Skip to main content

Email security

Make sure no one can send email as your company.

See who is really sending as your domain, and close the gaps that let attackers impersonate you. DMARC done properly. Start with your domain.

No account, no card. Reads your public DNS in seconds.

8.3B

phishing emails detected in a single quarter

Microsoft, Q1 2026

4.5×

more clicks on AI-written phishing than human-written

Microsoft DDR 2025

10.7M

business email compromise attacks in a single quarter

Microsoft, Q1 2026

Three reasons your domain can't wait.

Impersonation

Without enforcement, attackers send invoices, password resets and payment requests as you, to your customers and your own staff. DMARC at p=reject is what stops them.

Deliverability

Gmail, Yahoo and Microsoft now check DMARC. Get it wrong and your legitimate email is throttled or junked, so replies, receipts and sales quietly stop arriving.

Compliance

Mailbox providers, cyber-insurance and enterprise procurement increasingly demand enforcement. Most domains are exposed and do not know it.

How it works

How to lock down your domain.

01

Publish one record

Add a single DMARC DNS record. That is the whole setup. No agent, no code, no mail routing changes.

02

See every sender

Within a day you see every service sending as your domain, who owns it, and exactly why it fails authentication.

03

Reach p=reject safely

Fix the real senders, verify each fix, and switch on full enforcement knowing your legitimate email keeps flowing.

Inside SenderLedger

See every sender and what needs fixing.

SenderLedger shows the provider, volume, DMARC pass rate and approval status for each source sending as you, so your team can prioritise exactly what is blocking enforcement. Failing and unapproved senders surface first.

Senders ciphercue.com Console
Google Workspace aligned DKIM
Approved
52,000 msgs 100% DMARC
Resend DKIM unaligned
Approved
5,321 msgs 12% DMARC Case open
Unidentified bulk source both mechanisms fail
Not approved
2,104 msgs 0% DMARC
Customer forwarding forwarding SPF failure
Forwarding
130 msgs 75% DMARC
  1. Identify
  2. Approve
  3. Fix
  4. Enforce

You work through every unknown and failing sender, approving the legitimate ones and fixing the rest, until all your genuine mail is authenticated and the domain is ready for p=reject.

Next enforcement decision

Find out who is sending as your domain.

Add one DNS record and see every sender within a day. Free for your first domain.