Do it yourself

The tools, free, no account.

Everything we use, in your browser. Your files never leave your computer: there's nothing to upload and nothing for us to keep. Use them forever, whether or not you ever hire us.

Tool one

Read your own email reports.

Every day, Gmail, Outlook and the rest send your domain a report listing every server that sent email using your name. They arrive as zip files full of raw data, which is why almost nobody reads them. Drop them here and they become plain English.

Nothing is uploaded. The files are opened on this computer.

I don't have any report files yet

They only arrive once your domain asks for them, which takes one line in your DNS:

Type: TXT   Name: _dmarc
v=DMARC1; p=none; rua=mailto:your-email@yourdomain.com

p=none changes nothing about how your email is delivered. It only turns the reports on. Use an email address you already read: it doesn't have to be a new one. They arrive daily as zip files, so an alias or a filter into its own folder keeps your inbox sane. Wait a day or two and the files start arriving. The free check writes this line out for your exact domain.

What to look for

Reading them without a manual.

Your own services, passing

Google, Microsoft, your invoicing tool, your newsletter. These should pass. Write the list down: it's exactly what you need before tightening anything.

Something of yours, failing

A service you recognise that fails isn't an attack. It means that service isn't set up to sign your mail yet, and tightening enforcement would start bouncing it. Fix it before you tighten.

A server you don't know, failing

This is the one that counts. Note whether those messages were delivered, sent to spam, or refused. Delivered means people read them.

The same stranger, every day

One failure from an unknown server is noise, often forwarded mail. The same unknown server appearing day after day, in volume, is somebody working.

Volume you can't explain

If a quiet week suddenly shows thousands of messages using your name, something changed. That's worth an hour of attention the same day.

What they can't tell you

Reports show servers and counts, never the content of messages or who received them. They also only cover providers that send reports, which is most of the big ones.

Tool two

Check for look-alike addresses.

The same check that runs on the front page: about 240 versions of your name, which of them are taken, and what each one has on it.

Run the free check

If the trail leads inside

When the mail is passing, it isn't forgery.

Mail that passes your checks was sent with your own credentials. That isn't someone imitating you, it's someone using an account, and it needs a different response, quickly. Work down this list.

1 · Sign-in history

In Google Workspace or Microsoft 365, look at recent sign-ins for locations and devices nobody recognises.

2 · Forwarding rules

Check for mail rules nobody set up, especially forwarding or auto-delete. This is the classic invoice-fraud move, because it hides the replies from the real owner.

3 · Connected apps

Look at which applications have access to the mailbox, and remove anything unfamiliar.

4 · Reset and lock

Change the password and turn on two-step sign-in for everyone, not just the affected account.

5 · Call anyone who was sent payment details

By phone, using numbers you already have. Not by email, and not a number from an email.

Who to call

Your email provider's support, and your IT person if you have one. If money has already moved, your bank the same day and a report at ic3.gov.

We watch and we tell you. We aren't incident responders, and we'll say so plainly rather than take money for something outside what we do.

Tool three

When your phone number is the one being used.

If people have called you back angry about calls you never made, or told you that you asked them to never call again when you never called at all, your number is being spoofed. Someone set your number as the caller ID on their own calls, and the callbacks land on you.

The honest part first

There's nothing to scan. Phone networks keep no public record of who borrowed your number, so no tool, ours or anyone else's, can show you who did it or undo it. What follows is the short list that does something.

  1. File a complaint with the FCC

    This is the step with teeth: illegally spoofing a number to defraud carries penalties of up to $10,000 per call. On the FCC complaint site choose Phone, then unwanted calls, then the sub-issue about your own number being spoofed. Write down dates, times and what the callbacks told you before you file.

    Open the FCC complaint form

  2. Lock down your voicemail and call your carrier

    Set a voicemail password if you don't have one: some systems let anyone calling from your own number straight in, and a spoofer can use that. Then ask your carrier about their free call-blocking and number-protection tools. Every major US carrier has them now, usually in their app.

  3. Have a calm answer ready

    Do not argue or engage. A plain script works: My phone number is being spoofed by a scammer. I didn't call you, and I am sorry you got that call. You can report it to the FCC. Let unknown numbers go to voicemail and decide later.

  4. Reduce the noise around it

    Put your number on the National Do Not Call Registry. It won't stop scammers, but it stops legitimate telemarketing, which makes the spoofing pattern easier to see. For a business number, a call-screening app that labels likely spam cuts the noise most.

    National Do Not Call Registry

One nuance worth knowing: spoofing is only illegal when it's meant to defraud or cause harm. That's why the FCC complaint is the real lever rather than a guaranteed shut-off. It builds the case that gets bad actors fined and their numbers cut off, so reporting matters even when nothing appears to happen immediately.

What's the catch

Watching someone lose a business over an afternoon's work isn't a business model. So the finding, the plan and the tools are free and stay free. If the work is more than you want to carry, that's what we charge for.

What these tools can't do

They tell you the truth at the moment you check. They can't watch around the clock, they can't see fake social profiles (those go to each platform directly), and for phone numbers they can point you at the right action but can't scan a network that keeps no record. Honest tools beat reassuring ones.

If you would rather not do this every week

That's what we sell: we read the reports daily, watch the look-alike names, and write to you the day something changes. No pressure, and the tools above stay free either way.

See pricing Get in touch

Get in touch