SecOps ForcesEmail security & managed DMARC

Managed services

Your domain namecan be spoofedas things stand.

Anyone can send a message that appears to come from your company — to your customers, your accountant, your suppliers. DMARC is the only mechanism that genuinely stops it, provided it is taken all the way without blocking your own mail.

Per domain / year · No volume commitment · Continuous monitoring

dmarc — primary domain35 domains
35/100 · starting score as found
DMARC policyp=none
SPF alignment3 sources unaligned
DKIM signingpartial
Lookalike domains registered4 found
Aggregate reports readnone

What we find

Publishing a DMARC record
protects nothing by itself.

Most domains we take over already have DMARC. It simply stayed in monitoring mode, because nobody dared enforce it without knowing what would break.

Policy

A p=none that has lasted three years

The policy is published, reports arrive, nobody reads them. The domain stays exactly as spoofable as before.

Senders

Forgotten business tools

Billing, payroll, CRM, campaigns: every department has a tool sending on your behalf, and no inventory lists them.

SPF

The ten DNS lookup limit

An SPF record past the technical limit stops being evaluated: protection drops with no alert to say so.

Brand

Lookalike domains already registered

One character of difference is enough to fool a customer or an accountant. Those registrations often precede the attack by months.

Overall security score

65 %

Score history

Domains monitored

62

Under contract

61 monitored
1 out of scope

DMARC status

1 at reject
1 at monitoring
DomainScoreDMARCType
secopsforces.com95 %rejectSMTP
secopsforces.io35 %monitoringparked
9Domains
19Certificates
6Expiring soon
Certificatemail.secopsforces.comin 12 d
Domainsecopsforces.ioin 8 mo

Interface preview — illustrative data.

What you see

We run it. You keep the visibility.

The service is managed — we make the technical calls and we apply them. But you see exactly what we see: the same dashboard, the same numbers, whenever you want.

Every domain, one score

A consolidated security score across the estate, and the detail domain by domain. You know which are under contract, which are monitored, and which are out of scope — often the first time an organisation has that list in full.

Where each domain stands

How many are at reject, at quarantine, still monitoring, and how many return no reports at all. That is the map of the migration: what is protected, what is in progress, and what has not started.

The curve, domain by domain

Each domain’s score tracked over time, from the first reading. That is what demonstrates progress — and what makes visible a domain that slips back because a new sender appeared unannounced.

Expiries, before they become incidents

Your domain names and certificates, with their expiry date, their registrar and an alert as the date approaches. An expired domain is a brand going to auction; an expired certificate is a service down on a Sunday.

Your addresses in known breaches

The addresses you entrust to us are checked against public breach data, and you are told when one appears. An address in a breach does not mean the account is compromised — it means someone should go and check.

A domain joins in three clicks

Every acquisition, every new brand enters the arrangement without a project or a meeting. That is what makes the effort survive in a growing group — ours runs more than sixty domains this way today.

What you can show

Enough to answer without calling us.

A customer asks where you stand on DMARC. Your insurer wants proof. Your board wants a number. It is all in the dashboard, dated.

Overall security score

The level across the estate, out of one hundred. The single figure you quote when you do not have ten minutes to explain.

Score history

The curve since the first reading, over several years if need be. That is what proves a continuous effort rather than a coat of paint before an audit.

Policy breakdown

How many domains at reject, quarantine, monitoring, or no reports. The most honest measure of real progress — a domain at monitoring is not protected.

Domains monitored

The exact count, and the ones that are not. It is the question an auditor asks, and the one almost nobody can answer from memory.

Upcoming expiries

Domains and certificates coming due. The only indicator on this list that prevents an incident rather than documenting one.

Exposed addresses

Those appearing in a known breach, with the date of the last check. Enough to trigger a targeted reset rather than a blanket campaign.

How we work

To p=reject, without losing legitimate mail.

The risk is operational rather than technical: enforcing too quickly blocks an invoice, a payroll run or a campaign. We move in measured stages.

01

Inventory

Every domain, every legitimate sender, including the ones nobody had listed.

02

Alignment

SPF and DKIM fixed source by source, until every legitimate flow authenticates.

03

Enforcement

Gradual move to quarantine then reject, in stages, with verification at each step.

04

Monitoring

New senders, lookalike domains, certificate expirations: watched continuously, alerts qualified.

Pricing

Two plans,
per domain.

The service is billed per domain. A six-month project to fix, or an annual plan to keep monitoring all year.

Project — 6 months

€3,000/ domain

The fix: your domains brought to p=reject, with no legitimate mail lost.

  • Inventory of legitimate senders
  • Gradual move to p=reject
  • SPF, DKIM and alignment hardening
  • Readout at the end of the project

Annual

€5,000/ domain / year

The fix, then monitoring kept in place all year.

  • The full correction project
  • Continuous monitoring: new senders, lookalike domains
  • Credential breaches, domain and certificate expiries
  • Dashboard and evidence at any time

Priced per domain. The number of domains and the scope are set in a first call.

Going further

Email is only one attack path.

The same environments almost always show gaps on the Microsoft 365 side.

Microsoft 365 audit

The full picture of your tenant: identities, mail, sharing, endpoints.

Optional · €2,500

Continuous posture

Configuration monitored around the clock, with exportable evidence for your insurer.

From €1.20/user/mo annual · 100–500/tenant

Frequently asked

Common questions about DMARC.

How long does it take to reach p=reject?
Six to twelve weeks depending on how many senders need aligning. The inventory takes a few days, alignment depends on your third-party vendors, and enforcement moves in stages so nothing breaks. Going faster is technically possible, and it is exactly how billing gets blocked.
Is there a minimum number of users?
No. Email security is priced per domain — a six-month project or an annual plan — whatever your headcount. It is Microsoft 365 posture monitoring that is billed from 100 users, not this.
What if a legitimate flow gets blocked?
That is precisely what the staged approach prevents: at each step we review the reports before tightening. If an unknown flow appears, it is identified and aligned before the policy would reject it.
Do we need to change mail provider?
No. DMARC, SPF and DKIM are DNS records: they work with Microsoft 365, Google Workspace or any other platform, with no migration.

Can your domain be spoofed?

Thirty minutes to look at your records, your senders and the lookalike domains already registered. You will know where you stand before deciding anything.