Ruvalin

Email security for small firms and professional practices

Nobody should be able to email your clients in your name.

Today, anyone can.

We publish the SPF, DKIM and DMARC records on your domain that get those messages refused before they arrive.

Public DNS records only. No access to your systems, no scanning, no email sent. Checked domains are not retained.

97.6%

of the 1,115 French estate agencies whose DNS records we read have no active protection against impersonation.

Read in August 2026, from public DNS records. Two domains out of 1,115 were at rejection.

01

The problem

An email in your company’s name tells a client that your bank details have changed, a few days before a payment is due. They pay the fraudster.

Typing “accounts@your-company.com” into the From field takes the same skill as typing the subject line.

Three records published on your domain fix this: SPF, DKIM and DMARC. Most of the ones we look up are still in monitoring, where impersonation is observed and never blocked.

Example
From
accounts@your-company.com
Subject
Updated bank details

Authentication-Results: … dmarc=fail (p=none) header.from=your-company.com

  • p=noneno instruction
  • p=rejectrejection requested

1,115 estate agencies, August 2026

  • 756no DMARC record
  • 332p=none
  • 17undetermined
  • 8p=quarantine
  • 2p=reject

02

Services

  1. Email authentication audit and remediation

    Your SPF, DKIM and DMARC records established, every service sending in your name listed, then DMARC moved to rejection in stages.

  2. Continuous monitoring and monthly report

    We collect the reports receiving servers send back and give you a monthly summary: who tried to impersonate you, what was refused, what needs adjusting.

  3. Phishing awareness training for your staff

    Measured simulation campaigns, then a short session: the three checks to make before approving a transfer.

03

Price and what happens next

Audit and setup
from€1,200
Monitoring and monthly report
€120a month

The exact fee depends on how many domains and sending services you run. You get it during the call.

  1. 1

    The fifteen-minute call

    We look your domain up while we are on the phone and tell you what protects you. Nothing is sold at this stage.

  2. 2

    The written audit

    The state of your records, and the list of services sending in your name.

  3. 3

    The proposal

    A firm price, a duration, and what stays on your side. Valid for thirty days.

  4. 4

    Setup

    Two to three weeks, almost entirely on our side. On yours, a handful of DNS changes to sign off.

04

Common questions

05

The record we publish

The complete record, exactly as it will be published on your domain.

_dmarc.your-company.com

published in your domain’s DNS, under this name

v=DMARC1; p=reject; rua=mailto:dmarc@ruvalin.com; pct=100; adkim=s; aspf=s
v=DMARC1
The version of the standard.
p=reject
Refuse any message claiming to come from us that cannot prove it. This is the line that protects you, and it is almost always the missing one. We get there in stages, over a few weeks.
rua=mailto:dmarc@ruvalin.com
The address where receiving servers send their daily account of what arrived in your name.your-company.com._report._dmarc.ruvalin.com IN TXT "v=DMARC1"That address is ours. The standard requires the domain receiving the reports to declare that it accepts them, which is all this record says. Without it the large operators send nothing.
pct=100
The share of messages the instruction applies to. It starts lower and ends at a hundred.
adkim=s; aspf=s
Strict alignment: the domain your client sees must be the one that signed the message, not a subdomain that resembles it.

Want to know what is published on yours? Check your domain

06

Contact

Fifteen minutes on the phone is enough to establish whether your domain is exposed.

Who you will be speaking to

Ruvalin is the sole trader business of Tom Gernez, in Montigny-lès-Metz, France. You will have the same person from the first call through to the final report.

The practice and the full legal identity

Ten booby-trapped messages, shown as they really arrive. The test tells you which ones would have caught you. Take the test

CallBook