Does your company let forged senders through?
In CEO fraud, the email appears to come “from the boss” or “from accounts” — in reality the sender is forged. This test sends you a single email that appears to come from a colleague at your own domain. If it arrives, your infrastructure is vulnerable.
How it works
You confirm your address
You receive a confirmation link at your own address. Testing only starts after the click — so nobody can misuse other people’s mailboxes.
I forge a colleague at your domain
You enter the name and address of a supposed sender from your own domain. Only that domain can be tested — never someone else’s.
Your result
You immediately see an assessment of your SPF/DMARC settings — and whether the forged email lands in your inbox.
Fair & safe
This test sends an email in another person’s name. So that it can’t become a tool for abuse, fixed rules apply — even if the test is requested via the interface or an AI assistant:
- Your own domain only: the recipient and spoofed sender address must have the same domain. Other people’s domains can’t be tested.
- Only to your confirmed address: the test email goes exclusively to the mailbox that clicked the confirmation link.
- A human always approves: even if an AI assistant requests the test, nothing is sent until you click the link in your confirmation email. This link is never handed out to the interface.
- One test per domain and hour: so nobody can flood a mailbox with test emails.
- Fixed content: the text of the test email is predefined and consists of the explanation of the test. It can’t be freely designed — so no real phishing text can be sent via secureIT.
- Logged: every test requested and carried out is logged and reported to me.
- No sharing with third parties, no newsletter
Set up the test
All addresses must have the same domain.