Email and domain
SPF
Sender Policy FrameworkA TXT record in your domain's DNS listing the servers and services allowed to send email on your behalf. A receiving server compares the message's origin with that list. It ends in -all (reject anything unauthorised) or ~all (mark as suspicious). SPF has a limit of ten DNS lookups, which is easily exceeded as services are added.
Risk if missing: spoofing of your domain from other servers, and poorer deliverability of your legitimate email.
Back to indexDKIM
DomainKeys Identified MailA cryptographic signature your server adds to every outgoing message. The public key is published in DNS under a “selector”, and the receiver uses it to verify that the message came from your domain and was not altered. Keys of at least 2048 bits are recommended.
Risk if missing: undetectable message tampering and less reliable DMARC results, especially for forwarded email.
Back to indexDMARC
Domain-based Message Authentication, Reporting and ConformanceA policy published in DNS stating what to do with messages that fail SPF and DKIM aligned with your domain: nothing (p=none), send to spam (quarantine) or reject (reject). It also asks receivers for daily reports showing who sends email using your domain.
Risk if missing: fraud impersonating your company without your knowledge, and growing rejection by Gmail, Yahoo and Microsoft if you send in volume.
Back to indexMTA-STS
SMTP MTA Strict Transport Security (RFC 8461)A policy published at https://mta-sts. + your domain that requires sending servers to deliver to you only over TLS, with a valid certificate for your MX servers. In enforce mode, if a secure connection is not possible, the sender does not deliver the message instead of sending it unencrypted.
Risk if missing: downgrade attacks to plain text, or diversion of your incoming email to a fake server.
Back to indexTLS-RPT
SMTP TLS Reporting (RFC 8460)A DNS record asking sending servers for a daily report on their encrypted delivery attempts: how many succeeded, how many failed and why. It is the early-warning system for MTA-STS and DANE.
Risk if missing: delivery failures caused by expired certificates or misconfigurations go unnoticed.
Back to indexDNSSEC
Domain Name System Security ExtensionsA DNS extension that cryptographically signs the answers from your zone. Validating resolvers discard forged answers. It is enabled at your DNS provider and completed by publishing a DS record at your domain registrar.
Risk if missing: forged DNS answers that divert users or email, and no possibility of using DANE.
Back to indexDANE
DNS-based Authentication of Named EntitiesPublishes your mail server's certificate fingerprint in a TLSA record protected by DNSSEC. Senders that validate DANE only deliver to the server whose certificate matches. Exchange Online supports it for inbound email on its DNSSEC-enabled MX hosts; Google Workspace does not.
Risk if missing: without a cryptographic anchor, a sender can be tricked into delivering your email to an impostor.
Back to indexBIMI
Brand Indicators for Message IdentificationA DNS record pointing to your company logo in SVG Tiny PS format, so supporting mailboxes can display it next to your messages. Requires DMARC at quarantine or reject. Display depends on each provider: Gmail requires a VMC or CMC certificate, and Outlook does not display BIMI logos.
If missing: none for security; you do lose a visible authenticity signal towards your customers.
Back to indexVMC
Verified Mark CertificateAn annual certificate, issued by an authorised certificate authority, that links your logo to a registered trademark. With a VMC, Gmail shows the logo together with a verified checkmark.
If missing: your BIMI record is not shown in Gmail.
Back to indexCMC
Common Mark CertificateAn alternative to the VMC for logos without a registered trademark: it requires proof that the logo has been used publicly for at least 12 months. Gmail shows the logo, but without the checkmark. It usually costs less than a VMC.
If missing: your BIMI record is not shown in Gmail.
Back to indexVMC vs CMC
Which one to chooseIf your logo is a registered trademark, a VMC gives the fullest presentation. If it is not, or the registration is pending, a CMC lets you show the logo in Gmail provided you can prove 12 months of use. Both are renewed yearly.
If chosen wrongly: paying for a certificate your case does not need, or being unable to obtain either.
Back to indexCAA
Certification Authority Authorization (RFC 8659)A DNS record stating which certificate authorities may issue TLS certificates for your domain. With the iodef tag, it also says where to report unauthorised attempts.
Risk if missing: any authority can issue a certificate for your domain, making it easier to impersonate your sites and servers.
Back to indexAI, governance and regulation
NIST AI RMF
NIST AI Risk Management Framework (US)A voluntary framework published by the US National Institute of Standards and Technology in 2023 to identify and manage the risks of artificial intelligence. It is organised in four functions: Govern, Map, Measure and Manage. In 2024 it was complemented by a profile specific to generative AI.
Risk if ignored: AI decisions without a common method, making it hard to demonstrate due diligence to boards, customers or auditors.
Back to indexISO/IEC 42001
Artificial intelligence management systemAn international standard published in 2023 that sets out the requirements for a management system for the responsible development and use of AI, with the same structure as ISO/IEC 27001. It is certifiable. An organisation can align with it without being certified.
Risk if ignored: AI use without defined roles, controls or evidence — something customers and tenders are starting to require.
Back to indexEU AI Act
Regulation (EU) 2024/1689A European regulation that classifies AI systems by risk level, prohibits certain uses and sets obligations for providers and professional users (deployers). Its provisions apply in stages from 2025. It can reach organisations outside the EU when their AI systems, or the output of those systems, are used in the Union.
Risk if ignored: non-compliance when offering products or services to European customers. Each case requires legal analysis.
Back to indexLaw 31814 (Peru)
Law promoting the use of artificial intelligence for the country's economic and social developmentA 2023 Peruvian law that promotes the use of AI under principles such as transparency, privacy and respect for fundamental rights. Its implementing regulation, approved later, develops a risk-based approach. The Presidency of the Council of Ministers acts as the technical and regulatory authority.
Risk if ignored: adopting AI without considering obligations the regulation introduces progressively. We recommend validating each case with legal counsel.
Back to indexNIS2
Directive (EU) 2022/2555A European cybersecurity directive requiring medium-sized and large entities in essential and important sectors to manage risks, report incidents and oversee their suppliers, with direct accountability for management. Each member state transposes it into its own law; in the Netherlands, the Cyberbeveiligingswet.
Risk if ignored: even if your company is outside the EU, your European customers may require equivalent controls from you as a supplier.
Back to indexSecure AI practices
Oversharing
Excessive sharing of informationFiles and sites shared with more people than necessary, often through links open to the whole organisation. Assistants such as Copilot or Gemini respect existing permissions, so they surface in seconds everything a user can already open.
Risk if missing: an AI assistant answers with salary, legal or customer information to someone who should not see it.
Back to indexDLP and sensitivity labels
Data Loss PreventionLabels that classify documents by sensitivity, and rules that stop labelled information from leaving the organisation or being processed improperly. In Microsoft 365 they are managed with Microsoft Purview; in Google Workspace, with Drive labels and DLP rules.
Risk if missing: sensitive data copied into external tools or shared without control.
Back to indexLeast privilege
Minimum necessary accessEach person, service account or AI agent gets only the permissions needed for its task, and nothing more. In automation this means dedicated accounts, narrowly scoped permissions and credentials that are not shared between workflows.
Risk if missing: a leaked credential or a badly instructed agent can read, change or delete far more than necessary.
Back to indexHuman in the loop
Human oversightA design in which a person reviews and approves the highest-impact actions of an automated system or AI agent — such as payments, messages to third parties or deletions — before they are carried out.
Risk if missing: errors or manipulation of an agent are executed without anyone stopping them.
Back to indexDescriptions of standards and laws are general and for information only; they do not constitute legal advice.