Email Security & Anti-Phishing (DMARC)
Email security and DMARC done right: SPF, DKIM and DMARC to p=reject safely, report monitoring and anti-phishing. Stop domain spoofing. Free scoping call.
Email security and DMARC stop criminals from sending mail that looks like it came from your domain, and they cut the phishing and invoice-fraud attempts that land in your own staff’s inboxes. We set up SPF, DKIM and DMARC correctly, move you safely to an enforcing policy, and monitor the reports so a spoofing attempt against your brand becomes an alert rather than a customer’s loss.
SafetyBis is a European offensive-security team. We harden email for organisations across Europe and remotely worldwide, and we have run the phishing simulations that show how easily a spoofed sender gets a click. Email is still the front door for most breaches. The good news is that the controls to shut the obvious spoofing are well defined, free to implement, and badly configured almost everywhere.
What email security and DMARC actually covers
There is more to this than one DNS record. Real protection combines authentication so receivers can trust your mail, a policy that tells them what to do with fakes, monitoring so you can see who is sending as you, and inbound defence so the phishing aimed at your people is caught. Each piece does a different job, and leaving one out leaves the door ajar.
Authentication: SPF, DKIM and DMARC
These three work together. SPF lists which servers are allowed to send for your domain. DKIM signs each message so the receiver can verify it was not tampered with and really came from you. DMARC ties the two to the visible From address through alignment, and tells receiving servers what to do when a message fails. Miss the alignment and an attacker can still forge the address your users actually see, even with SPF and DKIM technically passing.
The policy that does the work
A DMARC record with p=none monitors but blocks nothing. It is a starting point, not protection. The protection comes from moving to p=quarantine and then p=reject, at which point receiving servers actively bin mail that fails your checks. The whole risk is doing that without accidentally blocking your own newsletters, your CRM or your finance system, which is why the move has to be evidence-led.
How we get you to enforcement safely
The reason so many domains sit stuck on p=none is fear of breaking legitimate mail. That fear is reasonable and entirely manageable. We use the reports to find every real sender first, fix their authentication, and only then tighten the policy.
Discovering every sender
Companies send mail from more places than they think: the mail platform, the CRM, the helpdesk, the marketing tool, the accounting system, the odd server someone set up years ago. We deploy DMARC in monitoring mode and read the aggregate reports to build a complete picture of who is sending as you, legitimate and not.
Fixing alignment for real senders
For each legitimate service we set up proper SPF entries and DKIM signing so it authenticates and aligns. This is the unglamorous work that makes enforcement safe. Skip it and moving to reject silently drops mail your business depends on.
Tightening the policy in stages
We step the policy up deliberately, often using the DMARC percentage tag to enforce on a slice of traffic first, watching the reports at each stage. By the time you reach p=reject, we have evidence that no legitimate mail is caught, and forged mail from your domain is being rejected outright.
What enforcement actually buys you
Once you are at p=reject, an attacker can no longer send mail that appears to come from your exact domain to any receiver that honours DMARC, which is essentially all the major providers. That closes off the most convincing phishing, the fake invoice that appears to come from your CEO, and the supplier-impersonation fraud that hits your customers. It also protects your deliverability and your brand.
Inbound defence and business email compromise
DMARC stops people spoofing your domain. It does nothing about the phishing arriving in your own inboxes from lookalike domains and compromised third parties, and that is where the expensive fraud usually happens.
Lookalike and cousin domains
Attackers register domains that read like yours at a glance, then send convincing mail from them. We help you monitor for these registrations and configure inbound rules and warnings so a message from a near-miss domain is flagged before someone acts on it.
Business email compromise and invoice fraud
The costliest email attacks are not malware. They are a well-written message asking finance to change bank details or pay an urgent invoice, sent from a spoofed or compromised account. We tune inbound impersonation detection, add banners for external and first-time senders, and pair the technical controls with the awareness training that stops the click. The technology and the human have to both hold.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Encryption and brand trust
Two often-missed pieces round out a strong email posture: making sure mail is encrypted in transit, and earning the visible trust marks that raise your open rates.
