Solutions / Email Authentication

Managed DMARC, taken all the way to blocking.

SPF, DKIM and DMARC set up, staged to enforcement and monitored for you, so mail faked as your domain is refused before it reaches a customer, a supplier or your finance team.

Blocking in 6 to 10 weeksNo genuine sender lostWritten review monthly
Free email record checkNO SIGNUP

See how far along your DMARC and BIMI records already are, scored the same way we score them in an audit. It reads public domain records only: nothing is changed, nothing is published, no email address asked for.

Faked mail rule (DMARC)SCORED
Inbox logo record (BIMI)SCORED
Logo file and certificate (VMC)SCORED

SPF is not part of this check. Count your SPF lookups here →

Why it reaches the board

Every one of these starts with an email that passes as you.

Without DMARC set to block, anyone can put your exact domain in the From field. The message arrives looking internal, because as far as the receiving system is concerned, it is.

Invoice fraud

The invoice is real. The bank details are not.

A supplier or a member of your finance team appears to send a routine payment request with one account number changed. Nothing looks wrong, because nothing about the address is wrong.

Payroll redirection

One salary, paid to the wrong account.

A change-of-details request sent from your own domain to your own payroll team. It is paid once and it is rarely recovered, and the same request works again next month.

Customer phishing

Your customers, phished in your name.

Mail sent as you asking customers to pay or log in. The complaints arrive at your support desk, the refunds come out of your revenue, and the reputation cost is yours to carry.

Awareness training asks a person to spot a message built not to be spotted. Blocking removes the address itself, and it is the one control here that does not depend on anybody noticing.

The four records

Each one covers something the others do not.

Four records in your domain settings, each with a different job, and a gap in any of the first three is a gap an attacker can use. Two of them we run, one we watch, and one is an extra you can add.

Hover or select a record to hold it · cycling on its own otherwise

SPF record · lookup count1 / 10 LOOKUPS · 0 DEAD
In your DNS
acme.com TXT
"v=spf1 include:acme._spf.jssec.com -all"
hardened · flattened · 1 lookup · 0 dead
When it is wrong
!

11 lookups: the record stops resolving

Over the limit, receiving systems abandon the check and treat it as a permanent error. Salesforce and Mailchimp mail begins to fail even though both are approved. A third dead entry does the same thing on its own.

What the inbox does
?

[email protected]

Remittance advice · via unapproved server

SPF FAIL

Mail from a server that is not on your list fails the check, and DMARC decides what happens to it next.

EXAMPLE RECORDS · acme.com⏸ HELD · SPF
On DKIM · where the line sits

DKIM signing happens inside whichever platform sends your mail, so the switch is not ours to throw. What we own is knowing it is wrong: every sender is checked, a failure is raised as an alert, and it stays open until the reports show that sender passing.

What you are buying

A base that stands on its own, and two extras.

The base is the part that stops mail faked from your address, and it is the part everyone starts with. The extras are jobs that only some organisations need, so nobody pays for work their records do not require.

In the basefrom £950 / MONTH · Up to 3 domains you send from

DMARC Visualisation

DMARC reports →

The daily reports every major email provider sends back, collected and turned into a named list of everything sending as you.

DMARC Health

ON THIS PAGE

Your records watched for correctness and for change, every sender accounted for, and DMARC staged all the way to blocking without losing genuine mail.

Optional extrasAdded only if your records need them

Two jobs on one record. Hardening clears the lookups that resolve to nothing and the entries authorising tools you no longer send from. Flattening rewrites a record still over the ten-lookup limit into one that passes. Scoped to whichever yours needs.

BIMI Certification

BIMI certification →from £1,800 ONE-OFF

Your verified logo beside your mail in the inboxes that support it, including the Verified Mark Certificate it depends on.

How it works

Managed end to end. Nothing lands on your team.

You approve DNS changes and read a review once a month. The audit, the staging, the reports and the chasing of failing senders are ours. One agreement, one team, one named analyst.

