Kavach

Check · Domain & email identity · default severity high

Email spoofing policy (DMARC)

What Kavach checks

DMARC tells the world's mail servers to reject email that fakes your domain.

Why it matters

Without an ENFORCING DMARC (p=quarantine/reject), anyone can send phishing that looks exactly like it came from you -- the root of most Business Email Compromise.

How an attacker uses it

  1. Attacker sends an invoice email 'from' ceo@yourcompany.com.
  2. With no enforcing DMARC, it lands in the inbox, fully trusted.
  3. Finance pays the attacker's bank details.

How to fix it

Publish a DMARC record and move to p=quarantine, then p=reject: v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 2.

Scan your site free → Monitor it continuously