✉️ EMAIL DELIVERABILITY

Stop Landing in
the Spam Folder

We set up DMARC, SPF, DKIM, and advanced email authentication so your messages reach inboxes — not junk folders. Protect your domain from spoofing and improve deliverability across every provider.

📧
DMARC SPF DKIM BIMI MTA-STS
🔍 FREE INSTANT CHECK

Check Your Email Settings Right Now

Enter your domain below to instantly scan your DMARC, SPF, DKIM, BIMI, MTA-STS and DNS records. You’ll see exactly what’s missing or misconfigured — no signup required.

See something red? Pick a plan and we’ll fix it for you — or start a free 14-day trial first.

🛡 STOP EMAIL SPOOFING

How DMARC and DKIM Protect You From Spoofed Emails

Anyone can send an email that appears to come from your domain. SPF, DKIM and DMARC are the three checks that let receiving servers tell your real mail from a forgery.

Why spoofing is so easy

1

Email never checked who was sending

Email was designed before spoofing was a concern. The protocol lets a sending server claim any From address, much like writing any return address on a paper envelope. Nothing in the basic system verifies it.

2

Attackers use your name to be believed

A criminal sends a message with your domain in the From line to your customers, suppliers or staff. It really comes from their server, but it looks like you. Typical uses are fake invoices, changed bank details, payroll diversion and password-reset lures.

3

Without DMARC, receivers have to guess

Gmail, Outlook and Yahoo fall back on spam filters and reputation. Some forged mail gets through, and some of your genuine mail is wrongly sent to junk, because nothing proves who is real.

What SPF, DKIM and DMARC each do

🛡️

SPF

Which servers may send as you

SPF is a DNS record listing the servers and services allowed to send mail for your domain. The receiver compares the IP address of the connecting server with that list.

Limit: It checks a hidden envelope address rather than the From line people see, and it breaks when mail is forwarded.

🔑

DKIM

Proof the message is genuine and untouched

Your mail system signs each message with a private key. The receiver fetches the matching public key from your DNS and checks the signature. Any change to the signed content breaks it, and an attacker without your private key cannot forge a valid signature for your domain.

Limit: A valid signature does not say which domain the recipient should expect. An attacker can sign with their own domain and still show yours in the From line.

📊

DMARC

Ties it together and sets the rule

DMARC requires that SPF or DKIM passes and that the domain it validated matches the visible From domain, which is called alignment. Your policy then tells receivers to monitor, quarantine or reject failures, and reports show every message sent in your name.

Limit: It only protects the domains you own and publish it for.

What happens to real and forged mail

ScenarioSPFDKIMDMARCOutcome
Your staff send from Microsoft 365 or Google Workspace PassPassPass Delivered
An attacker sends as you from their own server FailFailFail Rejected
A recipient forwards your genuine email FailPassPass Delivered, because DKIM still validates
An attacker signs with their own domain but shows yours in From Not alignedNot alignedFail Rejected, because alignment catches it
Your invoicing app sends as you but was never set up FailFailFail Blocked, which is why we monitor first

What DMARC does not do

DMARC is powerful but narrow. Knowing its limits is how you build the right defence around it.

🎭 Lookalike domains

DMARC cannot stop someone registering a similar domain such as yourcornpany.com. That needs lookalike-domain detection, which is included in our Fortress plan.

📥 Phishing sent to you

DMARC protects other people from forged mail claiming to be you. It does not filter the phishing that lands in your own inbox, which needs inbound filtering and staff awareness.

🔓 Hijacked mailboxes

If an attacker takes over a real account, the mail they send is authenticated. Multi-factor authentication is what stops this.

🪪 Display-name tricks

A message from "Your CEO" at a free webmail address passes its own checks. Mail filtering and user training handle this case.

Why Your Emails Land in Spam

Without proper email authentication, inbox providers like Gmail, Outlook, and Yahoo have no way to verify your messages are legitimate — so they flag them as suspicious.

🚫
No SPF Record

Without SPF, anyone can send email pretending to be your domain. Providers penalize unauthenticated senders.

⚠️
Missing DKIM Signing

Without DKIM, your emails can be tampered with in transit. Providers can't verify message integrity.

