leave, and we hand back your DMARC record with the exact text to publish in its place.
This site and our portal are held to the same checks we run on yours.
About 30 seconds. No account. Nothing to install.
PASSIVE CHECKS ONLY · READS PUBLIC RECORDS · NOTHING TO INSTALL