Ruvalin

Service

Continuous monitoring and monthly report

Once the configuration is live, mail servers around the world send back a daily XML account of what was sent in your name. Monitoring means collecting them, reading them, and sending you a monthly summary in plain language: who tried to impersonate your domain, what was rejected, and what needs adjusting when you change tools.

Duration · Monthly, with no minimum term

Who it is for

  • A domain already at rejection whose reports nobody opens, because they arrive as compressed XML files.
  • A company that changes tools regularly: a new CRM, a new invoicing system, a new sending platform. Each change can break alignment without warning.
  • An organisation that has to account for its arrangements to an insurer, a customer or a board.

Who it is not for

  • A domain still at p=none: monitoring only makes sense after the rollout, and the audit comes first.
  • A team that already has someone to read these reports and the time to do it. The reader published on this site is free.

Why this does not happen on its own

An aggregate report is a compressed XML file, sent once a day per mailbox provider. An ordinary domain receives between five and thirty a day. Opened in a text editor they are unreadable; accumulated in a mailbox they become noise, and noise eventually gets filtered.

This is the commonest point of failure: the configuration is correct, the reports arrive, and nobody looks at them after the first month. An impersonation campaign then goes unnoticed exactly as if nothing had been set up.

What the summary contains

  • Total volume sent in your name, and how it breaks down by source.
  • Impersonation attempts: how many, from where, against which mailboxes, and what became of them.
  • Legitimate senders that have started failing, with the cause. It is nearly always a tool change nobody mentioned.
  • New sources appearing during the month, to be identified.
  • What to change, if anything, with the exact value.

What these reports contain, and what they do not

An aggregate report contains no message content and no recipient addresses: only counters by source IP address. That is what makes processing them straightforward under the GDPR, and it is also why monitoring gives access to nothing your staff write.

Detailed failure reports (ruf) can contain headers from real messages. They are not enabled, deliberately: they add little and commit a great deal.

What you get

  1. 01Daily collection of reports from every provider, on a dedicated address.
  2. 02A one-page monthly summary in plain language.
  3. 03An out-of-cycle alert if a spike in impersonation or an alignment failure appears.
  4. 04The corrections to make, with exact values, when a tool change breaks something.

FeesFees depend on how many domains are monitored. They take a few minutes to discuss on the phone.

Common questions

The work itself, explained in full and free

Fifteen minutes on the phone is enough to establish whether your domain is exposed, and the call commits you to nothing.

Services

CallBook