Glossary

Email security and AI glossary

The terms we use, in plain language: what each one is and what your company risks by ignoring it.

Email and domain

SPF

Sender Policy Framework

A TXT record in your domain's DNS listing the servers and services allowed to send email on your behalf. A receiving server compares the message's origin with that list. It ends in -all (reject anything unauthorised) or ~all (mark as suspicious). SPF has a limit of ten DNS lookups, which is easily exceeded as services are added.

Risk if missing: spoofing of your domain from other servers, and poorer deliverability of your legitimate email.

Back to index

DKIM

DomainKeys Identified Mail

A cryptographic signature your server adds to every outgoing message. The public key is published in DNS under a “selector”, and the receiver uses it to verify that the message came from your domain and was not altered. Keys of at least 2048 bits are recommended.

Risk if missing: undetectable message tampering and less reliable DMARC results, especially for forwarded email.

Back to index

DMARC

Domain-based Message Authentication, Reporting and Conformance

A policy published in DNS stating what to do with messages that fail SPF and DKIM aligned with your domain: nothing (p=none), send to spam (quarantine) or reject (reject). It also asks receivers for daily reports showing who sends email using your domain.

Risk if missing: fraud impersonating your company without your knowledge, and growing rejection by Gmail, Yahoo and Microsoft if you send in volume.

Back to index

MTA-STS

SMTP MTA Strict Transport Security (RFC 8461)

A policy published at https://mta-sts. + your domain that requires sending servers to deliver to you only over TLS, with a valid certificate for your MX servers. In enforce mode, if a secure connection is not possible, the sender does not deliver the message instead of sending it unencrypted.

Risk if missing: downgrade attacks to plain text, or diversion of your incoming email to a fake server.

Back to index

TLS-RPT

SMTP TLS Reporting (RFC 8460)

A DNS record asking sending servers for a daily report on their encrypted delivery attempts: how many succeeded, how many failed and why. It is the early-warning system for MTA-STS and DANE.

Risk if missing: delivery failures caused by expired certificates or misconfigurations go unnoticed.

Back to index

DNSSEC

Domain Name System Security Extensions

A DNS extension that cryptographically signs the answers from your zone. Validating resolvers discard forged answers. It is enabled at your DNS provider and completed by publishing a DS record at your domain registrar.

Risk if missing: forged DNS answers that divert users or email, and no possibility of using DANE.

Back to index

DANE

DNS-based Authentication of Named Entities

Publishes your mail server's certificate fingerprint in a TLSA record protected by DNSSEC. Senders that validate DANE only deliver to the server whose certificate matches. Exchange Online supports it for inbound email on its DNSSEC-enabled MX hosts; Google Workspace does not.

Risk if missing: without a cryptographic anchor, a sender can be tricked into delivering your email to an impostor.

Back to index

BIMI

Brand Indicators for Message Identification

A DNS record pointing to your company logo in SVG Tiny PS format, so supporting mailboxes can display it next to your messages. Requires DMARC at quarantine or reject. Display depends on each provider: Gmail requires a VMC or CMC certificate, and Outlook does not display BIMI logos.

If missing: none for security; you do lose a visible authenticity signal towards your customers.

Back to index

VMC

Verified Mark Certificate

An annual certificate, issued by an authorised certificate authority, that links your logo to a registered trademark. With a VMC, Gmail shows the logo together with a verified checkmark.

If missing: your BIMI record is not shown in Gmail.

Back to index

CMC

Common Mark Certificate

An alternative to the VMC for logos without a registered trademark: it requires proof that the logo has been used publicly for at least 12 months. Gmail shows the logo, but without the checkmark. It usually costs less than a VMC.

If missing: your BIMI record is not shown in Gmail.

Back to index

VMC vs CMC

Which one to choose

If your logo is a registered trademark, a VMC gives the fullest presentation. If it is not, or the registration is pending, a CMC lets you show the logo in Gmail provided you can prove 12 months of use. Both are renewed yearly.

