Free tool
Everything below is public DNS and unauthenticated endpoints — the same view any attacker gets before writing a single phishing email. Hosting, mail routing, security gateways, Microsoft 365 tenant, and the full SPF / DKIM / DMARC posture.
Passive reconnaissance only: no connection is made to your servers, no email is sent, nothing is stored. Analyse domains you own or are authorised to test.