SPF
Authorised senders kept within the lookup limit as your tooling changes.
Sender policyWe take your domains from no policy to enforced DMARC without breaking legitimate mail — reading every report, fixing every sender, and moving you to p=reject safely.
Your mail platform, ticketing, and payroll senders all passing SPF and DKIM alignment.
Four spoofing sources now rejected; three were shadow IT tools we authenticated instead.
Sending and parked domains both enforced, with reports monitored daily for regressions.
Three of these senders were legitimate. We fixed them before enforcing.
Every record you need to authenticate mail, kept correct as your sending estate changes — and monitored so nothing silently breaks.
Authorised senders kept within the lookup limit as your tooling changes.
Sender policyKey publication and rotation across every platform that sends for you.
Signing keysStaged movement from none to quarantine to reject, with alignment verified.
Policy & alignmentDaily XML reports parsed into readable sender and volume reporting.
RUA analysisFailure samples reviewed to separate spoofing from misconfiguration.
RUF samplesYour logo shown in supporting inboxes once enforcement is in place.
Brand indicatorsEncryption in transit enforced and failures reported back to us.
Transport securityNon-sending and lookalike-adjacent domains locked down, not left open.
Full estateRaw XML from every mailbox provider is parsed into sender, volume, and pass-rate reporting your team can actually act on.
Every service sending as your domain is identified — including the marketing and finance tools IT never onboarded.
We move you from p=none to quarantine to reject on evidence, so legitimate mail is fixed before policy tightens.
SPF, DKIM, and DMARC records maintained for you, including SPF lookup limits and key rotation.
Unauthorised senders and spoofing attempts against your domains are flagged as they appear in reports.
Sending and parked domains both covered, so an unused domain cannot be used to impersonate you.
Enforcement is staged deliberately. We monitor first, fix every legitimate sender, then tighten policy so nothing you rely on ever gets blocked.
We inventory every domain you own, check existing SPF, DKIM, and DMARC records, and publish reporting addresses to start collecting data.
At p=none we watch several weeks of reports to build a complete picture of who sends as you and what currently fails alignment.
Legitimate senders are authenticated one by one — records corrected, DKIM signing enabled, SPF kept inside its lookup limit.
Policy moves to quarantine, then reject, with reports monitored throughout and parked domains locked to reject from the start.
DMARC management is built for teams protecting a brand in the inbox — and for anyone facing a customer, insurer, or regulator asking why their domain can still be spoofed.
Record management, report analysis, sender remediation, and staged enforcement across every domain you own.