If chosen wrongly: paying for a certificate your case does not need, or being unable to obtain either.

Back to index

CAA

Certification Authority Authorization (RFC 8659)

A DNS record stating which certificate authorities may issue TLS certificates for your domain. With the iodef tag, it also says where to report unauthorised attempts.

Risk if missing: any authority can issue a certificate for your domain, making it easier to impersonate your sites and servers.

Back to index

AI, governance and regulation

NIST AI RMF

NIST AI Risk Management Framework (US)

A voluntary framework published by the US National Institute of Standards and Technology in 2023 to identify and manage the risks of artificial intelligence. It is organised in four functions: Govern, Map, Measure and Manage. In 2024 it was complemented by a profile specific to generative AI.

Risk if ignored: AI decisions without a common method, making it hard to demonstrate due diligence to boards, customers or auditors.

Back to index

ISO/IEC 42001

Artificial intelligence management system

An international standard published in 2023 that sets out the requirements for a management system for the responsible development and use of AI, with the same structure as ISO/IEC 27001. It is certifiable. An organisation can align with it without being certified.

Risk if ignored: AI use without defined roles, controls or evidence — something customers and tenders are starting to require.

Back to index

EU AI Act

Regulation (EU) 2024/1689

A European regulation that classifies AI systems by risk level, prohibits certain uses and sets obligations for providers and professional users (deployers). Its provisions apply in stages from 2025. It can reach organisations outside the EU when their AI systems, or the output of those systems, are used in the Union.

Risk if ignored: non-compliance when offering products or services to European customers. Each case requires legal analysis.

Back to index

Law 31814 (Peru)

Law promoting the use of artificial intelligence for the country's economic and social development

A 2023 Peruvian law that promotes the use of AI under principles such as transparency, privacy and respect for fundamental rights. Its implementing regulation, approved later, develops a risk-based approach. The Presidency of the Council of Ministers acts as the technical and regulatory authority.

Risk if ignored: adopting AI without considering obligations the regulation introduces progressively. We recommend validating each case with legal counsel.

Back to index

NIS2

Directive (EU) 2022/2555

A European cybersecurity directive requiring medium-sized and large entities in essential and important sectors to manage risks, report incidents and oversee their suppliers, with direct accountability for management. Each member state transposes it into its own law; in the Netherlands, the Cyberbeveiligingswet.

Risk if ignored: even if your company is outside the EU, your European customers may require equivalent controls from you as a supplier.

Back to index

Secure AI practices

Oversharing

Excessive sharing of information

Files and sites shared with more people than necessary, often through links open to the whole organisation. Assistants such as Copilot or Gemini respect existing permissions, so they surface in seconds everything a user can already open.

Risk if missing: an AI assistant answers with salary, legal or customer information to someone who should not see it.

Back to index

DLP and sensitivity labels

Data Loss Prevention

Labels that classify documents by sensitivity, and rules that stop labelled information from leaving the organisation or being processed improperly. In Microsoft 365 they are managed with Microsoft Purview; in Google Workspace, with Drive labels and DLP rules.

Risk if missing: sensitive data copied into external tools or shared without control.

Back to index

Least privilege

Minimum necessary access

Each person, service account or AI agent gets only the permissions needed for its task, and nothing more. In automation this means dedicated accounts, narrowly scoped permissions and credentials that are not shared between workflows.

Risk if missing: a leaked credential or a badly instructed agent can read, change or delete far more than necessary.

Back to index

Human in the loop

Human oversight

A design in which a person reviews and approves the highest-impact actions of an automated system or AI agent — such as payments, messages to third parties or deletions — before they are carried out.

Risk if missing: errors or manipulation of an agent are executed without anyone stopping them.

Back to index

Descriptions of standards and laws are general and for information only; they do not constitute legal advice.

Which of these controls does your domain have?

The free checker reviews it in seconds and shows you what is missing.