Ruvalin

Email security for small firms and professional practices

Nobody should be able to email your clients in your name.

Today, anyone can. Nothing in the way email works checks that a sender is who they claim to be. Your clients, your suppliers and your accountant have no way of telling. Ruvalin puts in place the protections that get those messages rejected before they arrive.

01

The problem

The common fraud is not dramatic: an email in your company's name tells a client that your bank details have changed, a few days before a payment is due. The transfer goes out. It does not come back.

Email was designed in 1982, when the handful of connected networks trusted one another. Nothing in the protocol checks a sender's identity. Typing “accounts@your-company.com” into the From field takes exactly as much technical skill as typing the subject line.

Three records, added to your company's domain name, fix this: SPF, which declares which servers may send on your behalf; DKIM, which puts a cryptographic signature on every legitimate message; and DMARC, which tells receiving servers what to do with messages that fail the first two checks. Few firms your size have all three in place, and fewer still have gone as far as rejection. A DMARC record left in monitoring is an alarm fitted but never wired in.

02

What we install, in full

No black box. This is the complete record, exactly as it will be published on your domain, and what each part of it says.

_dmarc.your-company.com

published in your domain's DNS, under this name

v=DMARC1; p=reject; rua=mailto:rapports@ruvalin.com; pct=100; adkim=s; aspf=s
v=DMARC1
The version of the standard. It is always this one.
p=reject
The instruction: refuse any message claiming to come from us that cannot prove it. This is the line that actually protects you, and it is the one that is almost always missing.
rua=mailto:rapports@ruvalin.com
The address where mail servers around the world send their daily account of what they received in your name. This is what makes monitoring possible at all.
pct=100
The share of messages the instruction applies to. During the staged rollout we deliberately start lower.
adkim=s; aspf=s
Strict alignment: the domain your client sees must be exactly the one that signed the message, not a subdomain that resembles it.

03

Services

  1. Email authentication audit and remediation

    We establish the state of your SPF, DKIM and DMARC records, and we draw up the full list of services sending email in your name: mailboxes, invoicing, newsletters, booking tools. We fix what is missing, then move DMARC to rejection in stages, once every legitimate sender has been accounted for.

  2. Continuous monitoring and monthly report

    Once the configuration is live, mail servers around the world send back a daily account of what was sent in your name. We collect them, we read them, and you get a monthly summary in plain language: who tried to impersonate your domain, what was rejected, and what needs adjusting when you change tools.

  3. Phishing awareness training for your staff

    No technical control stops an employee replying to a message from a domain that merely looks like yours. We run measured simulation campaigns, then a short session with no jargon: the three checks to make before approving a transfer or typing a password. The point is vigilance, not blame.

Fees depend on how many domains and sending services you run. They take a few minutes to discuss on the phone.

04

Who

Ruvalin is the practice of Tom Gernez, a French independent information security consultant. He will be the same person you speak to from the first call through to the final report.

Engagements involving penetration testing are delivered together with senior partner engineers, under my responsibility. Everything else I do myself: audit, configuration, monitoring, training.

You will find no client logos here, no testimonials and no numbers. Discretion is part of the work, and I would rather be judged on what I say on the phone.

05

Common questions

06

Contact

The phone is still the quickest route. Fifteen minutes is enough to establish whether your domain is exposed, and the call commits you to nothing.

Telephone
+33 6 44 64 17 13