{"id":349319,"date":"2026-09-01T07:32:18","date_gmt":"2026-09-01T07:32:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/email-authenticity-checker\/"},"modified":"2026-10-09T11:17:38","modified_gmt":"2026-10-09T11:17:38","slug":"inboxauth-email-authenticity","status":"publish","type":"plugin","link":"https:\/\/bcc.wordpress.org\/plugins\/inboxauth-email-authenticity\/","author":17632768,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.1","stable_tag":"1.0.1","tested":"7.1.3","requires":"5.8","requires_php":"7.0","requires_plugins":null,"header_name":"InboxAuth - Email Authenticity","header_author":"Go Web Smarty","header_description":"Verify your domain's email authenticity and discover who's sending as you, then generate SPF\/DKIM\/DMARC records to stop spoofing \u2014 guided by a step-by-step setup wizard.","assets_banners_color":"f2f5f9","last_updated":"2026-10-09 11:17:38","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/spoofing.wpencryption.com","header_author_uri":"https:\/\/gowebsmarty.com","rating":0,"author_block_rating":0,"active_installs":20,"downloads":297,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"gowebsmarty","date":"2026-09-01 07:35:21","revision":3675547},"1.0.1":{"tag":"1.0.1","author":"gowebsmarty","date":"2026-10-09 11:17:38","revision":3736480}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3676590,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3676590,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3676590,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3676590,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3736480,"resolution":"1","location":"assets","locale":"","width":3554,"height":1295},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3736480,"resolution":"2","location":"assets","locale":"","width":3538,"height":1334},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3736480,"resolution":"3","location":"assets","locale":"","width":3541,"height":1344},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3736492,"resolution":"4","location":"assets","locale":"","width":3511,"height":939},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3736492,"resolution":"5","location":"assets","locale":"","width":1800,"height":747},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3736492,"resolution":"6","location":"assets","locale":"","width":1800,"height":798}},"screenshots":{"1":"Dashboard page with email security score and SPF, DKIM, DMARC status","2":"Setup Wizard","3":"Configure a mailbox to receive rua reports for each sent email","4":"48 Hours observer window to analyze who are sending emails from your @domain.com","5":"Analyze all the senders from 48 hours window and choose only the legitimate senders","6":"Generate SPF &amp; DMARC records based on chosen senders and add it to your domain DNS records"}},"plugin_section":[],"plugin_tags":[6930,145801,235808,278610,145798],"plugin_category":[],"plugin_contributors":[178183],"plugin_business_model":[],"class_list":["post-349319","plugin","type-plugin","status-publish","hentry","plugin_tags-dkim","plugin_tags-dmarc","plugin_tags-email-security","plugin_tags-email-spoofing","plugin_tags-spf","plugin_contributors-gowebsmarty","plugin_committers-gowebsmarty"],"banners":{"banner":"https:\/\/ps.w.org\/inboxauth-email-authenticity\/assets\/banner-772x250.png?rev=3676590","banner_2x":"https:\/\/ps.w.org\/inboxauth-email-authenticity\/assets\/banner-1544x500.png?rev=3676590","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/inboxauth-email-authenticity\/assets\/icon-128x128.png?rev=3676590","icon_2x":"https:\/\/ps.w.org\/inboxauth-email-authenticity\/assets\/icon-256x256.png?rev=3676590","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/inboxauth-email-authenticity\/assets\/screenshot-1.png?rev=3736480","caption":"Dashboard page with email security score and SPF, DKIM, DMARC status"},{"src":"https:\/\/ps.w.org\/inboxauth-email-authenticity\/assets\/screenshot-2.png?rev=3736480","caption":"Setup Wizard"},{"src":"https:\/\/ps.w.org\/inboxauth-email-authenticity\/assets\/screenshot-3.png?rev=3736480","caption":"Configure a mailbox to receive rua reports for each sent email"},{"src":"https:\/\/ps.w.org\/inboxauth-email-authenticity\/assets\/screenshot-4.png?rev=3736492","caption":"48 Hours observer window to analyze who are sending emails from your @domain.com"},{"src":"https:\/\/ps.w.org\/inboxauth-email-authenticity\/assets\/screenshot-5.png?rev=3736492","caption":"Analyze all the senders from 48 hours window and choose only the legitimate senders"},{"src":"https:\/\/ps.w.org\/inboxauth-email-authenticity\/assets\/screenshot-6.png?rev=3736492","caption":"Generate SPF &amp; DMARC records based on chosen senders and add it to your domain DNS records"}],"raw_content":"<!--section=description-->\n<p>InboxAuth helps protect your domain from email spoofing, phishing, and unauthorized email senders with a guided email authentication setup. The plugin scans your domain\u2019s SPF, DKIM, and DMARC DNS records to identify missing configurations, authentication issues, and potential security gaps. Whether you manage a business website, an online store, or a WordPress-powered service, InboxAuth makes it easier to understand and improve your domain\u2019s email security.<\/p>\n\n<h3>Protect Your Domain from Email Spoofing<\/h3>\n\n<p>Without properly configured email authentication, attackers may be able to send fraudulent emails that appear to come from your domain. These spoofed emails can be used for phishing attacks, impersonation, and email-based scams that damage your brand reputation and undermine customer trust. InboxAuth helps you identify weaknesses in your email authentication setup and guides you toward configuring SPF, DKIM, and DMARC records to reduce the risk of domain spoofing and unauthorized email use.