01

Audit

Every system that sends email as you, found and listed.

02

Set up

SPF cleared of dead and unused entries, DMARC staged towards blocking, every sender checked for a valid signature.

03

Block

DMARC switched to blocking, with no genuine sender lost.

04

Monitor

The daily reports watched, so new senders are caught early.

YOU

Approve the record changes. Read one page a month.

US

Everything else, including the part where something changes at 2am.

Time to blocking

6 to 10 weeks

Depending on how many systems send mail as you.

Your team's involvement

A few DNS changes

Publish the DMARC record we give you, and with Managed SPF, point your SPF at ours once. Every change after that is ours to make.

SPF kept inside its ten-lookup limit, with no dead entries
DKIM checked on every sender, failures tracked until they pass
DMARC set to block, and watched
Finding everything that sends as you
Outside tools checked against the records
Rules for unused and secondary domains
Alerts the moment a record changes
A monthly written review with your analyst
The daily reports collected and read for you
Extra domains added as you acquire them
The path to blocking

Staged, monitored, reversible.

The risk is never the DMARC record itself, it is the sender nobody remembered. So we only tighten it after every sender is accounted for, and every step can be rolled back the moment the reports show something unexpected.

Most organisations already sit at stage one. If your DMARC is in watch-only mode today you have the reporting but nothing is being blocked, and the real work starts at stage two.

01

Monitor

p=none

Turn DMARC on in watch-only mode with reporting. Nothing is blocked; you start seeing everything that sends as you.

02

Account for senders

the real work

Each sender is identified and either set up to pass the checks or moved off your domain.

03

Send to spam

p=quarantine

Failing mail goes to spam instead of the inbox. Reports are watched for anything genuine caught by the change.

04

Block

p=reject

Mail that fails is turned away before it is delivered. Reporting continues, so new senders show up before they cause problems.

What it does and does not cover

Blocking stops mail faking your domain, not every lookalike.

With DMARC set to block, mail putting your exact domain in the From field is refused rather than delivered. That is the trick behind fake invoices, redirected payroll, and most email payment fraud.

It does nothing about a lookalike domain, because that domain passes every check as itself. Closing that side needs monitoring and takedowns, which is why we treat both as one programme rather than separate products.

See how takedowns work →
The reporting half

The DMARC reports, read for you.

DMARC does more than block. The same record asks every major email provider for a daily report on mail sent using your name, and those reports are how we know, before blocking goes on, that no genuine sender is about to break.

Reading them is a service in its own right. DMARC Reports turns those daily files into a named list of everything sending as you, with a written review each month.

Sender report● COLLECTING
RAW REPORTS IN · LAST 24H
google.com!acme.com!1721779200.xml.gz
outlook.com!acme.com!1721779200.xml.gz
yahoo.com!acme.com!1721779200.xml.gz
mail.ru!acme.com!1721779200.xml.gz
protonmail.ch!acme.com!1721779200.xml.gz
google.com!acme.com!1721779200.xml.gz
outlook.com!acme.com!1721779200.xml.gz
yahoo.com!acme.com!1721779200.xml.gz
mail.ru!acme.com!1721779200.xml.gz
protonmail.ch!acme.com!1721779200.xml.gz
READ AS NAMED SENDERS
Google Workspace
12,480PASS
Salesforce
3,204PASS
Mailchimp
1,890PASS
not recognised · mail.ru
412FLAGGED
EXAMPLE REPORT · ON A LOOPREVIEW READY
Pricing

Priced to the size of your brand.

Pricing starts at £950 a month for up to three sending domains, covering the DMARC reports read and turned into a named list of everything sending as you, your records watched, and alerts when one changes. Each domain after the first three is £120 a month. BIMI certification and Managed SPF are separate one-off jobs, priced on the work your records actually need, so nobody pays for a fix that does not apply to them. We are taking a few companies at a time, so the way in is the waitlist.

FAQ

See where your brand stands.