Can scammers pretend to be you?
Enter your business's web address. In about ten seconds you'll see whether anyone can send email that looks like it came from you.
Free. No sign-up. We only look at settings that are already public.
Our bank details have changed
Hi,
Please note our new bank details for all future payments, including the invoice due this week.
Checking
- Finding who handles your email
- Checking who's allowed to send as you
- Looking for email signing
- Checking what happens to fakes
Show the technical details
Get your free fix report
Step-by-step instructions for your email provider, written so whoever looks after your email can follow them.
- The exact settings to add or change, ready to copy
- What to check first so nothing real gets blocked
- How long each step takes, usually under an hour in total
Stopping people pretending to be you is what Jatzo does.
Domain watch
On Business Pro, Jatzo checks these settings for your domains every day and shows you if one gets weaker.
See howEmail analysis
Flags fake and dangerous emails your team receives, with a plain explanation of why.
See howOr email us at contact@jatzo.co.uk.
Why this matters
Email was never built to check who's really sending it. Unless your email settings say otherwise, anyone can send a message that shows your name and your email address.
Scammers use this to send your customers fake invoices and "new bank details" from you. Your customers pay the scammer, and it's your name on the email.
Three settings, which live alongside your web address, tell the world's email systems which messages really come from you and what to do with the fakes. Most small businesses have never set them up properly. It usually takes less than an hour to fix.
Is this check safe? Do you access my email?
No. We only read public settings that anyone on the internet can already see, the same ones email systems read every time you send a message. We never see your emails or passwords.
What are SPF, DKIM and DMARC?
They're the three settings we check. SPF lists who's allowed to send email as you. DKIM adds a hidden signature to your real emails. DMARC tells other email systems what to do with emails that fail those checks: let them through, send them to junk, or block them.
My result says "Couldn't confirm" for signing. Is that bad?
Not necessarily. Email signing can be set up in a way we can't see from outside. The full report explains how to check it with whoever runs your email.
Who can fix it?
Whoever looks after your web address or email: your IT support, your web designer, or you, if you're comfortable changing settings. The fix report is written so any of them can follow it.
Do you keep the address I check?
Only if you ask us to email you the report. Otherwise the check isn't saved against you.
