Glossary
Email and domain security, in plain English.
DMARC, SPF, DKIM, alignment, enforcement, MTA-STS, BIMI and more, each in one plain sentence.
- Alignment
- The checks passing for the same domain people see in the From line.
- BIMI
- Your logo beside your emails in the inbox.
- CAA
- The DNS record that says which companies may issue certificates for your domain.
- DKIM
- A tamper-proof signature on every message you send.
- DMARC
- Your instruction to inboxes about mail that fails the checks: watch it, junk it or refuse it.
- DNSSEC
- A seal on your DNS answers that stops them being forged.
- Enforcement
- DMARC set to quarantine or reject: the settings that actually protect you.
- External attack surface
- Everything about you that an outsider can see and reach from the internet.
- Hosted DMARC
- We keep your DMARC record for you; you point at it once.
- HSTS
- The header that tells browsers always to use the secure version of your site.
- Look-alike domain
- A domain one letter off yours, registered to fool your customers.
- MSP
- The IT company that runs a business's IT for it.
- MTA-STS
- Makes other servers deliver your mail over an encrypted, verified connection.
- p=none, p=quarantine, p=reject
- Watch and block nothing; send fakes to junk; refuse fakes outright.
- PSA
- The ticketing and billing system an MSP runs its service desk on.
- Sender
- Any service sending email as you: Microsoft 365, your newsletter tool, your accounts software.
- SPF
- The list of services allowed to send email for you.
- Spoofing, impersonation
- Sending email that pretends to come from your domain.
- Subdomain takeover
- A forgotten subdomain, still pointing at a service a stranger can claim.
- TLS
- The encryption between a browser and a website, and between mail servers.
- TLS reporting
- A report whenever a server could not deliver to you securely.