Domain trust
Email Trust and Spoofing Repair
A legitimate message reaching spam or a fake email sent in the company’s name calls for one first step: connect real senders to the right signals.
The symptom before the setting
Start with the message behaving unexpectedly
Legitimate messages land in spam.
Customers receive messages impersonating the business.
Several services send email, but nobody knows which senders are authorized.
A strict policy is being considered before the platforms that actually send mail are inventoried.
What DNS does not prove
A record can exist and still name the wrong sender
A DNS record can exist and still describe the wrong senders. Diagnosis connects observed messages, sending platforms and SPF, DKIM and DMARC signals before a change is proposed.
What this can look like
- An old newsletter service remains authorized in SPF.
- Microsoft 365 works, but a billing platform also sends as the domain.
- The domain has DKIM, but nobody has confirmed that its selector belongs to the right provider.
- Forwarding or relaying changes the alignment expected by the DMARC policy.
Connect email to real senders
What the diagnosis needs to separate
- The services that actually send email and the evidence of rejection, spam or impersonation.
- SPF: the services allowed to send using the domain.
- DKIM: the signature added by an authorized sending service.
- DMARC: the policy that compares the announced identity with the real sender, including forwarding and connector effects.
What can be confirmed
A sequence before the next change
- A map of visible signals, confirmed facts and unknowns.
- A list of legitimate senders to confirm before tightening a policy.
- A correction and verification sequence proportionate to the observed problem.
- A clear ownership question: who authorizes DNS, sending-platform and policy changes?
Diagnose before tightening policy
What is included and what needs more evidence
In the diagnosis
- A review of public DNS and supplied delivery evidence.
- Identification of obsolete, conflicting or incomplete records.
- A recommended sequence before changing sending platforms or policy.
Planned separately
- DNS changes and sending-platform configuration.
- Deeper reputation, mail-log or mail-flow analysis.
- Ongoing monitoring and recurring provider coordination.
Scope, deliverables, and pricing are confirmed before work begins. Additional work requires approval.
Evidence first
Changes follow the sender inventory
We confirm the scope, evidence, customer responsibilities and any licences or third-party costs before changes are considered.
What the domain owner provides
- Name legitimate senders and providers allowed to send for the domain.
- Provide examples of rejection, spam or impersonation without sending unnecessary data.
- Authorize DNS or sending-platform changes separately.
A useful next conversation
Start with legitimate senders
Tell us what is happening. Initial contact confirms the right scope and requirements; it does not authorize a change.
Start with legitimate senders