What does your email setup tell a cyber underwriter?
Enter a domain and we will read its public SPF and DMARC records — the two email-authentication answers almost every cyber application asks for, and the two most businesses cannot give. Nothing is stored and nothing is emailed to you.
Reads published DNS records only. No scanning, no probing, nothing that touches your servers. This is not a security assessment, not an eligibility decision, and not a quote.
SPF says who may send. DMARC says what to do when someone else tries.
Business email compromise is the loss that turns up most often on small-business cyber claims, and it usually starts with someone sending mail that looks like it came from your domain. SPF publishes the list of hosts allowed to send as you. DMARC tells receiving mail servers what to do when a message fails that check — and, just as usefully, sends you reports about who is trying.
The finding we see most often is a DMARC record set to p=none. It exists, it looks like compliance on a questionnaire, and it enforces nothing at all. Moving to p=quarantine and then p=reject is usually a short piece of work, and it is one of the few controls a business can change quickly that underwriters actually price.
More on the exposure itself: business email compromise. When you are ready for a real indication, the application takes a few minutes.