Skip to main content
Email Security

Protect Your Domain and Accounts without breaking the legitimate email.

SPF, DKIM, and DMARC are just part of the problem. We link them to identity security, real referral providers, and the processes needed for phishing, BEC, and compromised accounts.

Authentication rollout

SPF, DKIM and DMARC are a route, not three biscuits.

We start with real referral sources and increase enforcement only after we know what needs to remain legitimate.

01

Inventory senders

We identify the platforms and services that legitimately send in the domain name before we strengthen our DNS policies.

02

SPF

We define authorized infrastructure and remove old or unknown sources that increase the spoofing area and record complexity.

03

DKIM

We validate signature for active providers, selectors, and alignment with the domain used in legitimate streams.

04

DMARC visibility

We start from reports and alignments to see who sends and what would be affected by a stricter policy.

05

Enforcement

We gradually strengthen the policy once legitimate sources are known and errors that may block the valid email have been corrected.

06

Monitor & maintain

Changes in suppliers, selectors, and referral streams must be tracked so that the posture does not degrade after roll-out.

@

Domain + identity

A real message can come from a compromised account.

Domain authentication reduces direct spoofing. Identity controls reduce the risk that a compromised legitimate mailbox becomes the attacker’s channel. We need both.

01

MFA

A compromised password should not be enough to access critical accounts.

02

Session & sign-in review

We investigate sign-ins, sessions and unusual behaviors when there is suspicion of compromise.

03

Forwarding & mailbox rules

Hidden or modified rules may maintain access or exfiltrate conversations after the initial compromise.

04

Privileged accounts

Administrative accounts and high-impact roles should be separated and reviewed in proportion to the risk.

05

Recovery paths

Recovery methods, alias and alternative channels can become a bypass path if left uncontrolled.

Start from the symptom

Let’s start with the real problem.

Not all email problems are DMARC problems and not all phishing incidents are DNS problems.

01

Domeniul poate fi spoofed

We check the SPF/DKIM alignment, DMARC policy and actual referral sources before moving to enforcement.

02

Legitimate emails go to spam

We separate authentication, reputation, and configuration issues from changes that can do more harm to deliverability.

03

Have you had phishing or BEC

We also treat the issue as an identity incident: accounts, sessions, forwarding, MFA, reset, referral sources and similar domains.

04

Use more suppliers.

We document each authorized source and avoid unsustainable SPF records or remaining DKIM selectors from old services.

Provider-neutral

Keep the provider working.

Security doesn’t have to become a disguised commercial migration. We set up controls around the existing platform when it can support the requirements.

Microsoft 365

Domain authentication, identity controls and review in the context of the existing tenant.

Google Workspace

DNS authentication and account security without forced migration to another provider.

Proton

Domain configuration and controls available in the provider model.

Zoho

SPF, DKIM, DMARC and posture review for organizations using the Zoho ecosystem.

SMTP / transactional providers

We map the sources of applications, billing, marketing and other systems that send email automatically.

Multiple providers

We separate streams and ownership so that a new service doesn’t break the policy of the entire domain.

Live posture

Monitoring after the rollout.

A good configuration today can go wrong after a new provider, a migration, or a SaaS service starts sending in the name of the domain.

Include your email in a Security Assessment
01 new or unknown sources observed in reports watch
02 Failure of alignment or signing watch
03 DNS changes affecting authentication watch
04 Selectors or services left after migration watch
05 Change of provider or marketing/transactional email platforms watch
06 Compromised account signals or unusual forwarding watch

Frequently asked questions

Can DMARC be put directly on reject? +

Technically it is possible, but it is not a good strategy without inventory of legitimate sources and alignment verification. A strict policy applied too early can block valid streams that your organization has not yet documented.

Do SPF, DKIM and DMARC stop phishing completely? +

No. They reduce direct domain impersonation and provide control and visibility over message authentication. Phishing can use similar domains, compromised accounts or other techniques, which is why identity security and incident response processes remain important.

Do I need to change my email provider? +

Not normally. We work with the existing platform and separate what needs to be changed in DNS, tenant and identity/security processes. Migration only makes sense if there are separate reasons for it.

What if a mailbox is compromised? +

The situation should be treated as an incident: sessions, passwords, MFAs, forwarding rules, sign-ins, privileges and other persistence mechanisms must be analyzed before we consider the issue closed.

Can Email Security Support Compliance? +

Identity controls, MFA, domain authentication, incident handling and associated evidence may support relevant controls from ISO27001, SOC2, NIS2 or other programs without a DNS configuration automatically signifying compliance with a framework.

The email must remain authentic and operable.

We start with the existing domain and platform, then strengthen the posture without sacrificing legitimate streams.

Talk about Email Security
ZebraByte

Managed frameworks Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert