Enter your domain below to instantly scan your DMARC, SPF, DKIM, BIMI, MTA-STS and DNS records. You’ll see exactly what’s missing or misconfigured — no signup required.
See something red? Pick a plan and we’ll fix it for you — or start a free 14-day trial first.
Anyone can send an email that appears to come from your domain. SPF, DKIM and DMARC are the three checks that let receiving servers tell your real mail from a forgery.
Email was designed before spoofing was a concern. The protocol lets a sending server claim any From address, much like writing any return address on a paper envelope. Nothing in the basic system verifies it.
A criminal sends a message with your domain in the From line to your customers, suppliers or staff. It really comes from their server, but it looks like you. Typical uses are fake invoices, changed bank details, payroll diversion and password-reset lures.
Gmail, Outlook and Yahoo fall back on spam filters and reputation. Some forged mail gets through, and some of your genuine mail is wrongly sent to junk, because nothing proves who is real.
SPF is a DNS record listing the servers and services allowed to send mail for your domain. The receiver compares the IP address of the connecting server with that list.
Limit: It checks a hidden envelope address rather than the From line people see, and it breaks when mail is forwarded.
Your mail system signs each message with a private key. The receiver fetches the matching public key from your DNS and checks the signature. Any change to the signed content breaks it, and an attacker without your private key cannot forge a valid signature for your domain.
Limit: A valid signature does not say which domain the recipient should expect. An attacker can sign with their own domain and still show yours in the From line.
DMARC requires that SPF or DKIM passes and that the domain it validated matches the visible From domain, which is called alignment. Your policy then tells receivers to monitor, quarantine or reject failures, and reports show every message sent in your name.
Limit: It only protects the domains you own and publish it for.
| Scenario | SPF | DKIM | DMARC | Outcome |
|---|---|---|---|---|
| Your staff send from Microsoft 365 or Google Workspace | Pass | Pass | Pass | Delivered |
| An attacker sends as you from their own server | Fail | Fail | Fail | Rejected |
| A recipient forwards your genuine email | Fail | Pass | Pass | Delivered, because DKIM still validates |
| An attacker signs with their own domain but shows yours in From | Not aligned | Not aligned | Fail | Rejected, because alignment catches it |
| Your invoicing app sends as you but was never set up | Fail | Fail | Fail | Blocked, which is why we monitor first |
DMARC is powerful but narrow. Knowing its limits is how you build the right defence around it.
DMARC cannot stop someone registering a similar domain such as yourcornpany.com. That needs lookalike-domain detection, which is included in our Fortress plan.
DMARC protects other people from forged mail claiming to be you. It does not filter the phishing that lands in your own inbox, which needs inbound filtering and staff awareness.
If an attacker takes over a real account, the mail they send is authenticated. Multi-factor authentication is what stops this.
A message from "Your CEO" at a free webmail address passes its own checks. Mail filtering and user training handle this case.
Without proper email authentication, inbox providers like Gmail, Outlook, and Yahoo have no way to verify your messages are legitimate — so they flag them as suspicious.
Without SPF, anyone can send email pretending to be your domain. Providers penalize unauthenticated senders.
Without DKIM, your emails can be tampered with in transit. Providers can't verify message integrity.
Without DMARC, you have zero visibility into who's spoofing your domain — and no way to stop them.
We implement every layer of email authentication to maximize your deliverability and protect your brand.
Defines exactly which mail servers are authorized to send email on behalf of your domain. We audit all your sending sources and create an optimized SPF record.
Digitally signs every outgoing email so recipients can verify it hasn't been altered in transit and truly comes from your domain.
Tells receiving servers what to do with unauthenticated emails and gives you reports on who's using (or abusing) your domain.
Advanced protocols that display your brand logo in inboxes (BIMI) and encrypt mail server connections to prevent interception (MTA-STS).
Deliverability is more than DNS records. We optimize your entire email ecosystem.
Full analysis of your current setup — blacklist checks, reputation scoring, header analysis, and authentication gaps.
Clean invalid addresses, set up proper bounce handling, and warm up new IPs/domains for optimal sender reputation.
Proper reverse DNS (PTR), HELO/EHLO configuration, TLS enforcement, and mail server hardening for Microsoft 365 or Google Workspace.
Continuous DMARC report analysis, blacklist monitoring, and alerts if your domain reputation drops.
Already blacklisted? We identify the cause, fix the underlying issue, and submit delisting requests to all major blacklist providers.
Specialized configuration for M365 and Google Workspace including connectors, transport rules, and anti-spam tuning.
We analyze your current DNS records, mail flow, and reputation.
We implement SPF, DKIM, and DMARC with proper DNS records.
We watch DMARC reports and gradually tighten your policy.
Full p=reject policy — spoofed emails are blocked entirely.
Jumping straight to a strict policy blocks your own legitimate mail. We move through three stages, so nothing real is lost on the way.
p=none
Mail is delivered as normal while reports begin to arrive. This is the safe starting point, but it gives you visibility rather than protection. Many domains never move past it.
p=quarantine
Mail that fails authentication is sent to the junk folder. We ramp this up gradually with the pct setting, for example 10%, then 50%, then 100%, so a missed sender is caught early.
p=reject
Mail that fails is refused before it reaches the recipient. This is the goal, the strongest protection against spoofing, and the level BIMI brand logos require.
Since February 2024 they expect SPF and DKIM from every sender. Bulk senders, meaning more than about 5,000 messages a day, must also publish DMARC, align the From domain, offer one-click unsubscribe on marketing mail and keep spam complaints low.
Microsoft has introduced comparable authentication requirements for high-volume senders to Outlook.com, Hotmail and Live.com addresses.
Provider requirements tighten over time. We track them so your records stay compliant without you having to follow every announcement.
Fully managed email authentication — we do the setup, you get the inbox placement. No contracts, no setup fees, cancel anytime.
Get authenticated and stop the spoofing.
Full authentication stack with threat intelligence.
Enterprise-grade defense with a dedicated engineer.
All plans include managed setup, DNS record publishing, and enforcement rollout by a TechShield engineer.
Need more domains or a custom rollout? Request a custom quote · Not ready? Start a free 14-day trial
If people act on email that claims to be from you, your domain is worth protecting.
Invoices, quotes and customer replies that must reach the inbox, from a domain people trust.
Professions whose names are attractive to impersonators and whose clients act on what an email says.
Receipts, newsletters and campaigns sent through several platforms that all need aligned authentication.
Donor and parent communications that need to land reliably, on a limited IT budget.
Related: IT security blog · Managed IT plans · Online presence & local SEO · Cloud backup
We’ll deploy DMARC monitoring on your domain, collect real reports from Gmail, Outlook and Yahoo, and walk you through exactly who is sending as you. Keep the records whether you stay or not.
Tell us about your setup and we'll provide a free assessment and quote.