Case study · Guest tools · 2024

The Domain Scanner.

EasyDMARC's most-used tool among guest, logged-out visitors — a free, no-login domain health check that's the top of the whole funnel. I designed the scan state, the post-scan report, a guided fix funnel with a dedicated track for every failing record, and an embeddable widget builder — all on the EasyDMARC design system.

EasyDMARC Domain Scanner results — a 'Scanning results' report with a Medium risk-assessment band, an overall score of 6 of 10, per-record SPF, DMARC, and DKIM cards with traffic-light status dots, and a 'What's next? Launch Setup Wizard' call to action.
Role
Product Designer
Year
2024
Status
Live · most-used guest tool
Context

The tool most people meet EasyDMARC through.

EasyDMARC protects organizations' email — DMARC, SPF, DKIM, BIMI. But before anyone signs up, they want one question answered: is my domain actually safe? The Domain Scanner — surfaced publicly as the Domain Health Check and Domain Tester — answers it for free, with no account. Type a domain, get an instant report on its SPF, DMARC, DKIM, and BIMI records.

That makes it the single most-used tool among guest, logged-out visitors — the top of the acquisition funnel and, for a lot of people, their first impression of the whole product. So it has to do two hard things at once: hand a complete stranger a serious security audit they can understand in seconds, and give them an honest, non-pushy path to fix whatever's broken.

A guest tool is a strange brief — no onboarding, no context, no second chance. The scanner has seconds to be legible, credible, and genuinely useful before it earns the right to suggest a next step.

Scope

What I designed.

I owned the Domain Scanner end-to-end as a guest experience — the scan state, the results report, the guided fix funnel, and the embeddable widget — all on the EasyDMARC design system.

  • Default scan state — the entry point: one field, one promise, and a quiet “embed” affordance for other sites.
  • The post-scan report — a plain-language risk level, an overall score out of 10, per-record SPF / DMARC / DKIM cards, the detailed record values, and inline warnings for the subtle cases.
  • A fix funnel for every result — a setup wizard with a dedicated, self-contained track for each failing record (SPF, DMARC, DKIM), including all intro, publish, verify, error, and success states.
  • The embed widget builder — a live-preview “Adjust the embed” modal with theming, content controls, and auto-generated embed code, so the scanner can live on anyone's site.

The screens below are a selection — enough to show the structure and the key states, not every screen in the flow.

Default state

One field, one promise.

The scanner opens on a single input. No login, no setup, no choosing what to check — just a domain and a Scan button, wrapped in a one-line explanation of what comes back. The Scan Domain button stays disabled until there's something to scan, and a small Get an embed link in the corner quietly signals that this tool can travel.

Domain Scanner default state — the 'Domain Scanner and Health Check' module at the top of the public page, with a single 'Enter your domain name' field, a disabled Scan Domain button, and a 'Get an embed' link in the top-right corner.

The entry point — deliberately bare. Everything a guest needs to start is one field and one button; the landing page around it does the convincing, the tool just works.

The page in full

The scanner in its native habitat.

The scanner doesn't live alone — it sits at the top of a public marketing page that has to earn a stranger's trust before they type anything. Below the input: a plain-language explainer of what a domain health check is (with a preview of the report they'll get), the reasons it matters, a diagram of the four records being checked, social proof, and an FAQ. The scan module leads; everything under it supports the decision to use it.

The full public Domain Scanner page, top to bottom — the global nav and a 'Domain Scanner and Health Check' scan module, a 'What is a Domain Health Check?' explainer with a sample report preview, a 'Why Check Domain Security?' section with four benefit cards, a Domain Checker diagram branching to SPF / DMARC / DKIM / BIMI, a marketing block, an FAQ, a customer logo strip (Picsart, Panasonic, G2, FxPro, and others), and the footer.

The whole page, top to bottom — scan module first, then the explainer, the four-record diagram, social proof, and the FAQ. The tool is the hook; the rest of the page is there to convert a curious visitor into someone who scans.

