Anyone can check whether you have done this - and almost nobody has finished it. We exist to get it finished, and to show you the evidence at every step rather than asking you to take our word for it.
1 domain, no card required. £50 a month after that, 5 domains included.
| Source IP | Messages | Pass | Alignment |
|---|---|---|---|
209.85.220.41 |
572,850 | 100.0% | DKIM + SPF |
40.107.243.72 |
281,400 | 99.9% | DKIM + SPF |
198.51.100.24 |
132,660 | 99.4% | SPF only |
203.0.113.88 |
13,200 | 0.0% | neither |
No jargon in this section. If you have been sent here by an insurer, an IT supplier or a customer's security questionnaire, start at the top.
Email was designed in a more trusting age. The "from" line is simply typed by whoever sends the message, like the return address on an envelope - and nothing checks it. A criminal can send an invoice that appears to come from your finance team, and it will look genuine to the person who receives it.
The messages go to your customers, your suppliers and your own staff: a change of bank details, an urgent request from the boss, a delivery that needs a small fee. The loss lands on someone who trusted your name, and the first you hear of it is usually the phone call afterwards.
You publish a few short lines in your domain's DNS - the same place your website address lives. They tell every mail server in the world who is allowed to send email as you, and what to do with anything else: let it through, put it in spam, or reject it outright.
Two reasons, and neither is laziness. The daily reports arrive as thousands of XML files that no human can read. And turning the policy up without knowing who sends on your behalf is how a company blocks its own invoices, payslips or newsletters - so most people publish the record, see the wall of XML, and stop at the safe setting that changes nothing.
We read the reports for you and turn them into a plain list of who is sending as your domain, how much, and whether it passes. When the evidence says tightening the policy is safe, we say so - and show you exactly what it would have stopped last month before you change anything.
Nothing here needs your mail to pass through us, and nothing needs software installed. You publish one line in DNS and the reports start arriving.
Not everything worth doing needs a specialist. Stopping people forging your email has stayed the preserve of a small number of experts, and the result is that the organisations most likely to be impersonated are the least likely to be protected.
Spoofing your domain costs an attacker nothing and costs your customers their trust. The controls that stop it have existed for a decade. What has been missing is a way to run them without a specialist on staff.
Every change we suggest comes from what your own mail is actually doing this week. We refuse anything that would stop your mail arriving, we show you what a change would have blocked last month before you make it, and afterwards we check that what is published is still what you agreed to.
Everything that proves your mail is yours, everything that keeps mail to you encrypted, and a record of every change that cannot be quietly edited - priced so an organisation with five domains can afford the lot.
Publishing one DNS record starts the reports flowing within a day.
We give you a reporting address unique to your tenant. Put it in your DMARC record and receivers start sending reports.
Every source is identified with its volume, alignment and disposition, so you can tell your own mail from everyone else's.
Fix alignment for the senders that matter, then tighten the policy knowing exactly what it will stop.
example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc-acme-k7m2p9x4@reports.example.com; fo=1"
Six services covering the whole of email authentication. Two are included in every plan; the other four are the single add-on below, switched on per domain.
acme.example managed 13 / 10 lookups flattened to 0
Before: five includes, three of them nested. After: 34 address ranges, no lookups.
v=spf1 ip4:209.85.128.0/17 ip4:40.107.0.0/16 ip4:198.51.100.0/24 ip6:2a01:111:f400::/48 ~all
| Selector | Key | Status |
|---|---|---|
google | rsa 2048 | active |
selector1 | rsa 2048 | active |
legacy | rsa 1024 | rotate |
Includes are resolved and published as addresses, so the record costs nothing to evaluate. Only mechanisms that could actually produce a pass are inlined, so the flattened record authorises exactly what the original did.
Upstream address ranges change without warning. We re-resolve on a schedule and tell you when a new revision is ready, with a diff against the last one.
MTA-STS at enforce mode can stop delivery outright. We check your live MX records before publishing and refuse a policy that would leave one uncovered, then hold the new version back until your DNS confirms it.
Two add-ons, both optional, both described the same way as everything else: the problem first, then the approach, then what you get.
You are handing us reports about your mail. The controls below are the ones we would want to see in your position.
History checked - all 8,412 entries intact.
| Seq | Actor | Action | Outcome |
|---|---|---|---|
| 8412 | ops@acme.example | report.export | success |
| 8411 | ops@acme.example | member.role_change | success |
| 8410 | system | ingest.parse.success | success |
| 8409 | unknown@evil.test | auth.login.failure | failure |
If your auditor asks: every control is mapped to the NIST frameworks in a published matrix, and each is marked done, partly done or planned - honestly.
Everything in the standard plan is included from the first day of the trial.
Free
14 days
£50
per tenant, per month
£500
per tenant, per year
Add-ons: Additional domains from £8 per domain per month; Sender authentication and transport security £25 per month. Full pricing.
Most receivers send aggregate reports once a day, so the first data usually arrives within 24 to 48 hours of publishing the record.
Not on its own. Start at p=none, which only asks for reports and
changes nothing about delivery. You decide when to tighten it, and the dashboard
shows what each step would have stopped.
At enforce it can stop mail being delivered to you, which is why we
validate a policy against your live MX records and refuse to publish one that
would leave a server uncovered. New versions are also held back until your
_mta-sts TXT record confirms them, so senders never hold a policy we
are no longer serving.
Report collection stops and your data stays under your retention policy. Pick a plan and it resumes; nothing is deleted early.
No. We generate the records and tell you exactly what to publish, then check whether what is live matches. Your DNS stays yours. Hosted MTA-STS needs one CNAME from you and nothing more.
Yes. Any OpenID Connect provider can be configured per tenant, with optional just-in-time provisioning and the ability to require SSO for all members.
14 days, no card. See who is sending as your domain before you decide anything.
One DNS record to begin. Nothing is routed through us and no agent is installed.