Your own services, passing
Google, Microsoft, your invoicing tool, your newsletter. These should pass. Write the list down: it's exactly what you need before tightening anything.
Do it yourself
Everything we use, in your browser. Your files never leave your computer: there's nothing to upload and nothing for us to keep. Use them forever, whether or not you ever hire us.
Tool one
Every day, Gmail, Outlook and the rest send your domain a report listing every server that sent email using your name. They arrive as zip files full of raw data, which is why almost nobody reads them. Drop them here and they become plain English.
Nothing is uploaded. The files are opened on this computer.
They only arrive once your domain asks for them, which takes one line in your DNS:
p=none changes nothing about how your email is delivered. It only turns the reports on. Use an email address you already read: it doesn't have to be a new one. They arrive daily as zip files, so an alias or a filter into its own folder keeps your inbox sane. Wait a day or two and the files start arriving. The free check writes this line out for your exact domain.
What to look for
Google, Microsoft, your invoicing tool, your newsletter. These should pass. Write the list down: it's exactly what you need before tightening anything.
A service you recognise that fails isn't an attack. It means that service isn't set up to sign your mail yet, and tightening enforcement would start bouncing it. Fix it before you tighten.
This is the one that counts. Note whether those messages were delivered, sent to spam, or refused. Delivered means people read them.
One failure from an unknown server is noise, often forwarded mail. The same unknown server appearing day after day, in volume, is somebody working.
If a quiet week suddenly shows thousands of messages using your name, something changed. That's worth an hour of attention the same day.
Reports show servers and counts, never the content of messages or who received them. They also only cover providers that send reports, which is most of the big ones.
Tool two
The same check that runs on the front page: about 240 versions of your name, which of them are taken, and what each one has on it.
If the trail leads inside
Mail that passes your checks was sent with your own credentials. That isn't someone imitating you, it's someone using an account, and it needs a different response, quickly. Work down this list.
In Google Workspace or Microsoft 365, look at recent sign-ins for locations and devices nobody recognises.
Check for mail rules nobody set up, especially forwarding or auto-delete. This is the classic invoice-fraud move, because it hides the replies from the real owner.
Look at which applications have access to the mailbox, and remove anything unfamiliar.
Change the password and turn on two-step sign-in for everyone, not just the affected account.
By phone, using numbers you already have. Not by email, and not a number from an email.
Your email provider's support, and your IT person if you have one. If money has already moved, your bank the same day and a report at ic3.gov.
We watch and we tell you. We aren't incident responders, and we'll say so plainly rather than take money for something outside what we do.
Tool three
If people have called you back angry about calls you never made, or told you that you asked them to never call again when you never called at all, your number is being spoofed. Someone set your number as the caller ID on their own calls, and the callbacks land on you.
There's nothing to scan. Phone networks keep no public record of who borrowed your number, so no tool, ours or anyone else's, can show you who did it or undo it. What follows is the short list that does something.
This is the step with teeth: illegally spoofing a number to defraud carries penalties of up to $10,000 per call. On the FCC complaint site choose Phone, then unwanted calls, then the sub-issue about your own number being spoofed. Write down dates, times and what the callbacks told you before you file.
Set a voicemail password if you don't have one: some systems let anyone calling from your own number straight in, and a spoofer can use that. Then ask your carrier about their free call-blocking and number-protection tools. Every major US carrier has them now, usually in their app.
Do not argue or engage. A plain script works: My phone number is being spoofed by a scammer. I didn't call you, and I am sorry you got that call. You can report it to the FCC. Let unknown numbers go to voicemail and decide later.
Put your number on the National Do Not Call Registry. It won't stop scammers, but it stops legitimate telemarketing, which makes the spoofing pattern easier to see. For a business number, a call-screening app that labels likely spam cuts the noise most.
One nuance worth knowing: spoofing is only illegal when it's meant to defraud or cause harm. That's why the FCC complaint is the real lever rather than a guaranteed shut-off. It builds the case that gets bad actors fined and their numbers cut off, so reporting matters even when nothing appears to happen immediately.
Watching someone lose a business over an afternoon's work isn't a business model. So the finding, the plan and the tools are free and stay free. If the work is more than you want to carry, that's what we charge for.
They tell you the truth at the moment you check. They can't watch around the clock, they can't see fake social profiles (those go to each platform directly), and for phone numbers they can point you at the right action but can't scan a network that keeps no record. Honest tools beat reassuring ones.
That's what we sell: we read the reports daily, watch the look-alike names, and write to you the day something changes. No pressure, and the tools above stay free either way.