🎭
No DMARC Policy

Without DMARC, you have zero visibility into who's spoofing your domain — and no way to stop them.

Complete Email Authentication Stack

We implement every layer of email authentication to maximize your deliverability and protect your brand.

🛡️

SPF (Sender Policy Framework)

Defines exactly which mail servers are authorized to send email on behalf of your domain. We audit all your sending sources and create an optimized SPF record.

  • Identify all legitimate sending services
  • Create properly formatted DNS TXT record
  • Stay within the 10 DNS lookup limit
  • Cover web apps, CRM, marketing tools, etc.
🔑

DKIM (DomainKeys Identified Mail)

Digitally signs every outgoing email so recipients can verify it hasn't been altered in transit and truly comes from your domain.

  • Generate 2048-bit signing keys
  • Configure DKIM for all sending services
  • Publish public keys in DNS
  • Verify signatures are passing
📊

DMARC (Domain-based Authentication)

Tells receiving servers what to do with unauthenticated emails and gives you reports on who's using (or abusing) your domain.

  • Start with monitoring (p=none)
  • Gradually enforce quarantine → reject
  • Aggregate & forensic report analysis
  • Full visibility into domain abuse
✨

BIMI & MTA-STS

Advanced protocols that display your brand logo in inboxes (BIMI) and encrypt mail server connections to prevent interception (MTA-STS).

  • BIMI logo display in Gmail & Apple Mail
  • MTA-STS for encrypted mail delivery
  • TLS-RPT reporting setup
  • Brand trust & recognition boost

Beyond Authentication

Deliverability is more than DNS records. We optimize your entire email ecosystem.

🔍
Deliverability Audit

Full analysis of your current setup — blacklist checks, reputation scoring, header analysis, and authentication gaps.

📋
List Hygiene & Warm-up

Clean invalid addresses, set up proper bounce handling, and warm up new IPs/domains for optimal sender reputation.

🖥️
Mail Server Configuration

Proper reverse DNS (PTR), HELO/EHLO configuration, TLS enforcement, and mail server hardening for Microsoft 365 or Google Workspace.

📈
Ongoing Monitoring

Continuous DMARC report analysis, blacklist monitoring, and alerts if your domain reputation drops.

🚨
Blacklist Removal

Already blacklisted? We identify the cause, fix the underlying issue, and submit delisting requests to all major blacklist providers.

🏢
Microsoft 365 & Google Workspace

Specialized configuration for M365 and Google Workspace including connectors, transport rules, and anti-spam tuning.

How It Works

1
Audit

We analyze your current DNS records, mail flow, and reputation.

2
Configure

We implement SPF, DKIM, and DMARC with proper DNS records.

3
Monitor

We watch DMARC reports and gradually tighten your policy.

4
Enforce

Full p=reject policy — spoofed emails are blocked entirely.

From Monitoring to Full Protection

Jumping straight to a strict policy blocks your own legitimate mail. We move through three stages, so nothing real is lost on the way.

p=none

Monitor

Mail is delivered as normal while reports begin to arrive. This is the safe starting point, but it gives you visibility rather than protection. Many domains never move past it.

p=quarantine

Send to spam

Mail that fails authentication is sent to the junk folder. We ramp this up gradually with the pct setting, for example 10%, then 50%, then 100%, so a missed sender is caught early.

p=reject

Block

Mail that fails is refused before it reaches the recipient. This is the goal, the strongest protection against spoofing, and the level BIMI brand logos require.

What Gmail, Yahoo and Microsoft Now Expect

📬

Gmail & Yahoo

Since February 2024 they expect SPF and DKIM from every sender. Bulk senders, meaning more than about 5,000 messages a day, must also publish DMARC, align the From domain, offer one-click unsubscribe on marketing mail and keep spam complaints low.

📮

Microsoft Outlook.com

Microsoft has introduced comparable authentication requirements for high-volume senders to Outlook.com, Hotmail and Live.com addresses.

🧭

Rules keep changing

Provider requirements tighten over time. We track them so your records stay compliant without you having to follow every announcement.

