Sender authentication
SPF scope and lookup pressure, DKIM selector visibility, DMARC policy, reporting addresses, and domain-alignment signals.
A business domain is part of its reputation. Missing, conflicting, or overly permissive email-authentication records can make impersonation easier and legitimate delivery less predictable. We review the public configuration and turn it into a controlled fix plan.
The service examines public controls that help receiving systems verify who is allowed to send mail for the domain.
SPF scope and lookup pressure, DKIM selector visibility, DMARC policy, reporting addresses, and domain-alignment signals.
MX records, nameservers, CAA, certificate behavior, duplicate or conflicting records, and public configuration consistency.
Visible spoofing risk, weak policy posture, subdomain considerations, missing controls, and configuration dependencies that need owner review.
The goal is not to dump record values. The report explains what the configuration means and how to improve it without breaking legitimate senders.
| Finding | What the report explains | Recommended response |
|---|---|---|
| SPF conflict or excessive lookups | Which public mechanisms contribute to failure or maintenance risk. | Consolidate authorized senders carefully and retest before enforcement. |
| DKIM not visible | Whether the expected selector is publicly available and what evidence is missing. | Confirm the sending platform and publish the owner-approved record. |
| DMARC policy gap | Current policy posture, alignment, reporting configuration, and rollout risk. | Use a staged policy plan based on legitimate sending sources and reports. |
| Routing inconsistency | Conflicting MX or DNS signals and the services they may affect. | Validate business dependencies before changing production records. |
Every recommendation is designed to be reviewed by the domain owner or the team responsible for DNS and email administration.
Observed public records, alignment relationships, certificate behavior, and the affected domain or subdomain.
Immediate risks, safe preparation steps, dependencies, owner decisions, and recommended order of change.
Clear checks to confirm that owner-approved changes are published and visible without exposing private mail.
Safe boundaries protect employees, customers, and production communication.
We do not read mail, inspect employee accounts, collect credentials, or monitor users.
Employee testing and social-engineering exercises require a separate written engagement.
The audit recommends changes. Implementation occurs only with explicit owner approval and a rollback plan.
Combine domain security with the public website controls that visitors and browsers depend on.
We will inspect public records and explain whether the full $390 audit is the right next step.