Email and domain security

Email security, from SPF to DANE

Your domain is your company's identity on the internet. We configure and monitor the controls that stop others from sending email in your name and that protect the email you receive while it travels across the internet. No platform migration: everything is implemented in your own DNS.

The complete stack, in plain language

Each control solves a different problem. None is enough on its own; together they close the gaps exploited by email spoofing and interception.

1. Who may send in your name?

Sender authentication

SPF

Sender Policy Framework

The public list of servers allowed to send email as your domain. Receiving servers check it for every incoming message.

Risk if missing: anyone can send email from other servers using your domain, and your legitimate email is more likely to land in spam.

More in the glossary

DKIM

DomainKeys Identified Mail

A digital signature on every message, proving it came from your organisation and was not altered on the way.

Risk if missing: message integrity cannot be checked, and DMARC loses its strongest authenticity signal, especially for forwarded email.

More in the glossary

DMARC

Domain-based Message Authentication, Reporting and Conformance

Your instruction to the world: “if a message fails SPF or DKIM, reject it — and send me reports.” At p=reject, direct spoofing of your domain stops working.

Risk if missing: your domain can be used in fraud impersonating your management or finance team without you noticing. Gmail, Yahoo and Microsoft require DMARC from bulk senders.

More in the glossary

2. Is the email you receive protected in transit?

Encrypted, verified transport

MTA-STS

SMTP MTA Strict Transport Security

Tells other mail servers: “only deliver to me over an encrypted connection with a valid certificate.” Without this policy, encryption between mail servers is optional.

Risk if missing: an attacker on the path can force email to you to travel unencrypted, or divert it to a fake server.

More in the glossary

TLS-RPT

SMTP TLS Reporting

Daily reports from sending servers on whether they could deliver to you over an encrypted connection, and if not, why.

Risk if missing: an expired certificate or a misconfiguration can block or degrade incoming email for days without anyone noticing.

More in the glossary

DNSSEC

Domain Name System Security Extensions

A cryptographic seal on your domain's DNS answers, so nobody can forge them along the way.

Risk if missing: your domain's DNS answers can be forged without the resolver noticing, and DANE cannot be used.

More in the glossary

DANE

DNS-based Authentication of Named Entities (TLSA records)

Publishes your mail server's certificate fingerprint in signed DNS, so senders cannot be fooled by an impostor. Stricter than MTA-STS; requires DNSSEC.

Risk if missing: senders that validate DANE have no cryptographic anchor to verify they are delivering to the right server. In the Netherlands and Germany it is a common public-sector requirement.

More in the glossary

3. Is your brand recognised, and who issues your certificates?

Brand and certificates

BIMI

Brand Indicators for Message Identification

Shows your company's verified logo next to your messages in supporting mailboxes. Only works with DMARC at quarantine or reject.

Risk if missing: you lose a visible authenticity signal towards your customers. It is not a protective control itself, but the reward for having the others in order.

More in the glossary

VMC and CMC

Verified Mark Certificate · Common Mark Certificate

Annual certificates proving your right to use the logo. A VMC requires a registered trademark; a CMC requires at least 12 months of public use of the logo. Gmail requires one of the two to show the logo.

Risk if missing: your BIMI record exists, but Gmail does not show the logo.

More in the glossary

CAA

Certification Authority Authorization

A DNS record stating which certificate authorities may issue certificates for your domain, and whom to notify if someone tries.

Risk if missing: any certificate authority can issue a certificate for your domain, making fake sites and servers easier to pass off as genuine.

More in the glossary

How we work

We move in stages, guided by data, so that no legitimate email is blocked along the way.

  1. Assessment

    We scan your domain with our checker and review your DNS and email platform.

  2. Inventory

    Using DMARC reports, we identify every service that sends in your name: ERP, invoicing, marketing, alerts.

  3. Authentication

    We fix SPF and DKIM, then move DMARC from p=none to quarantine and on to reject.

  4. Transport

    We enable MTA-STS and TLS-RPT; on Microsoft 365, DNSSEC and DANE as well.

  5. Monitoring

    We review reports and alerts every month and tell you when something changes.

Plans and pricing

Indicative pricing

Prices in US dollars, excluding IGV/VAT. The check and the basic records are free; monitoring is a subscription; DANE and BIMI are fixed-price projects.

Self-service

Check

Free

No sign-up

To see where you stand and what to publish first.

  • Public checker with score
  • Exact SPF, DKIM and DMARC records for your domain
  • Re-check whenever you need
Check your domain
Subscription

DMARC Monitor

$19per month, per domain

or $190 per year (2 months free)

To reach p=reject without blocking legitimate email, and stay there.

  • Aggregate DMARC report processing
  • Inventory of services sending in your name
  • Alerts reviewed by an M&T Strategies specialist
  • Monthly summary in Spanish or English
  • Guidance all the way to p=reject
Request
Subscription

Secure Transport

$9per month, per domain

or $90 per year (2 months free)

MTA-STS and TLS-RPT hosted on our infrastructure.

  • MTA-STS policy hosted at mta-sts. + your domain, with certificate
  • Policy updates when your MX records change
  • TLS-RPT report processing and alerts

Please noteYou publish two records in your DNS; we host the policy. If you cancel, we hand the policy over so you can host it yourself.

Request
Project

DNSSEC + DANE

$890one-off, per domain

Microsoft 365 or your own mail server

Cryptographically verified email transport.

  • DNSSEC enabled at your DNS provider
  • Switch to the Exchange Online DNSSEC MX without downtime
  • TLSA record verification
  • Before/after report

Please noteNot available for Google Workspace: Gmail publishes no TLSA records for inbound email. Your DNS provider must support DNSSEC. DANE protects against senders that validate it.

Request
Project

BIMI

$690one-off + certificate at cost

Requires DMARC at quarantine or reject

Your logo next to your messages in supporting mailboxes.

  • Logo conversion to SVG Tiny PS
  • Logo hosting and BIMI record
  • Support with the VMC or CMC application

Please noteGmail only shows the logo with a VMC or CMC certificate, which is paid separately and renewed yearly. Outlook does not display BIMI logos.

Request
Tailored

Enterprise

Let's talk

Scope set after assessment

For corporate groups and needs beyond email.

  • Portfolios of multiple domains and brands
  • Secure AI adoption
  • AI process automation
  • Managed IT
See Enterprise

Indicative pricing, to be confirmed in the proposal. Per domain unless stated otherwise. The annual subscription costs the same as ten months.

What you should know before you buy

We would rather you hear it from us than find out later.

  • Moving DMARC to reject without a complete inventory can block legitimate email, such as electronic invoices sent by a provider on your behalf. That is why we move in stages, guided by reports.
  • DANE only protects against senders that validate it. MTA-STS covers the rest, which is why we recommend both.
  • Google Workspace does not support DANE for inbound email. On Google Workspace, MTA-STS and TLS-RPT are the maximum available.
  • BIMI does not stop any attack: it shows your logo once everything else is in order. Gmail requires a VMC or CMC; Outlook does not display BIMI logos.
  • Everything stays in your DNS and your tenant. There is no technical dependency on M&T Strategies, except the MTA-STS policy while we host it.

Start with the free check

Check your domain in seconds. If you want help with the result, write to us and we will go through it with you.