Glossary

Email and domain security, in plain English.

DMARC, SPF, DKIM, alignment, enforcement, MTA-STS, BIMI and more, each in one plain sentence.

Alignment
The checks passing for the same domain people see in the From line.
BIMI
Your logo beside your emails in the inbox.
CAA
The DNS record that says which companies may issue certificates for your domain.
DKIM
A tamper-proof signature on every message you send.
DMARC
Your instruction to inboxes about mail that fails the checks: watch it, junk it or refuse it.
DNSSEC
A seal on your DNS answers that stops them being forged.
Enforcement
DMARC set to quarantine or reject: the settings that actually protect you.
External attack surface
Everything about you that an outsider can see and reach from the internet.
Hosted DMARC
We keep your DMARC record for you; you point at it once.
HSTS
The header that tells browsers always to use the secure version of your site.
Look-alike domain
A domain one letter off yours, registered to fool your customers.
MSP
The IT company that runs a business's IT for it.
MTA-STS
Makes other servers deliver your mail over an encrypted, verified connection.
p=none, p=quarantine, p=reject
Watch and block nothing; send fakes to junk; refuse fakes outright.
PSA
The ticketing and billing system an MSP runs its service desk on.
Sender
Any service sending email as you: Microsoft 365, your newsletter tool, your accounts software.
SPF
The list of services allowed to send email for you.
Spoofing, impersonation
Sending email that pretends to come from your domain.
Subdomain takeover
A forgotten subdomain, still pointing at a service a stranger can claim.
TLS
The encryption between a browser and a website, and between mail servers.
TLS reporting
A report whenever a server could not deliver to you securely.