The report

A serious audit a stranger can read in seconds.

A scan returns a lot — SPF, DMARC, DKIM and BIMI status, the raw record values, policy strength, and a verdict on each. The job of the report is to rank that by what matters: a plain-language Risk Assessment band up top, a single overall score out of 10, then per-record cards that use a three-dot traffic light so the state reads before the label does.

Below the summary, each record expands into its actual value and a specific, human explanation of what's wrong and why it matters — with inline warnings for the subtle cases, like a DMARC policy that's technically present but set too strictly. Every path forward narrows to one button: Launch Setup Wizard.

The full Domain Scanner results page, top to bottom — the scan module with example.com entered, the 'Scanning results' report (Medium risk band, score 6 of 10, SPF / DMARC / DKIM cards, Launch Setup Wizard), the 'Overall detailed results' section listing each record's value with an inline DMARC warning, an 'Identify email problems' block with an Increase Score button, the FAQ, and the footer.

The same report in full context — the scan box stays on top so a guest can immediately re-scan or try another domain, the detailed records and the “Increase Score” nudge sit below the summary, and the supporting FAQ answers the questions a first-time visitor still has.

The fix funnel

A guided fix for every failing record.

A score isn't the point — fixing the domain is. Clicking through from the report launches a setup wizard that turns the report's findings into work. A three-stop stepper — Activate EasySPF → Activate DMARC → Activate DKIM — frames the whole journey, and the entry screen restates exactly what the scan found, counting the detected issues per record so the user knows the size of the job before they start.

Setup Wizard entry — 'Let's Optimize Your Domain', with the SPF / DMARC / DKIM stepper across the top and three cards showing the count of detected issues per record (SPF 1, DMARC 1, DKIM 2), plus two warning banners and a Launch Setup Wizard button.

The wizard entry — the scan's findings, restated as a to-do list. Detected-issue counts per record (and any warnings) set expectations before the first step.

Each record then gets its own self-contained track, the same shape every time: explain the issue in plain terms, show the current state, hand over the exact record to publish, and verify it. Designing one rhythm and reusing it across SPF, DMARC, and DKIM is what keeps a multi-step DNS task from feeling endless.

SPF

SPF track, intro — 'Cover the first issue: SPF', a plain-language explanation of SPF, the domain's existing SPF state (status Valid, lookup count 14/10 in red, 1 email sender), and Later / Fix Issues buttons.
SPF track, publish & verify — 'Update your DNS with EasySPF' (Step 2/2), numbered DNS instructions, an SPF record card with Host / Type / Value and Copy buttons, a Quick Guides sidebar, a red 'Record verification failed' error state, and a Verify button.
SPF track, success — 'Congratulations! Your SPF Record Has No Issues', the SPF stats now all green (Valid, 6/10, 8 senders), and a primary Activate DMARC button handing off to the next track.

The SPF track — intro (what SPF is, plus the current lookup-count and sender stats), the publish-and-verify step with the exact record to add and a verification-failed error state, and the success screen that hands off to DMARC.

DMARC

DMARC track, intro — 'Optimize Your DMARC Record' (Step 1/2), the existing DMARC state shown as four red status cards (DMARC status Invalid, EasyDMARC Reporting Inactive, Domain Policy None, Subdomain Policy None), and Later / Fix Issues buttons.
DMARC track, no-record variant — the same 'Optimize Your DMARC Record' screen for a domain with no DMARC record at all, all four status cards reading 'No Record', with a welcome-back message about setting up comprehensive DMARC reporting.
DMARC track, success — 'Congratulations! Your DMARC Record Has No Issues', status cards now showing Valid and Active, a note about policy enforcement after aggregate reports arrive, and a primary Configure DKIM button.

The DMARC track follows the same rhythm — a status read (Invalid / Inactive / No Record), a step-by-step fix, and a “no issues” success that routes straight into DKIM. Same layout, same buttons, different record.

