Service
Email authentication audit and remediation
The audit establishes the state of your SPF, DKIM and DMARC records, draws up the complete list of services sending email in your name, fixes what is missing, then moves DMARC to rejection in stages. Two to three weeks, most of it on my side: for you it is one scoping call and a handful of DNS changes.
Duration · Two to three weeks
Who it is for
- A small firm or professional practice of five to two hundred people, with a domain name and clients who receive invoices.
- An organisation that already has a DMARC record stuck in monitoring and does not know how to go further without breaking its mail.
- A company whose customer, insurer or compliance questionnaire has just asked the question.
- A sender exceeding 5,000 messages a day to Gmail, Yahoo or Outlook and seeing
550 5.7.515rejections appear.
Who it is not for
- A domain that sends no email at all: publish a rejection policy and an empty SPF record. It is free and takes ten minutes, and the guides show how.
- An organisation that already has a security officer and a DMARC platform: the work there is project management, not audit.
- A need for managed IT, backup or general helpdesk. That is not the trade.
What happens, week by week
- 01
The audit, one hour
It relies only on the public DNS records of your domain, the ones anyone can look up. No access to your systems is needed, and you can run the same audit yourself, free, on this site.
- 02
The inventory, two to four weeks
A DMARC record in monitoring brings a daily account of what was sent in your name. That is what reveals the forgotten senders: the invoicing package bought six years ago, the recruitment platform, the newsletter an intern set up.
- 03
The alignment, half a day
Every legitimate sender has to pass SPF or DKIM on your domain, not on their provider's. That is the technical part, and the one that takes the most back-and-forth with suppliers.
- 04
The tightening, one to two weeks
Quarantine, then rejection, then strict alignment. Never at once, and never before the reports are clean. The procedure is published in full in the corresponding guide: nothing I do is a secret.
The access I need
| Stage | Access required |
|---|---|
| Initial audit | None. Public DNS only. |
| Implementation | The domain's DNS zone, or you enter the values I provide yourself. |
| Aligning providers | Nothing from me: you enable DKIM at each of them, with the steps written out. |
| Your mailboxes | Never. |
What you get
- 01A written audit of the starting state, in plain language, readable by a board.
- 02The named list of every service sending in your name, including the ones nobody had in mind.
- 03The exact values to publish, ready to paste, for each record.
- 04A DMARC record at rejection, with strict alignment, and the evidence that nothing legitimate is being blocked.
- 05A point of contact for the six months that follow, for when you change tools.
FeesFees depend on how many domains and sending services you run. They take a few minutes to discuss on the phone.
Common questions
The work itself, explained in full and free
Fifteen minutes on the phone is enough to establish whether your domain is exposed, and the call commits you to nothing.