Check a few things yourself.
Passive checks you can run on your own domain in a few seconds. No signup, no email wall, nothing stored. If they turn something up and you want a hand fixing it, you know where to find me.
Can someone send email as you?
Checks SPF, DKIM and DMARC and tells you, in plain English, whether anyone can forge mail from your domain. Most companies fail this.
Security headers checker
Grades your HTTP response headers — CSP, HSTS, frame protection and more — and gives you the exact values to set.
Everything here is passive: public DNS lookups and a single HTTP request for response headers. Nothing is scanned, no payloads are sent, no response bodies are read, and no results are stored or logged against you. The endpoints validate every target against private address ranges before connecting, because a tool that fetches user-supplied URLs is an SSRF vector and it would be embarrassing to get that wrong here of all places.