DKIM

DKIM track, intro — 'You're Almost Done: Next is DKIM', explaining that precise DKIM guidance arrives with the first DMARC report, illustrated by a preview carousel of a sending-sources table (Google Workspace, Amazon SES, SendGrid) with SPF Pass and DKIM Pass rates.
DKIM track, configuration — a per-sending-source Configuration modal for Google, showing SPF status Configured and DKIM status Not Configured, a 'Go to DKIM Configuration' link, and a Test Sending Source button.
DKIM track, roadmap — 'The roadmap on Your DMARC Journey', a circular DMARC Monitoring diagram with three stages: Receive Aggregate Reports, Discover not-configured email sending sources, and Configure SPF and DKIM.

DKIM is the most open-ended — its configuration depends on each sending source — so this track leans on a preview carousel and a per-source configuration modal, then closes on a roadmap of what to expect after onboarding: aggregate reports, discovering unconfigured senders, and configuring each one.

Embed widget

A scanner that travels.

The most-used guest tool gets more useful the more places it lives. From the scan page, Get an embed opens an “Adjust the embed” builder: a live preview on the left, controls on the right, and an auto-generated <script> snippet underneath that drops the scanner onto any site.

The controls cover the things a host actually cares about — a light or dark theme, full color customization (background, title, paragraph, buttons, shadow), editable title, paragraph, and button labels, a redirect URL, and a switch to deactivate the widget's outbound links. The preview updates as they go, so what they configure is exactly what they ship.

Adjust the embed modal, light theme with Customize open — the default light preview, the Adjustments panel showing Background, Title, and Paragraph color fields, and the Widget Code snippet below the preview.
Adjust the embed modal, light theme — a live Domain Scanner preview with a sample scan result (SPF, DMARC, DKIM, BIMI cards and a score of 8 of 10) and the Widget Code snippet below it.
Adjust the embed modal, light theme with the full Customize panel open — Background, Title, Paragraph, Buttons and Shadow color fields plus a Shadow toggle, beside a live preview that includes a sample scan result.
Adjust the embed modal, dark theme with the full Customize panel open — the same color controls on the right and a navy-themed live preview with a sample scan result on the left.
Adjust the embed modal, dark theme — a live Domain Scanner preview on a navy background with a scanned result and a 'Widget Code' script snippet with a Copy button.
The embed Adjustments / settings bar in detail — Reset to Default, Theme (Light / Dark), a Customize section with Background, Title, Paragraph, Buttons and Shadow colors, a Content section with editable Title and Paragraph and Button 1 / Button 2 labels, a Redirect URL field, and a 'Deactivate widget links' toggle.

The whole builder in one place — light and dark themes, full color control (background, title, paragraph, buttons, shadow), a live preview that updates with a sample scan result, the generated <script> snippet, and the Adjustments settings bar where every theme and content choice is made. The same scanner, restyled to fit someone else's site, quietly carrying EasyDMARC with it.

Outcome

An anonymous check, turned into a path.

The Domain Scanner is the front door — the most-used tool among guest visitors and, for many, the first thing EasyDMARC ever does for them. The design turns a cold, anonymous health check into something legible and credible in seconds, then converts curiosity into momentum: a guided, self-serve funnel that walks a stranger from “here's what's wrong” to “here's exactly how to fix it,” one record at a time.

And because the same tool is embeddable, every fix it drives can happen on someone else's site too — the scanner markets the platform by being genuinely useful first.

What I'd carry forward

The strongest decision here was committing to one repeated rhythm — explain, show state, hand over the record, verify — and reusing it across SPF, DMARC, and DKIM instead of designing three bespoke flows. For a guest with no patience and no onboarding, predictability is the feature. Once the first track teaches the pattern, the rest of the funnel almost reads itself.

Happy to walk through the funnel in detail — the states that didn't make the cut, the embed tradeoffs, the copy decisions — in a conversation.

Get in touch

Like what you see?

I'm open to senior product design roles and select freelance engagements. Always happy to chat.

Get in touch