✉️ EMAIL PROTECTION PLANS

Simple Monthly Pricing

Fully managed email authentication — we do the setup, you get the inbox placement. No contracts, no setup fees, cancel anytime.

Email Guardian

Get authenticated and stop the spoofing.

$20 /month
per domain group · billed monthly
1 active domain
Up to 100,000 compliant emails/mo
6 months data history
2 platform users
  • ✓ Hosted DMARC record management
  • ✓ Hosted SPF (no 10-lookup limit)
  • ✓ Hosted DKIM key management
  • ✓ RUA aggregate report processing
  • ✓ Daily deliverability dashboard
  • ✓ Guided p=none → p=reject rollout
  • ✓ Email alerts on auth failures
  • ✓ Business-hours support
  • × Hosted BIMI / VMC
  • × MTA-STS & TLS-RPT
  • × Forensic (RUF) reports
MOST POPULAR

Email Sentinel

Full authentication stack with threat intelligence.

$30 /month
per domain group · billed monthly
Up to 5 active domains
Up to 1,000,000 compliant emails/mo
1 year data history
5 platform users
  • ✓ Everything in Email Guardian
  • ✓ Hosted MTA-STS + TLS-RPT
  • ✓ Hosted BIMI (logo in the inbox)
  • ✓ RUA and RUF forensic reports
  • ✓ SPF & DKIM analytics
  • ✓ DMARC geolocation threat map
  • ✓ IP / domain blacklist monitoring
  • ✓ Priority support + quarterly review
  • × Lookalike domain detection
  • × SIEM streaming

Email Fortress

Enterprise-grade defense with a dedicated engineer.

$45 /month
per domain group · billed monthly
Up to 25 active domains
Unlimited compliant emails
2 years data history
Unlimited platform users
  • ✓ Everything in Email Sentinel
  • ✓ Lookalike / cousin domain detection
  • ✓ SIEM & log streaming support
  • ✓ AI-assisted remediation guidance
  • ✓ Managed VMC certificate assistance
  • ✓ Custom alerting & scheduled reports
  • ✓ Dedicated deliverability engineer
  • ✓ 24/7 priority support

All plans include managed setup, DNS record publishing, and enforcement rollout by a TechShield engineer.

Need more domains or a custom rollout? Request a custom quote · Not ready? Start a free 14-day trial

Who Needs Managed DMARC

If people act on email that claims to be from you, your domain is worth protecting.

🏢

Small & growing businesses

Invoices, quotes and customer replies that must reach the inbox, from a domain people trust.

🏥

Healthcare, legal & finance

Professions whose names are attractive to impersonators and whose clients act on what an email says.

🛒

Online stores & marketers

Receipts, newsletters and campaigns sent through several platforms that all need aligned authentication.

🤝

Non-profits & schools

Donor and parent communications that need to land reliably, on a limited IT budget.

Works With the Platforms You Already Use

Microsoft 365Google WorkspaceMailchimpConstant ContactSendGridHubSpotSalesforceZendeskBrevo

Email Authentication Questions Answered

Email spoofing is when an attacker sends a message that appears to come from your domain, such as accounts@yourcompany.com, even though it was sent from a server you do not control. Email was designed without a sender check, so without SPF, DKIM and DMARC anyone can forge a From address. Spoofed mail is commonly used for invoice fraud, payroll diversion and credential phishing.

DMARC lets you publish a rule telling receiving mail servers what to do with messages that claim to be from your domain but fail authentication. A message passes only if SPF or DKIM validates and the validated domain matches the visible From address. At a policy of reject, mail that fails is refused before it reaches the recipient, so attackers can no longer use your exact domain convincingly. DMARC reports also show you every system sending mail as you.

DKIM adds a cryptographic signature to each outgoing message, created with a private key that only your mail system holds. The receiving server checks it against the public key published in your DNS. A forger cannot produce a valid signature for your domain, and any change to the signed content breaks the check, so DKIM proves both origin and integrity. On its own it does not say which domain the recipient should expect, which is why DMARC alignment completes the job.

