Domain security checklist
Your email security begins before the inbox.
Own the domain. Control DNS. Authenticate senders. Protect administrator accounts. Then discuss clever filtering.
Deploy DMARCReview email setupPartner review pending
Verify current terms directly with EasyDMARC
This opens the provider's official website directly. It is not an affiliate link and SignalBridge earns nothing from the visit.
Visit EasyDMARC official siteCommercial disclosure: SignalBridge is evaluating the EasyDMARC partner programme. No affiliate link is active. This content is written before any approval.
Ownership
- The organisation is the legal registrant.
- Registrar and DNS accounts use named administrators and MFA.
- Recovery email and phone are controlled by the business.
- Renewal is documented and not tied to a former contractor's card.
Authentication
- Exactly one valid SPF record exists.
- Every legitimate sender uses aligned SPF or DKIM.
- DKIM keys are active for the mailbox provider and major sending services.
- DMARC reports go to a monitored destination.
- Policy progression is documented before quarantine or reject.
Operations
- New SaaS senders require approval before using the domain.
- DNS changes are logged.
- Reports are reviewed on a schedule.
- Departing staff lose registrar, DNS and mailbox administration access immediately.
- Lookalike-domain monitoring and inbound phishing controls are treated separately from DMARC.
The recurring failure: a business protects the mailbox, leaves the registrar on an old personal account, and calls the result secure.
Last reviewed 19 July 2026. DNS, sender requirements and vendor capabilities change. Verify before publishing records.
Partner review pending
Continue with EasyDMARC
This opens the provider's official website directly. It is not an affiliate link and SignalBridge earns nothing from the visit.
Visit EasyDMARC official site