Email authentication operations

Get to enforcement without breaking legitimate mail

See whether Gmail, Microsoft, and Yahoo are ready to accept your mail. Discover every sender, fix authentication blockers, manage SPF and DKIM, simulate enforcement before any DNS change, and verify the result afterwards.

Talk to Sales →
Simulate before DNS changes·Approval-gated actions·Observation windows·Armed rollback·MSSP-ready·17 free tools

Start here — no account needed

Will Gmail, Microsoft, or Yahoo accept your mail?

Check your domain against each major provider's sender requirements — from public DNS, in seconds. Here is the shape of the answer you get back:

Google

Likely OK
  • SPF published
  • DKIM alignment
  • DMARC policy
  • Spam rate < 0.3% — requires telemetry

Microsoft

At risk
  • SPF published
  • DKIM alignment
  • DMARC policy
  • 550 5.7.515 risk

Yahoo

Needs check
  • SPF published
  • DKIM alignment
  • One-click unsubscribe — requires telemetry
  • Sender reputation — requires telemetry

Public DNS only tells part of the story. Connect DMARC reporting to identify your legitimate senders, uncover the blockers behind every failure, and know whether moving to p=reject is safe.

Check your domain — free

Most teams do not fail at visibility. They stall at safe enforcement.

DMARC dashboards can tell you what is broken. That is not the hard part. The hard part is deciding what to change, proving it is safe, and carrying it through production DNS without disrupting legitimate mail. SpoofSentry closes that gap with governed workflows for sender discovery, failure root cause analysis, staged policy progression, and approval-gated change execution.

Simulate before you enforce

See which senders pass, fail, or need remediation before you tighten policy. Replay recent aggregate report data against quarantine or reject to understand the blast radius.

Approve before DNS changes

Keep humans in control with review points for sender authorization and enforcement changes. Every high-impact action is gated, scoped, and auditable.

Observe after every step

Use fixed observation windows, structured outcomes, and rollback-aware execution to move toward enforcement safely. Prove progress to leadership with before/after enforcement proof.

See it in action

Built for security teams, not just dashboards

Every feature is operational — from onboarding checklists to HIPAA readiness checks.

Signature capability

One score for your entire domain posture

Most tools tell you whether you have a DMARC record. SpoofSentry tells you whether your domain is actually protected. The Domain Security Score is a 100-point composite across ten dimensions — not just authentication, but transport encryption (MTA-STS, TLS-RPT, DANE), DNS trust, and hidden takeover risk.

  • Ten dimensions: DMARC policy, SPF alignment, DKIM alignment, sender coverage, MTA-STS, TLS-RPT, BIMI readiness, lookalike threat exposure, managed SPF/DKIM, DANE
  • Letter grades A through F with historical trend tracking
  • Anonymized industry benchmarks — see where you rank
  • Free preview score at /tools — no account needed
Learn more about the Domain Security Score →
Domain Posture OverviewLast 30 days
DMARC
92
SPF
95
DKIM
88
Senders
78
MTA-STS
60
TLS-RPT
100
BIMI
0
Lookalike
85
DANE
40
DNS Risk
35
Composite Score74/100

Bottom 30% for your sector · 3 issues to address

More than DMARC monitoring

Every layer of domain security — in one platform

DMARC is the foundation. SpoofSentry builds the entire security stack on top — from transport encryption to brand protection to automated threat response.

🤖

Sender Authorization Intelligence

AI-powered ESP detection across 26+ providers. Behavioral profiling with hourly cadence fingerprinting, volume anomaly detection, and authentication degradation alerts. Full governance lifecycle from discovery to retirement.

🛡️

Takedown Orchestration

Detect lookalike domains via typosquat, homoglyph, and TLD variant scanning. Automated evidence collection and multi-channel abuse dispatch to Google Web Risk, Netcraft, URLhaus, and registrars — with case tracking and escalation.

