Engineering capabilities
- Monitoring policy with aggregate reporting
- Report analysis and sender remediation
- Staged progression to quarantine then reject
- Subdomain policy and alignment mode design
Security & DNS
The policy layer that tells receivers what to do with mail failing SPF and DKIM alignment, moved to enforcement in stages so legitimate mail is never lost.
Policy is raised in steps, guided by aggregate reports, so spoofing is blocked without collateral damage to legitimate mail.
Two to four weeks of reporting establishes who is really sending as the domain.
Every legitimate source is brought into alignment before policy moves.
Percentage ramp limits exposure while behaviour is confirmed.
Enforcement with continued report monitoring so new senders are caught early.
Not if the rollout is staged. Policy stays at monitoring until reports show every legitimate source authenticating and aligning, which is exactly what the reporting phase is for.
Typically six to twelve weeks for a normal estate, longer where many third-party platforms send on the domain.
The domain in the visible From address must match the domain validated by SPF or DKIM. Authentication can pass while alignment fails, and DMARC only accepts an aligned pass.
Send the environment details and get an engineered proposal with assumptions, risks and a rollback path.