Get every legitimate email into the inbox. Keep every fake one out.
I audit, configure, and monitor SPF, DKIM, and DMARC for businesses, agencies, and SaaS senders — so your emails stop landing in spam and no one can spoof your domain.
Most domains are sending mail unprotected — and don't know it
Good emails land in spam
Gmail, Yahoo, and Microsoft now require proper authentication. One misconfigured record and your invoices, receipts, and outreach quietly go to junk.
Anyone can impersonate your domain
Without an enforced DMARC policy, attackers can send phishing emails that appear to come from you — putting your customers and your reputation at risk.
Nobody's watching the reports
Even when DMARC is turned on, the reports it generates are dense XML files. Most businesses never see who's failing, or who's spoofing them.
Enforcement feels risky to flip on
Moving from "monitor only" to actually blocking bad mail can break legitimate tools if it's done blind. It needs to be staged and verified.
Five ways to lock down how your domain sends email
Each engagement starts with an audit, and moves at the pace that's safe for your sending volume. Pricing is scoped to your domain count and complexity — get a quote after a short audit.
SPF, DKIM & DMARC audit and setup
Full review of current DNS records and sending sources, followed by correct implementation of all three — consolidated SPF, per-platform DKIM keys, and an initial DMARC record.
Alignment and authentication fixes
Resolving SPF-DKIM alignment mismatches, SPF lookup-limit errors, and misconfigured third-party senders like your CRM, helpdesk, or marketing platform.
DMARC report monitoring
Ongoing parsing of aggregate and forensic reports, with a monthly plain-language summary of who's sending on your behalf and whether they're passing.
Unauthorized sender & failure investigation
When a report flags something unexpected, I trace it back to the source, confirm whether it's a forgotten tool or a genuine spoofing attempt, and recommend the fix.
Policy rollout: p=none → quarantine → reject
A staged, monitored path to full enforcement — validating every legitimate sender passes before tightening the policy, with a rollback plan at each stage.
Four stages, from first scan to full enforcement
Audit
I scan your domain's current SPF, DKIM, and DMARC setup and map every service sending on your behalf.
Fix
I correct and publish the records, sign every legitimate sender, and confirm alignment across the board.
Monitor
DMARC reports start flowing. I watch them for a defined period to confirm nothing legitimate is failing.
Enforce
Once the data confirms it's safe, we move the policy to quarantine, then reject — blocking spoofed mail for good.
What proper authentication actually gets you
Better inbox placement
Authenticated mail is trusted mail — fewer of your emails get filtered to spam or promotions.
Protection from spoofing
An enforced DMARC policy stops attackers from sending phishing emails that look like they came from you.
A domain your customers can trust
Clean authentication protects the reputation you've built, especially for domains handling invoices or account access.
Compliance with sender requirements
Meets Gmail and Yahoo's bulk sender requirements, so your outreach and transactional mail aren't at risk of being blocked outright.
Visibility into who sends as you
Monthly reporting shows every service and server sending on your domain's behalf — no more blind spots.
A safe, staged rollout
No flipping a switch and hoping. Every step is validated against real data before the next one begins.
Technical authentication only — no campaigns, no copy
What I handle
- SPF, DKIM, DMARC configuration
- DNS record audits and fixes
- Authentication & alignment troubleshooting
- DMARC report monitoring
- Spoofing & unauthorized sender investigation
- Policy enforcement rollout
What I don't handle
- Email campaign design or copywriting
- List building or subscriber growth
- Marketing automation strategy
- Sending platform selection or setup unrelated to authentication
What enforcement looks like in practice
These are illustrative placeholders showing the format your real case studies will take — swap in actual client results (with permission) once you have them.
Before you reach out
What are SPF, DKIM, and DMARC, in plain terms?+
SPF lists which servers are allowed to send email for your domain. DKIM signs your emails so receivers know they weren't altered in transit. DMARC tells receiving mail servers what to do when a message fails those checks, and sends you reports on the results.
Will moving to enforcement break my email?+
Not if it's staged correctly. I monitor your DMARC reports first to confirm every legitimate sender is passing, then move the policy up gradually — with a rollback plan at each step if anything looks off.
How long does the whole process take?+
The audit and initial setup usually take 3–7 business days. Full enforcement rollout, from p=none to p=reject, typically runs 4–12 weeks depending on how many senders you have and how quickly issues surface.
Which email platforms and DNS hosts do you support?+
Any platform that sends email on your behalf — Google Workspace, Microsoft 365, and marketing, CRM, or transactional tools — and any DNS host, including GoDaddy, Cloudflare, Namecheap, and Route 53.
How does pricing work?+
Every engagement starts with a short audit so I can scope the work accurately. From there I'll send a fixed quote for setup, and — if you'd like ongoing monitoring or a staged enforcement rollout — a monthly retainer rate.
Do you manage email campaigns too?+
No — I focus purely on the technical authentication side. I don't write copy, build lists, or manage campaigns, so I pair well with your existing marketing team or agency.
Find out exactly where your domain stands
Tell me about your domain
Share a few details and I'll follow up with what I find and a scoped quote. No commitment required.