MTA-STS and TLS-RPT
By default, mail servers will fall back to unencrypted delivery if TLS negotiation is downgraded, which opens the door to interception. MTA-STS tells sending servers to require TLS for your domain, and TLS-RPT reports any failures so you can see attempted downgrades. Together they close a quiet gap that most domains leave open.
BIMI and the verified logo
Once you are enforcing DMARC, BIMI lets your verified brand logo appear next to your messages in supporting inboxes. It is a reward for doing the authentication properly: better recognition, higher engagement, and one more signal to your recipients that the mail is genuinely from you.
Compliance and standards
Email authentication is increasingly expected rather than optional, both by regulators and by the mailbox providers themselves.
Provider requirements and frameworks
Major mailbox providers now require SPF, DKIM and DMARC for bulk senders, and failing to authenticate hurts your deliverability directly. ISO 27001 control A.8.23 covers web and messaging protections, and email fraud sits squarely in the risk assessments behind SOC 2, GDPR and DORA. We document the setup so it satisfies both the technical bar and the audit question.
Protecting personal data in transit
GDPR expects appropriate technical measures for personal data, and unencrypted email is a weak point. Enforcing TLS through MTA-STS is a concrete, demonstrable control you can point to.
Why have an offensive team run your email security
Configuring DMARC is not hard in theory. Doing it without breaking mail, keeping it enforced as your sending estate changes, and reading the abuse in the reports is where it goes wrong, and it is where our background helps.
We know what a convincing spoof looks like
In the phishing simulations we run for clients, the messages that get the most clicks are the ones that appear to come from a trusted internal or supplier address. Enforcing DMARC removes the most convincing version of that attack outright. Because we have sat on the attacker’s side, we prioritise the controls that actually change an attacker’s odds, not the ones that just look tidy on a scan report.
Reports read by a person, not a parser
Aggregate reports arrive as XML from dozens of receivers every day. A tool can chart them; it takes judgement to tell a newly onboarded marketing platform apart from a spoofing campaign warming up against your brand. We watch for the patterns that matter and tell you when something needs action, rather than leaving you a dashboard to interpret alone.
It stays fixed
Email estates drift. A new SaaS tool starts sending on your behalf, a record gets edited, a policy quietly slips. Ongoing monitoring catches the drift before it either breaks your mail or reopens the spoofing gap, so the protection you paid to set up is still real a year later.
Pricing
Email security dmarc cost depends on how many domains and sending services you have and whether you want a one-off setup or ongoing monitoring and inbound defence. Below is the shape of a typical monthly plan. Getting to enforcement is usually quick; the ongoing value is in the monitoring and the inbound protection.
| Plan | What’s covered | Response | Price per month |
|---|---|---|---|
| Starter | One domain: SPF, DKIM and DMARC set up, moved to enforcement, RUA report monitoring, quarterly review | Business-hours support | from €120/month |
| Growth | Multiple domains and senders, MTA-STS and TLS-RPT, BIMI, ongoing report monitoring with alerting on new spoofing sources | Same-day support, monthly review | from €250/month |
| Enterprise | Full estate plus inbound anti-phishing and impersonation defence, lookalike-domain monitoring, integration with awareness training | Priority support, monthly reporting | from €450/month |
| Managed retainer | End-to-end managed email security with a named contact, ongoing tuning and incident support for email fraud | 24/7 for active fraud incidents | from €800/month |
| Custom / large estate | Many domains, complex sending or M&A cleanup, scoped after a free call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, so there are no hourly surprises. Get a fixed quote
FAQ
How much does email security and DMARC cost?
What is the difference between SPF, DKIM and DMARC?
Will moving to p=reject break our legitimate email?
How long does it take to get to enforcement?
Does DMARC stop phishing aimed at our own staff?
What are the DMARC RUA and RUF reports for?
Do the mailbox providers actually require this now?
Does this help with ISO 27001 or GDPR?
Related services
Any organisation whose name gets spoofed or whose finance team gets fake payment requests: companies invoicing customers, firms handling supplier payments, and brands whose reputation suffers when phishing goes out under their domain. If your DMARC is still on p=none, you are being impersonated and cannot see it.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.