Know your domain's posture — before someone else finds out.
PostoChecker gives IT/IS admins fast, self-service email forensics and domain posture checks —
the answers a SOC platform would give you, without deploying one.
Full command of your domain and email operations, in one admin's hands.
Analysis
Runs in your browser
Outbound
DNS-over-HTTPS only
Grading
Cited to the RFC
Verdict
One correlated score
Launch lineup
One intelligence layer for your domain and email operations.
Automated analysis that empowers IT/IS admins to answer "is this a problem?" for a message, a domain, a report, or an IP — without doing the work by hand.
Coming soon
Email Header Threat Analyzer
Paste raw headers or drop an .eml file. Nothing is ever kept or persisted — no disk, no
logs, no third parties. Full routing reconstruction, SPF/DKIM/DMARC alignment, deep link and content
forensics — correlated into one verdict: OK, Suspicious, or Likely Spam/Phishing, in seconds.
Coming soon
Coming soon
Automated Intelligence DMARC RUA Report Card
Turns raw DMARC aggregate (RUA) XML into a plain-language summary your team can actually read
and act on — no more unopened report emails.
Coming soon
Coming soon
Domain Posture Scanner
One scan covers SPF, DKIM, DMARC, MTA-STS, and BIMI presence — each graded against its IETF spec,
with a combined posture score instead of a black box.
Coming soon
Coming soon
Dispatch Hub
Found a malicious IP? Report it to well-known community DNSBL / blacklist providers in one click —
currently dispatching to three databases at once, built for abuse investigations and deliverability protection.
Built for the IT/IS admin, not the SOC platform budget
Privacy-first
The Email Header Threat Analyzer processes your headers in memory only. Nothing is ever persisted to
disk, logs, or third parties — and no outbound calls are made while diagnosing it.
Standards-grounded
Every grade cites the RFC behind it — so a verdict is never a black box.
Correlated, not siloed
Header findings and live domain posture blend into one 0–100 verdict — an auth-failing message
against a p=reject domain reads as forgery, not two disconnected reports.
About PostoChecker
Email never slows down. Neither should the team watching it.
IT/IS admins are expected to have SOC-grade visibility into their organization's email and domain security — without the SOC-grade tooling, headcount, or budget that's supposed to come with it. Just a DNS zone they own, an inbox full of things that might be phishing, and no time to become a security analyst on top of everything else on their plate.
IT/IS ops fields every spoofed invoice, every mismatched Reply-To, every DMARC report nobody's opened — they're the actual frontline of daily security operations, upstream of any SOC. Sharpen what happens there, and everything downstream gets faster and easier to act on: cleaner, better-documented findings instead of a hallway "can you check this?" starting from scratch.
Status
Ready to check your posture?
The full suite launches soon — check back for the live portal.