Policy
SecOps ForcesEmail security & managed DMARC
Managed services
Your domain namecan be spoofedas things stand.
Anyone can send a message that appears to come from your company — to your customers, your accountant, your suppliers. DMARC is the only mechanism that genuinely stops it, provided it is taken all the way without blocking your own mail.
Per domain / year · No volume commitment · Continuous monitoring
What we find
Publishing a DMARC record
protects nothing by itself.
Most domains we take over already have DMARC. It simply stayed in monitoring mode, because nobody dared enforce it without knowing what would break.
Senders
Forgotten business tools
SPF
The ten DNS lookup limit
Brand
Lookalike domains already registered
Overall security score
Score history
Domains monitored
62Under contract
DMARC status
| Domain | Score | DMARC | Type |
|---|---|---|---|
| secopsforces.com | 95 % | reject | SMTP |
| secopsforces.io | 35 % | monitoring | parked |
Interface preview — illustrative data.
What you see
We run it. You keep the visibility.
The service is managed — we make the technical calls and we apply them. But you see exactly what we see: the same dashboard, the same numbers, whenever you want.
Every domain, one score
Where each domain stands
The curve, domain by domain
Expiries, before they become incidents
Your addresses in known breaches
A domain joins in three clicks
What you can show
Enough to answer without calling us.
A customer asks where you stand on DMARC. Your insurer wants proof. Your board wants a number. It is all in the dashboard, dated.
Overall security score
The level across the estate, out of one hundred. The single figure you quote when you do not have ten minutes to explain.
Score history
The curve since the first reading, over several years if need be. That is what proves a continuous effort rather than a coat of paint before an audit.
Policy breakdown
How many domains at reject, quarantine, monitoring, or no reports. The most honest measure of real progress — a domain at monitoring is not protected.
Domains monitored
The exact count, and the ones that are not. It is the question an auditor asks, and the one almost nobody can answer from memory.
Upcoming expiries
Domains and certificates coming due. The only indicator on this list that prevents an incident rather than documenting one.
Exposed addresses
Those appearing in a known breach, with the date of the last check. Enough to trigger a targeted reset rather than a blanket campaign.
How we work
To p=reject, without losing legitimate mail.
The risk is operational rather than technical: enforcing too quickly blocks an invoice, a payroll run or a campaign. We move in measured stages.
Inventory
Every domain, every legitimate sender, including the ones nobody had listed.
Alignment
SPF and DKIM fixed source by source, until every legitimate flow authenticates.
Enforcement
Gradual move to quarantine then reject, in stages, with verification at each step.
Monitoring
New senders, lookalike domains, certificate expirations: watched continuously, alerts qualified.
Pricing
Two plans,
per domain.
The service is billed per domain. A six-month project to fix, or an annual plan to keep monitoring all year.
Project — 6 months
The fix: your domains brought to p=reject, with no legitimate mail lost.
- Inventory of legitimate senders
- Gradual move to p=reject
- SPF, DKIM and alignment hardening
- Readout at the end of the project
Annual
The fix, then monitoring kept in place all year.
- The full correction project
- Continuous monitoring: new senders, lookalike domains
- Credential breaches, domain and certificate expiries
- Dashboard and evidence at any time
Priced per domain. The number of domains and the scope are set in a first call.
Going further
Email is only one attack path.
The same environments almost always show gaps on the Microsoft 365 side.
Microsoft 365 audit
Continuous posture
Frequently asked
Common questions about DMARC.
How long does it take to reach p=reject?
Is there a minimum number of users?
What if a legitimate flow gets blocked?
Do we need to change mail provider?
Can your domain be spoofed?
Thirty minutes to look at your records, your senders and the lookalike domains already registered. You will know where you stand before deciding anything.