<\/p>\n\n<h3>Improve Email Deliverability and Domain Reputation<\/h3>\n\n<p>Properly configured email authentication can help legitimate emails reach recipients more reliably while reducing opportunities for attackers to impersonate your domain. InboxAuth is designed for website owners, developers, businesses, and WordPress administrators who want a simpler way to check SPF, DKIM, and DMARC records, troubleshoot email authentication issues, and improve their domain\u2019s email security. Take control of your domain\u2019s email authentication with InboxAuth and build a stronger foundation for secure, trustworthy email communication.<\/p>\n\n<p>https:\/\/www.youtube.com\/watch?v=k9VUXMDQ9-s<\/p>\n\n<ol>\n<li><strong>DNS Scan<\/strong> \u2014 checks your current SPF, DKIM, and DMARC records.<\/li>\n<li><strong>Connect Mailbox<\/strong> \u2014 validates an IMAP connection to a <code>reports@yourdomain.com<\/code>\nmailbox that will receive DMARC aggregate reports.<\/li>\n<li><strong>Set DMARC<\/strong> \u2014 walks you through publishing a starter DMARC record\n(<code>p=none<\/code>, <code>rua=mailto:reports@yourdomain.com<\/code>) so reports start flowing in.<\/li>\n<li><strong>Observer Mode<\/strong> \u2014 runs a 48-hour window, then automatically parses every DMARC\naggregate report received via IMAP to build a list of everyone sending mail as\nyour domain.<\/li>\n<li><strong>Generate Records<\/strong> \u2014 once you've confirmed which senders are legitimate, generates\na tailored SPF record plus a DMARC record with your choice of <code>quarantine<\/code> or\n   reject enforcement, and validates both live via DNS.<\/li>\n<\/ol>\n\n<p>The Dashboard gives an at-a-glance view of SPF\/DKIM\/DMARC status, an overall Email\nSecurity Score, a one-click re-scan, and a link to test whether your domain can\ncurrently be spoofed via the companion Email Authenticity Checker tool.<\/p>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>PHP's <code>imap<\/code> extension enabled (for Step 2 \/ Step 4 mailbox access)<\/li>\n<li>PHP's <code>zip<\/code> extension enabled (Step 4 unpacks .zip-attached DMARC reports)<\/li>\n<li>Outbound DNS resolution available to the server (standard on virtually all hosts)<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin zip file via PLUGINS &gt; ADD NEW in your wp-admin.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Go to <strong>Email Authenticity Checker \u2192 Dashboard<\/strong> to begin, located on sidebar menu item within wp-admin.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20inboxauth%20prevent%20email%20spoofing%3F\"><h3>Can InboxAuth prevent email spoofing?<\/h3><\/dt>\n<dd><p>InboxAuth helps identify email authentication gaps and guides you through configuring SPF, DKIM, and DMARC. Correctly configured authentication records, particularly an appropriate DMARC policy, can significantly reduce the risk of unauthorized senders impersonating your domain.<\/p><\/dd>\n<dt id=\"what%20if%20i%20don%27t%20have%20imap%20access%20to%20a%20reports%40%20mailbox%3F\"><h3>What if I don't have IMAP access to a reports@ mailbox?<\/h3><\/dt>\n<dd><p>Step 2 requires a real mailbox at <code>reports@yourdomain.com<\/code> since DMARC aggregate\nreports are delivered as email attachments. Most hosting control panels let you\ncreate one in a couple of clicks.<\/p><\/dd>\n<dt id=\"is%20configuring%20spf%20and%20dkim%20enough%20to%20protect%20my%20domain%3F\"><h3>Is configuring SPF and DKIM enough to protect my domain?<\/h3><\/dt>\n<dd><p>SPF and DKIM are important parts of email authentication, but they do not replace DMARC. DMARC adds domain alignment checks and a policy that helps receiving mail servers handle messages that fail authentication. For stronger protection against email spoofing, configure all three correctly.<\/p><\/dd>\n<dt id=\"can%20inboxauth%20improve%20email%20deliverability%3F\"><h3>Can InboxAuth improve email deliverability?<\/h3><\/dt>\n<dd><p>Properly configured SPF, DKIM, and DMARC records can improve email authentication and help legitimate messages meet receiving providers' requirements. InboxAuth helps identify configuration issues that may affect authentication. However, inbox placement also depends on sender reputation, recipient engagement, email content, and other factors.<\/p><\/dd>\n<dt id=\"do%20i%20need%20technical%20knowledge%20to%20use%20inboxauth%3F\"><h3>Do I need technical knowledge to use InboxAuth?<\/h3><\/dt>\n<dd><p>InboxAuth is designed to simplify email authentication for WordPress website owners and administrators. Its guided setup helps you understand your domain's SPF, DKIM, and DMARC configuration and identify the changes needed to improve email security.<\/p><\/dd>\n<dt id=\"is%20inboxauth%20useful%20if%20i%20use%20a%20third-party%20email%20service%3F\"><h3>Is InboxAuth useful if I use a third-party email service?<\/h3><\/dt>\n<dd><p>Yes. If you send emails through a business email provider, email marketing platform, or transactional email service, SPF, DKIM, and DMARC configuration can help authenticate messages sent using your domain. Ensure your DNS records correctly reflect your authorized sending services.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Added setup tutorial video<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Protect your domain's email against email spoofing. Discover who's sending as you, then generate SPF\/DKIM\/DMARC records to stop spoofing \u2014 s \u2026","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/349319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=349319"}],"author":[{"embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/gowebsmarty"}],"wp:attachment":[{"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=349319"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=349319"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=349319"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=349319"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=349319"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/bcc.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=349319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}