Email authentication

Whether your domain can be used to impersonate you, and whether you would find out before a client did.

Email authentication is the rare control that fails silently. A domain can be sending mail that quietly lands in spam, or be open to anyone forging mail in its name, with nothing bouncing and nobody told. The records meant to prevent it, SPF, DKIM and DMARC, are usually present and usually not enforcing, which reads as protection and is not.

It is also the one part of your posture that can be checked from the outside, before any engagement, using only your public DNS. That is the same information an attacker reads to decide whether a domain is worth forging.

It runs across whole sectors. In June 2026 scans, 59 percent of 252 Australian law firms were open to a forged settlement email, and two in three of 124 wineries to a forged message reaching their wine club.

The check

A read of your public records in plain English: what is published, what it actually does, and whether your domain can currently be forged. It tells you what is wrong and why. It does not tell you how to fix it, because knowing what correct looks like and verifying it afterwards is the work.

The lookups run live against public DNS. The domain is not stored.

The fix

If you would rather have it handled than pass the findings to your own IT provider, the fix is a fixed AUD 650 + GST. One engagement, no retainer, scheduled and verified, with you keeping control of your systems throughout. The price covers the expertise and the verification, not the keystrokes.

If the fix leads within sixty days to the posture review, the $650 comes off that price. You do not pay twice for me to look at the same environment.

The read is yours to keep either way. If you would like it handled, the contact details are below. And if the concern is broader than email, the posture review looks at this same area alongside identity, endpoints, backup and ownership.

Common questions

What happens to the domain I type into the check?
It is looked up live against public DNS and the result is shown to you. It is not logged, stored or added to any list. The records read are the same ones anyone on the internet can read.
We send through Microsoft 365. Is this not already handled?
Microsoft signs the mail it sends, but the records that tell the world what to do with forged mail live in your DNS, and Microsoft does not set them for you. Most tenants have the records present and not enforcing, which reads as protection and is not.
Our email seems fine. Why would this matter?
Because the failure is silent. Mail landing in spam does not bounce, and a forged email sent in your name never touches your systems at all. The first sign is usually a client asking about an email you never sent.
Does the fix need access to our systems?
The changes are DNS records, made in your DNS host with you keeping control throughout, then verified from the outside afterwards. No passwords change hands and nothing is installed.

Let's talk.

If you want to work together, book a call below. If you would rather write first, email me and I will get back to you.