Email authentication operations
See whether Gmail, Microsoft, and Yahoo are ready to accept your mail. Discover every sender, fix authentication blockers, manage SPF and DKIM, simulate enforcement before any DNS change, and verify the result afterwards.
Talk to Sales →No account needed for the readiness check. Gmail began SMTP rejections in November 2025; Microsoft high-volume sender rules are tightening through 2026.
Discover & classify senders
142 senders found · 12 unauthorized flagged
Simulate enforcement impact
2.1% mail affected · 0 legitimate senders blocked
Approve change & deploy
Approved by j.chen · rollback armed
Observe results
Day 5 / 14 · 98.3% pass · 1 anomaly flagged
Advance to full enforcement
Advance to full enforcement (p=reject)
Start here — no account needed
Check your domain against each major provider's sender requirements — from public DNS, in seconds. Here is the shape of the answer you get back:
Public DNS only tells part of the story. Connect DMARC reporting to identify your legitimate senders, uncover the blockers behind every failure, and know whether moving to p=reject is safe.
DMARC dashboards can tell you what is broken. That is not the hard part. The hard part is deciding what to change, proving it is safe, and carrying it through production DNS without disrupting legitimate mail. SpoofSentry closes that gap with governed workflows for sender discovery, failure root cause analysis, staged policy progression, and approval-gated change execution.
See which senders pass, fail, or need remediation before you tighten policy. Replay recent aggregate report data against quarantine or reject to understand the blast radius.
Keep humans in control with review points for sender authorization and enforcement changes. Every high-impact action is gated, scoped, and auditable.
Use fixed observation windows, structured outcomes, and rollback-aware execution to move toward enforcement safely. Prove progress to leadership with before/after enforcement proof.
See it in action
Every feature is operational — from onboarding checklists to HIPAA readiness checks.
Overview of your email authentication status
Signature capability
Most tools tell you whether you have a DMARC record. SpoofSentry tells you whether your domain is actually protected. The Domain Security Score is a 100-point composite across ten dimensions — not just authentication, but transport encryption (MTA-STS, TLS-RPT, DANE), DNS trust, and hidden takeover risk.
Bottom 30% for your sector · 3 issues to address
More than DMARC monitoring
DMARC is the foundation. SpoofSentry builds the entire security stack on top — from transport encryption to brand protection to automated threat response.
AI-powered ESP detection across 26+ providers. Behavioral profiling with hourly cadence fingerprinting, volume anomaly detection, and authentication degradation alerts. Full governance lifecycle from discovery to retirement.
Detect lookalike domains via typosquat, homoglyph, and TLD variant scanning. Automated evidence collection and multi-channel abuse dispatch to Google Web Risk, Netcraft, URLhaus, and registrars — with case tracking and escalation.
When failure rates spike, correlate auth failures, sender patterns, DNS changes, IP reputation signals, and provider data to rank probable causes. Structured RCA with deterministic classification — not guesswork.
Continuous scanning for CNAME takeover risks, orphaned records, and SubdoMailing indicators across your entire portfolio. Provider-aware risk scoring for Heroku, S3, Azure, CloudFront, GitHub Pages, and more.
Real DNS monitoring for MTA-STS, TLS-RPT, DNSSEC chain validity, and DANE/TLSA records. Not just configuration — live verification against public DNS every 24 hours.
Volume spikes, auth degradation, geo anomalies, spoofing campaigns, DNS changes, sender behavior shifts, and lookalike activity. IP enrichment from AbuseIPDB, Spamhaus ZEN, and Google Safe Browsing. CT log monitoring every 6 hours.
Simulate policy impact before DNS changes. Approval-gated execution with observation windows and armed rollback. TTD, TTR, TTE metrics and executive-ready compliance reports.
End-to-end BIMI readiness assessment, logo validation, VMC lifecycle tracking, and DNS deployment. Display your brand logo in Gmail, Apple Mail, and Yahoo.
White-label portal, pooled billing, customer impersonation, portfolio analytics, cross-tenant remediation queue, and PSA integration (ConnectWise, Autotask, HaloPSA, ServiceNow).
Learn more →Auditor-ready evidence and control mappings across 10 frameworks — SOC 2, ISO 27001, NIST CSF, PCI-DSS v4.0, HIPAA, CISA BOD 18-01, NIS2, SMB1001, ASD ISM, and NCSC CAF — for the email-security controls inside each. Documents your controls; does not by itself make you compliant.
Export threat indicators, sightings, and campaigns to Splunk, Sentinel, Elastic, or any TAXII 2.1-compatible SIEM. Four collections, standards-compliant.
Slack, Teams, Splunk, Datadog, Elastic, Sentinel, ConnectWise, Autotask, HaloPSA, ServiceNow, Okta. RESTful API with 700+ endpoints, outbound webhooks with HMAC signing.
The safe-enforcement operating loop
Getting to p=reject is not a one-time project — it is a loop you run every time a new sender appears or a provider tightens the rules. SpoofSentry runs all eight stages for you, with a human gate before anything touches DNS and an armed rollback if mail degrades.
Find every service sending as your domain from real DMARC aggregate report data — known ESPs, shadow senders, and unknowns alike.
Read your domain against Gmail, Microsoft, and Yahoo sender requirements — what public DNS shows, and what still needs telemetry.
Fix what blocks enforcement: align SPF and DKIM, manage the SPF record, and correct misconfigured vendors — blocker by blocker.
Replay recent reports against a tighter policy to see the exact blast radius — which senders pass, fail, or need work — before you commit.
Every high-impact change stops at a review point. Authorization and policy steps are gated, scoped, and auditable before DNS is touched.
Advance the DMARC policy as a whole-policy step and write it through a native DNS integration — with a pre-flight safety check and armed rollback.
After each step, watch delivery metrics and failure patterns through a fixed observation window before recommending the next move.
Show before/after enforcement proof and generate control-mapped evidence for leadership, auditors, and insurers.
Who it's for
Free tools
Beyond email authentication
Domains accumulate DNS records over time. When the service behind a record is decommissioned but the record remains, attackers can claim the abandoned resource and send email from your subdomain. SpoofSentry detects dangling DNS and monitors DNSSEC chain validation and DANE TLSA records across authoritative and validating paths — the hidden risk layer most DMARC tools ignore entirely.
Pricing
Start free. Upgrade when you're ready to enforce, automate, and scale.
See who's sending email on your domain — no credit card, no commitment.
For growing businesses that need reliable monitoring, alerts, and compliance-ready reporting.
Billed annually
For IT and security teams who need enforcement simulation, auto-remediation, and threat intelligence.
Billed annually
Unlimited scale, white-label branding, and enterprise controls for MSSPs and large organizations.
14-day free trial on all paid plans. No credit card required. Full plan comparison →
Start with visibility, score your posture, and move toward enforcement with confidence.