Has your email been leaked or spoofed?
Enter your email. We'll check if it appears in known data breaches — and whether your domain's SPF, DKIM & DMARC stop criminals sending mail that looks like it's from you. Instant, plain-English.
Found gaps in your email security?
Solvbeat can set up your SPF, DKIM and DMARC properly — and keep watching them, so spoofing stays blocked for good, not just today.
See how we can help →Is one of your passwords already leaked?
Type a password to check it against billions of leaked ones. It never leaves your browser — only 5 characters of its scrambled hash are sent, so nobody (not even us) can see the password or work it out.
What this tool checks
Two questions decide whether your email is a liability: has your address already leaked, and can anyone pretend to be your domain? Here's what we look at.
Has your email been breached?
We check your address against known public data breaches. If it's in there, so is (often) a password — and attackers use those lists for credential-stuffing and phishing.
Who's allowed to send
SPF lists the mail servers permitted to send email for your domain. Without it — or without -all enforcement — anyone can send as you.
A tamper-proof signature
DKIM cryptographically signs your outgoing mail so receivers can verify it wasn't forged or altered in transit.
What to do with fakes
DMARC ties SPF and DKIM together and tells inboxes to reject or quarantine spoofed mail. p=none only watches; p=reject actually blocks.
Where your mail lands
MX records point to the servers that receive your email. We confirm they're configured and reachable.