🔬

Root Cause Analysis

When failure rates spike, correlate auth failures, sender patterns, DNS changes, IP reputation signals, and provider data to rank probable causes. Structured RCA with deterministic classification — not guesswork.

🔍

Dangling DNS & Subdomain Takeover

Continuous scanning for CNAME takeover risks, orphaned records, and SubdoMailing indicators across your entire portfolio. Provider-aware risk scoring for Heroku, S3, Azure, CloudFront, GitHub Pages, and more.

🔏

Transport Security (MTA-STS, DANE, TLS-RPT)

Real DNS monitoring for MTA-STS, TLS-RPT, DNSSEC chain validity, and DANE/TLSA records. Not just configuration — live verification against public DNS every 24 hours.

🚨

7-Signal Threat Intelligence

Volume spikes, auth degradation, geo anomalies, spoofing campaigns, DNS changes, sender behavior shifts, and lookalike activity. IP enrichment from AbuseIPDB, Spamhaus ZEN, and Google Safe Browsing. CT log monitoring every 6 hours.

📊

Enforcement Proof & Observation

Simulate policy impact before DNS changes. Approval-gated execution with observation windows and armed rollback. TTD, TTR, TTE metrics and executive-ready compliance reports.

BIMI & VMC

End-to-end BIMI readiness assessment, logo validation, VMC lifecycle tracking, and DNS deployment. Display your brand logo in Gmail, Apple Mail, and Yahoo.

🏢

MSSP Multi-Tenancy

White-label portal, pooled billing, customer impersonation, portfolio analytics, cross-tenant remediation queue, and PSA integration (ConnectWise, Autotask, HaloPSA, ServiceNow).

Learn more →
🔒

Compliance Evidence Mapping

Auditor-ready evidence and control mappings across 10 frameworks — SOC 2, ISO 27001, NIST CSF, PCI-DSS v4.0, HIPAA, CISA BOD 18-01, NIS2, SMB1001, ASD ISM, and NCSC CAF — for the email-security controls inside each. Documents your controls; does not by itself make you compliant.

📡

STIX/TAXII 2.1 Threat Feed

Export threat indicators, sightings, and campaigns to Splunk, Sentinel, Elastic, or any TAXII 2.1-compatible SIEM. Four collections, standards-compliant.

🔗

25+ Integrations & Open API

Slack, Teams, Splunk, Datadog, Elastic, Sentinel, ConnectWise, Autotask, HaloPSA, ServiceNow, Okta. RESTful API with 700+ endpoints, outbound webhooks with HMAC signing.

The safe-enforcement operating loop

One loop, run continuously, until enforcement holds

Getting to p=reject is not a one-time project — it is a loop you run every time a new sender appears or a provider tightens the rules. SpoofSentry runs all eight stages for you, with a human gate before anything touches DNS and an armed rollback if mail degrades.

01

Discover

Find every service sending as your domain from real DMARC aggregate report data — known ESPs, shadow senders, and unknowns alike.

02

Readiness

Read your domain against Gmail, Microsoft, and Yahoo sender requirements — what public DNS shows, and what still needs telemetry.

03

Remediate

Fix what blocks enforcement: align SPF and DKIM, manage the SPF record, and correct misconfigured vendors — blocker by blocker.

04

Simulate

Replay recent reports against a tighter policy to see the exact blast radius — which senders pass, fail, or need work — before you commit.

05

Approve

Every high-impact change stops at a review point. Authorization and policy steps are gated, scoped, and auditable before DNS is touched.

06

Deploy

Advance the DMARC policy as a whole-policy step and write it through a native DNS integration — with a pre-flight safety check and armed rollback.

07

Observe

After each step, watch delivery metrics and failure patterns through a fixed observation window before recommending the next move.

08

Prove

Show before/after enforcement proof and generate control-mapped evidence for leadership, auditors, and insurers.