SPF lists which servers may send mail for your domain. DKIM signs each message so it can be verified as genuine and unaltered. DMARC sits on top of both: it requires that at least one of them passes and aligns with the visible From domain, tells receivers what to do when neither does, and sends you reports. SPF and DKIM are the evidence, and DMARC is the rule and the reporting.

Yes. Each covers a weakness in the others. SPF breaks when mail is forwarded, and DKIM can break when a mailing list modifies a message, but DMARC passes if either one validates and aligns. Having both gives resilience, and DMARC is what turns them from signals into enforcement. Google, Yahoo and Microsoft now expect all three from high-volume senders.

The most common causes are missing or broken SPF, DKIM or DMARC records, an SPF record over the 10 DNS lookup limit, a sending service that is not authorised, poor sender reputation or blacklisting, high complaint rates, and mismatched reverse DNS. A free domain check shows which of these apply, and a deliverability audit finds the rest.

Since February 2024, Gmail and Yahoo expect senders to authenticate mail with SPF and DKIM, and bulk senders of more than about 5,000 messages a day must also publish a DMARC policy, align the From domain, offer one-click unsubscribe on marketing mail and keep spam complaints low. Microsoft has introduced comparable requirements for high-volume senders to Outlook.com. Requirements change, so we track them for you.

Start at none to collect reports without affecting delivery, move to quarantine once every legitimate sender is authenticating, and finish at reject. Reject gives the strongest protection, and BIMI requires an enforced policy. Moving too fast can block your own legitimate mail, which is why we run the monitoring phase first and ramp up gradually using the pct setting.

Only if a legitimate sender is not authenticated correctly, such as a forgotten invoicing tool, CRM or newsletter service. That is exactly what the monitoring phase is for. DMARC reports list every source sending as your domain, so each one is fixed before enforcement begins and legitimate mail keeps flowing.

Setup and monitoring usually begin within one business day. The time to full enforcement depends on how many services send mail as your domain. A simple domain on Microsoft 365 or Google Workspace can often reach enforcement in a few weeks, while a domain with many third-party senders takes longer because each one must be identified and authenticated first.

Not directly. DMARC protects other people from receiving forged mail that claims to be from your domain. It does not filter the phishing that arrives in your own inbox, and it does not stop lookalike domains, display-name tricks or a hijacked mailbox. Those need inbound mail filtering, multi-factor authentication and lookalike-domain monitoring, which is why DMARC works best as one layer of a wider email security setup.

Email Guardian is $20 per month (1 active domain), Email Sentinel is $30 per month (up to 5 active domains) and Email Fortress is $45 per month (up to 25 active domains). All three include hosted DMARC, SPF and DKIM management, and a 14-day free trial is available with no credit card.

Yes. We configure SPF, DKIM and DMARC for both, along with the third-party services that send mail on your behalf, such as marketing platforms, CRMs, helpdesk tools and invoicing software. We also tune connectors, transport rules and anti-spam settings so authentication and filtering work together.

BIMI displays your verified brand logo beside your messages in supporting inboxes. It requires an enforced DMARC policy and usually a verified mark certificate, so it is a finishing step rather than a starting point. It is optional, but it can improve brand recognition and trust once DMARC is at enforcement.

Use the free domain checker near the top of this page. Enter your domain and it scans your DMARC, SPF, DKIM, BIMI and MTA-STS records and shows what is missing or misconfigured, with no signup required.

Yes. We identify why a domain or IP was listed, fix the underlying cause and submit delisting requests. If your domain is being spoofed, we move it through a monitored DMARC rollout to enforcement so the abuse stops, and the reports show exactly what was being sent in your name.

Related: IT security blog · Managed IT plans · Online presence & local SEO · Cloud backup

✨ NO CREDIT CARD REQUIRED

Try It Free for 14 Days

We’ll deploy DMARC monitoring on your domain, collect real reports from Gmail, Outlook and Yahoo, and walk you through exactly who is sending as you. Keep the records whether you stay or not.

📊
Live DMARC Reports
🛡️
SPF & DKIM Setup
👤
Engineer Walkthrough
🚫
Cancel Anytime
No credit card · No contract · Setup within 1 business day

Get Your Email Protected

Tell us about your setup and we'll provide a free assessment and quote.

💬 Chat with Us