Email Security Test

Test your email server and DNS records for security, privacy, encryption, protection against spam and email spoofing, and other misconfigurations
Free online tool with PDF report
  • Email Server Security Test
  • Phishing Campaigns Detection
  • Email Server Encryption Test
  • Compromised Credentials Detection
  • DNS Misconfigurations Test
  • Black & Spam Lists Presence Detection
Free online tool with PDF report
6,374,198 tests performed
Provided "as is" without any warranty of any kind
14
tests
running
5,583
tests
in 24 hours
Tests in 24 Hours
Please wait. Data is loading...

Latest Tested Email Servers

Please wait. Data is loading...

Frequently Asked Questions

Q

What is email security?

A

Email security consists of technologies and procedures, implemented to test email servers for misconfigurations and vulnerabilities, verify email server’s SSL/TLS encryption, detect various DNS-related issues, find compromised credentials that may give access to email accounts, identify presence of your email server in various black lists and spam feeds, spot ongoing phishing and squatting campaigns targeting your users and more.

Q

What are common misconfigurations affecting email servers?

A

Commonly, we see email servers that have SMTP enumeration commands (i.e. VRFY, EXPN, RCPT) enabled, allow plain authentication without TLS, or can be used as open relays:

The MX server being an open relay allows anyone on the internet to use it to send spam or other malicious emails without any authentication. This can lead to the server being marked as a spammer and ultimately blacklisted, causing legitimate emails to also get blocked.

The prohibition of VRFY, EXPN, and RCPT commands on an MX server protects against SMTP Enumeration. SMTP Enumeration can be dangerous for the MX server as it allows attackers to gather information about valid email addresses on the server. This information can be used to launch phishing attacks, spam campaigns, or even attempts to compromise user accounts.

SMTP plain authentication is not recommended because it transmits passwords as plaintext, making them vulnerable to interception and theft by hackers. This type of authentication does not provide any encryption or security measures to protect sensitive information.

Our free Community Edition Email Security Test allows to check for all aforementioned misconfigurations. Simply enter your domain name or email server’s IP to get the full report.

Q

What is SSL/TLS?

A

Secure Sockets Layer (SSL) is a family of network protocols aimed to encrypt data transmission over other, higher level, protocols that transport web content, email or other types of information. Today SSL is considered obsolete and insecure, and is now replaced with a newer TLS (Transport Layer Security) family of protocols. Many people, however, still use the SSL acronym interchangeably with TLS. Billions of people unwittingly use SSL/TLS in a daily manner, for example, when they visit an HTTPS website, they are relying on TLS encryption when sending and receiving the data from the web server where the website is hosted.

Q

What is phishing and cybersquatting?

A

Phishing is a well-known computer attack targeting individual and corporate users with key purpose to steal their data or compromise their systems. Phishing is often dependent on social engineering that exploits human inattentiveness, emotions or fatigue. A phishing website may usurp one’s identity, for instance, by pretending to be a bank website, and asking to login with victim’s credentials. Upon login, the victim is redirected to the legitimate website, while login and password are stolen by the attackers.

Cybersquatting is unethical, and often illegal, practice to register domain names that include registered trademarks or brand names belonging to third parties without their permission. Cybercriminals may leverage cybersquatting tactics to impersonate banks, healthcare providers or governmental authorities and send emails from cybersquatted domains to lure inattentive website visitors into sharing their confidential information.