Subdomain Security Checker
Discover email authentication gaps across all your subdomains and sending infrastructure - before attackers exploit them. We find your subdomains, then check SPF, DKIM, and DMARC (including inherited policy) on every one.How the Subdomain Security Checker Works
Subdomains are the most overlooked attack surface in email security. This tool discovers them, then checks each one for DMARC, SPF, and DKIM coverage and flags which are open to spoofing.
Enter your root domain
Type your primary domain (e.g. company.com). The scanner discovers subdomains from public Certificate Transparency logs and by probing common mail, marketing, support, dev, and transactional names.
Authentication checks run
Each resolving subdomain is checked for a valid SPF record, DKIM signatures at common selectors, and its effective DMARC policy - including protection inherited from the parent domain's sp= or p=.
Get a prioritized action list
See which subdomains are vulnerable, which need improvement, and get specific remediation steps ordered by risk - so your team knows exactly what to fix first.
Why Subdomain Email Security Matters
Organizations typically lock down their root domain but leave subdomains unprotected. Attackers know this - and actively exploit subdomain email infrastructure to bypass filters and spoof trusted brands.
support.yourdomain.com, mail.yourdomain.com, and more.p=none only monitors - it does not block or quarantine spoofed email. Subdomains stuck in monitoring mode are effectively unprotected from a deliverability standpoint.sp=, or its p= if there is no sp=. Most organizations never set sp=, so this tool computes the real effective policy for each subdomain.Common Subdomain Email Security Vulnerabilities
These are the most common gaps our scanner finds across subdomain infrastructure - and what to do about each one.
_dmarc.subdomain.yourdomain.com with at minimum p=quarantine.p=none means monitoring mode only. Spoofed emails still reach inboxes - the policy generates reports but takes no enforcement action.p=quarantine once you have reviewed your reports, then advance to p=reject.v=spf1 include:youresp.com ~all - use your ESP's documented include.sp=reject is protected against spoofing - but has no reporting, no explicit control, and can send its own legitimate mail into rejection if it is not aligned.Frequently Asked Questions
Does my root domain DMARC policy protect subdomains?
sp=quarantine or sp=reject. If there is no sp=, receivers fall back to the root's p= for subdomains. Either way, a subdomain with its own DMARC record always overrides the parent. This tool computes the effective policy for you.What is subdomain spoofing and how does it work?
[email protected]. If that subdomain has no effective DMARC enforcement, receiving servers have no policy telling them to reject the message. Because the subdomain is associated with a trusted brand, these attacks succeed at high rates against employees, customers, and partners.How does the scanner discover my subdomains?
Should I add DMARC to non-sending subdomains too?
p=reject and an SPF record of v=spf1 -all. That tells receivers to reject any message claiming to come from it.What does "Vulnerable" mean in the results?
p=none (monitoring only). Spoofed mail from it can reach inboxes. "Warning" means it is enforced but relies only on the parent policy, is missing SPF, or is otherwise incomplete. "Secure" means it has its own DMARC record at p=quarantine or p=reject.Is DKIM detection definitive?
How do I protect all my subdomains at once?
sp=reject on your root domain's DMARC record - it covers every subdomain that has no policy of its own. Then work through each sending subdomain to configure proper SPF, DKIM, and its own DMARC. A hosted platform like PowerDMARC lets you manage every policy centrally, alerts you when new subdomains appear, and guides you to p=reject safely with aggregate and forensic reporting.More Free Email Authentication Tools
Verify your full email authentication stack with PowerDMARC's free tool suite.
DMARC Checker
Validate your DMARC record and enforcement policy.
Check DMARC →SPF Record Checker
Validate your SPF record for authorized senders.
Check SPF →DKIM Checker
Look up and validate DKIM records for any domain.
Check DKIM →Sender Reputation
Score a domain's full email authentication posture.
Check reputation →Protect every subdomain with PowerDMARC
Centrally manage DMARC policies across all your domains and subdomains, get real-time forensic alerts, and reach enforcement without complexity.