Managed DMARC, taken all the way to blocking.
SPF, DKIM and DMARC set up, staged to enforcement and monitored for you, so mail faked as your domain is refused before it reaches a customer, a supplier or your finance team.
Every one of these starts with an email that passes as you.
Without DMARC set to block, anyone can put your exact domain in the From field. The message arrives looking internal, because as far as the receiving system is concerned, it is.
Awareness training asks a person to spot a message built not to be spotted. Blocking removes the address itself, and it is the one control here that does not depend on anybody noticing.
Each one covers something the others do not.
Four records in your domain settings, each with a different job, and a gap in any of the first three is a gap an attacker can use. Two of them we run, one we watch, and one is an extra you can add.
Hover or select a record to hold it · cycling on its own otherwise
DKIM signing happens inside whichever platform sends your mail, so the switch is not ours to throw. What we own is knowing it is wrong: every sender is checked, a failure is raised as an alert, and it stays open until the reports show that sender passing.
A base that stands on its own, and two extras.
The base is the part that stops mail faked from your address, and it is the part everyone starts with. The extras are jobs that only some organisations need, so nobody pays for work their records do not require.
Managed end to end. Nothing lands on your team.
You approve DNS changes and read a review once a month. The audit, the staging, the reports and the chasing of failing senders are ours. One agreement, one team, one named analyst.
Staged, monitored, reversible.
The risk is never the DMARC record itself, it is the sender nobody remembered. So we only tighten it after every sender is accounted for, and every step can be rolled back the moment the reports show something unexpected.
Most organisations already sit at stage one. If your DMARC is in watch-only mode today you have the reporting but nothing is being blocked, and the real work starts at stage two.
Blocking stops mail faking your domain, not every lookalike.
With DMARC set to block, mail putting your exact domain in the From field is refused rather than delivered. That is the trick behind fake invoices, redirected payroll, and most email payment fraud.
It does nothing about a lookalike domain, because that domain passes every check as itself. Closing that side needs monitoring and takedowns, which is why we treat both as one programme rather than separate products.
See how takedowns work →The DMARC reports, read for you.
DMARC does more than block. The same record asks every major email provider for a daily report on mail sent using your name, and those reports are how we know, before blocking goes on, that no genuine sender is about to break.
Reading them is a service in its own right. DMARC Reports turns those daily files into a named list of everything sending as you, with a written review each month.
Priced to the size of your brand.
Pricing starts at £950 a month for up to three sending domains, covering the DMARC reports read and turned into a named list of everything sending as you, your records watched, and alerts when one changes. Each domain after the first three is £120 a month. BIMI certification and Managed SPF are separate one-off jobs, priced on the work your records actually need, so nobody pays for a fix that does not apply to them. We are taking a few companies at a time, so the way in is the waitlist.