DMARC Engine
Home/Free tools/Bulk Domain Scanner
Free tool · DMARC

Bulk Domain Scanner

Scan a whole list of domains at once for DMARC spoofability.

Paste a list of domains, one per line, to check them all at once. We look up each domain's DMARC record live and flag the ones that can be spoofed. Up to 50 domains, no sign-up, nothing stored.

Tip: paste straight from a spreadsheet column. Blanks and duplicates are ignored.

The Bulk Domain Scanner checks a whole list of domains in one pass and tells you which are spoofable. For each domain it looks up the DMARC record, reads the policy, and flags any domain that cannot stop forged mail. That usually happens because there is no DMARC record at all, or because the policy is set to p=none, which only monitors and still lets spoofed messages through.

Why this matters across a portfolio

Spoofing risk is decided per domain, and it is easy to protect your primary sending domain while leaving parked domains, acquisitions or regional brands wide open. Attackers prefer exactly those forgotten domains. A bulk scan turns a long list, whether every domain you own or a supplier and partner list, into a simple spoofable or protected verdict, so you can prioritise the gaps that matter.

Reading and fixing the result

Each row is classified by its DMARC state. The common verdicts and what to do:

  • No DMARC record: fully spoofable. Publish a DMARC record, starting at p=none with an rua reporting address, then tighten.
  • p=none: monitor-only, still spoofable. Move to p=quarantine then p=reject once reports confirm legitimate mail passes.
  • p=quarantine with low pct: only a fraction of failing mail is acted upon, so raise pct toward 100.
  • Sending vs non-sending domains: a domain that never sends mail can go straight to p=reject with an empty SPF (v=spf1 -all) to shut down spoofing immediately.

Note that a subdomain policy (sp=) governs subdomains separately, so an enforced parent domain does not automatically protect them. For large estates, fixing every domain by hand is slow; DMARC Engine can manage enforcement across a portfolio, and these free tools let you measure the exposure first.

Frequently asked questions

What does "spoofable" mean in the results?

A domain is treated as spoofable when nothing instructs receiving servers to reject forged mail from it. That means either no DMARC record exists, or the policy is p=none, which only monitors. In both cases an attacker can send mail that appears to come from the domain and it will usually be delivered.

Should domains that never send email be scanned too?

Yes, and they are often the weakest point. A non-sending or parked domain can still be spoofed, so it should publish a hard reject policy. The strongest configuration is v=spf1 -all for SPF plus a DMARC record at p=reject, which tells receivers no mail is legitimate from that domain.

My main domain is protected, so why are subdomains still flagged?

DMARC policy can apply differently to subdomains via the sp= tag. If sp= is absent the subdomain inherits the parent policy, but if it is set to none the subdomains remain spoofable even when the parent is at p=reject. Check the sp= value on each flagged parent.

Does the scanner check SPF and DKIM as well?

The bulk scan focuses on DMARC policy, because DMARC is what instructs receivers to act on spoofed mail. For a full per-domain breakdown of SPF, DKIM and alignment, run an individual domain through the DMARC Analyser or the Domain Analyser.

How many domains can I scan at once?

Paste your list of domains and the tool scans them together in a single pass. Very large lists may be processed in batches to stay within DNS rate limits, but the workflow is designed for whole portfolios rather than one domain at a time.

What is the first thing to fix on a spoofable domain?

Publish a DMARC record. For an active sending domain, start at p=none with an rua address so you can see your mail sources, then progress to quarantine and reject. For a domain that never sends, go straight to p=reject. See how to enforce.

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.