Who it's for

The right depth for every team

Security Teams

  • Managed SPF with automated refresh, RFC-aware validation, drift detection, and safe optimization
  • Continuous posture monitoring across SPF, DKIM, DMARC, DNSSEC, DANE, MTA-STS
  • Dangling DNS and subdomain takeover detection
  • Enforcement simulation before any DNS change
  • SIEM integration (Splunk, Sentinel, Elastic, Datadog)

IT Leadership

  • 100-point Domain Security Score with letter grades
  • AI executive summaries in plain English
  • Compliance evidence mapping across 10 frameworks
  • Weekly PDF digests and trend dashboards

MSSPs & MSPs

  • Multi-tenant portal with strict data isolation
  • White-label branding — custom domain, logo, reports
  • PSA/RMM integration: ConnectWise, Autotask, HaloPSA
  • Portfolio dashboard with per-client enforcement tracking

Multi-Domain Organisations

  • Portfolio-level posture visibility across all domains
  • Bulk enforcement operations with safety gates
  • Branded reporting for boards and auditors
  • Enterprise SSO (OIDC / SAML) and documented support commitments

Beyond email authentication

Find what attackers find — before they do

Domains accumulate DNS records over time. When the service behind a record is decommissioned but the record remains, attackers can claim the abandoned resource and send email from your subdomain. SpoofSentry detects dangling DNS and monitors DNSSEC chain validation and DANE TLSA records across authoritative and validating paths — the hidden risk layer most DMARC tools ignore entirely.

  • Dangling DNS detection — CNAME, MX, and SPF include scanning
  • DANE/DNSSEC monitoring — TLSA records + chain validation across authoritative and validating paths
  • Deliverability intelligence — Google Postmaster + Microsoft SNDS
Learn more about DNS risk detection →
DNS Risk Scan
blog.example.comDangling
old-app.example.comDangling
mail.example.comHealthy
_dmarc.example.comHealthy
example.comUnsigned
5 records scanned · 2 critical · 1 warning

Pricing

From free visibility to managed enforcement

Start free. Upgrade when you're ready to enforce, automate, and scale.

Save 20%

Monitor

See who's sending email on your domain — no credit card, no commitment.

$0/mo
  • 1 domain
  • DMARC visibility
  • Domain Security Score (preview)
  • 7-day data retention
  • 1 team member
Popular

Protect

For growing businesses that need reliable monitoring, alerts, and compliance-ready reporting.

$19/mo$24

Billed annually

  • Up to 5 domains
  • SPF, DKIM & DMARC monitoring
  • Full Domain Security Score
  • Dangling DNS detection
  • Remediation playbooks
  • Alerts & branded weekly digest
  • Provider readiness & deliverability investigate
  • Trends, benchmarks & deliverability
  • 5 AI summaries/mo
  • 30-day history

Enforce

For IT and security teams who need enforcement simulation, auto-remediation, and threat intelligence.

$52/mo$65

Billed annually

  • Up to 10 domains
  • Enforcement center & sender inventory
  • Auto-remediation with risk classification
  • Impact simulation & automatic rollback
  • Third-party & inbound vendor risk
  • Threat intel: IP reputation + CT monitoring
  • Score forecasting + sender profiling
  • 90-day trends & benchmarks
  • 25 AI summaries/mo
  • Full API & webhooks

Enterprise

Unlimited scale, white-label branding, and enterprise controls for MSSPs and large organizations.

Custom
  • Unlimited domains
  • White-label branding
  • MSSP multi-tenant portal
  • Sender Surface & Brand Risk Score
  • STIX/TAXII threat feed
  • MSSP remediation queue & vendor portfolio
  • Enterprise SSO (OIDC / SAML)
  • Unlimited AI summaries
  • 10-framework compliance
  • PSA/RMM integration
  • 365-day retention
  • Dedicated onboarding & priority support

14-day free trial on all paid plans. No credit card required. Full plan comparison →

Protect your domains before weak posture becomes brand damage

Start with visibility, score your posture, and move toward enforcement with confidence.

SpoofSentry — Domain Security, DMARC Enforcement & Takedown Platform