Email domain security

Email domain security review for SPF, DKIM, DMARC and business email trust

A remote review of your public email domain setup to identify spoofing, fake invoice and deliverability risks before attackers abuse them.

Why email domain security matters

Many business scams do not start with a technical break-in. They start with an email that looks believable enough to make someone click a link, approve a payment or trust a fake invoice. SPF, DKIM and DMARC help receiving mail systems decide whether a message claiming to be from your domain is legitimate.

ScanLens checks the public DNS signals around your email domain and explains what they mean in practical business language.

  • SPF sender policy
  • DKIM selector evidence
  • DMARC policy and reporting
  • MX provider visibility
  • CAA certificate policy
  • MTA-STS and TLS-RPT readiness

What you receive

  1. A written summary of your current public email domain setup.
  2. Evidence for SPF, DKIM, DMARC, MX and optional advanced records.
  3. A risk explanation focused on spoofing, phishing and fake invoices.
  4. Practical DNS recommendations you can send to your email or DNS provider.

Who this review is for

This is for a business owner, operations lead or IT provider who controls a company email domain and needs a written, public-record review before changing DNS. For the Starter review, provide one email domain, one public website and a short description of the concern. If DKIM uses a selector that is not publicly discoverable, provide the selector name from your mail provider.

Relevant background: phishing email warning signs and fake invoice scam risk review.

Sample output

Example finding: "DMARC record not detected. Priority: high. Business impact: messages that imitate the domain may be harder for recipients to reject consistently. Recommended next step: confirm all legitimate senders, publish a monitoring policy, review reports, then plan enforcement."

See the sample report format.

Scope, timing and exclusions

  • Starter: one business, one public website and one email domain; £99 total.
  • Delivery: within 2-3 business days after complete information is received and scope is confirmed.
  • Follow-up: seven calendar days of email clarification; no call is included.
  • Public DNS review only: no mailbox access, penetration testing, DNS login or DNS change is included.
  • Additional domains, implementation or expanded scope require a separate quote.

Business Protection Setup

Adds staff workflow
£399

Use this when you also need guidance for staff handling suspicious emails, invoices and payment requests.

Email domain FAQ

Do you need email account access?

No. The standard review uses public DNS and domain records only.

Can you fix DNS for me?

The standard report gives recommended record wording. Implementation depends on your DNS and email provider access.

What email domain should I send?

Use the part after the @ sign. For [email protected], the email domain is scanlens.app.

Is DMARC p=none bad?

Not always. It is often the safe first monitoring stage before moving toward quarantine or reject.

How much does this review cost?

The email-domain check is included in the £99 Starter Scam Safety Review. Prices shown are the total prices. No VAT is currently charged.

When does delivery start?

After ScanLens accepts the order, payment is received, the requested information is complete and the scope is confirmed.

Can I ask a question before buying?

Yes. Use the Business enquiry form to confirm the domain and concern without sending passwords, private documents or DNS credentials.