Cyber-insurance questionnaires ask pointed questions about your email. Enter your domain: we check what your underwriter can check on their own, and you leave with a dated report.
Free, no signup. Result in 15 seconds, with the full report (SPF, DKIM, DMARC, website).
Underwriting questionnaires have grown longer and renewal increasingly feels like an audit. On the email and digital-identity side, cyber insurers generally expect:
Because that is where the money leaves. Business email compromise (BEC) — a fake email from the boss or a supplier asking to change a bank account number — is one of the leading small-business claim causes. A domain without DMARC in blocking mode makes that fraud trivial: anyone can write to your bookkeeper in your name. To an underwriter that is a risk measurable in 30 seconds, from the outside, without your permission. You may as well know what they see.
Our free report covers what is publicly verifiable: SPF, DKIM, DMARC and its mode, HTTPS, the SSL certificate and its expiry, security headers, sending blocklists, domain age and protection. That is exactly the angle an insurer or a business customer takes when assessing you from outside.
What we cannot see are your internal controls: whether MFA is truly enforced for everyone, whether your backups are tested, what runs on your workstations. Those answers stay yours — be wary of any tool claiming to “certify” your insurability from an external scan.
Three levels, all usable the day someone asks for evidence:
Worth knowing: we are neither a broker nor an insurer, and every carrier has its own criteria — this is not insurance advice. The goal is simple: that you can answer the questionnaire's technical questions with evidence in hand.
Yes, and without asking your permission: SPF, DKIM, DMARC, your certificate and your security headers are public information. That is also why several insurers and brokers run an external check before pricing a risk.
Generally at least quarantine, and increasingly reject. DMARC at p=none ticks the “we have a record” box but blocks nothing — the kind of nuance that gets noticed when a questionnaire is read closely.
No, and nobody can. We check and document the publicly verifiable technical side of your email and web security. Underwriting and claims decisions belong to your insurer.
Often more than before you bought it: renewal is when the questions get harder, and a silent degradation (DMARC dropped during a provider change, an expired certificate) is exactly what continuous monitoring catches.
Yes, no signup and no card. We only read public information (DNS, site headers). The dated report downloads as a PDF.