Email Auth · Sub-capability

SPF + DKIM management

Automatic discovery of active signatures, key-age monitoring, anticipated rotation alerts and continuous cryptographic validation. No spreadsheets, no ad-hoc scripts.

Capabilities

Automatic DKIM discovery

We detect every active DKIM signature without you declaring them. If a new service starts signing on your domain, we tell you.

Full SPF tree

We unfold your SPF layer by layer: includes, redirects, final sources. Visual map of authorized providers.

DNS lookup counter

Exact count of DNS queries when validating your SPF. Alert before crossing the 10-lookup limit that breaks delivery.

DKIM key age

Monitoring of creation date. Keys > 2 years are cryptographically weak per 2024 best practice.

Cryptographic validation

RSA key size (≥ 2048) + ECC presence in modern providers. Automated best practice.

Anticipated rotation alerts

We notify you when a key is near expiry (provider) or rotated without your team knowing.