We assess the domain
We review the public email-authentication records and identify the systems your business legitimately uses to send email.
SenderShield checks the public settings that help protect your business domain from spoofing, then helps you secure them safely. Pay once for the setup, then add ongoing monitoring only if you want it.
Email authentication gives receiving systems clearer instructions about which services are allowed to send as your domain. SenderShield helps configure that safely without pretending it prevents every type of phishing or fraud.
Enter your company domain. We’ll check public DMARC and SPF records, HTTPS certificate health and website availability. We never ask for your email password.
Use the domain after the @ in your work email, or your company website address.
The scan checks public internet records only. Lookup requests are processed by a third-party DNS/SSL checking service. Do not enter passwords or confidential information.
A result is a technical snapshot, not evidence that your business has been hacked and not a guarantee against fraud. SenderShield focuses on email-domain authentication and monitoring.
The one-off Secure service finishes with a plain-English configuration summary. Protect customers then receive ongoing visibility when senders or authentication settings change.
SenderShield is not a one-click switch to strict DMARC enforcement. We first identify legitimate email senders, monitor the domain, and then strengthen protection in stages so normal business email is not accidentally disrupted.
We review the public email-authentication records and identify the systems your business legitimately uses to send email.
For a standard setup, we use a monitored rollout—typically at least 2–4 weeks—before moving toward quarantine or reject where appropriate.
After the one-off setup, you can stop there or add ongoing monitoring for new senders, authentication failures and configuration changes.
Monitoring is optional because DMARC itself is not a monthly repair job. The value is catching the changes around it—before they quietly create authentication or impersonation problems.
A CRM, newsletter platform, invoicing tool, website form or booking system can start sending mail for your domain. SenderShield helps check that it authenticates correctly.
Old services can remain in SPF, new services can push it toward technical limits, and DNS settings can change. Monitoring flags issues that a one-off setup cannot predict.
A concise report shows authentication health, relevant failures and changes. Healthy months are reported honestly rather than inventing “threats blocked.”
You do not need a permanent subscription just to have your email authentication configured properly. Start with the one-off setup, then choose whether ongoing monitoring is useful for your business.
SenderShield is designed around the practical problems smaller businesses actually have: not knowing every sender, worrying that a DNS change might break email, and not wanting another expensive security platform.
Strict enforcement is not switched on blindly. Legitimate sending services are checked before policy is strengthened.
Completion and monitoring reports show the status, relevant changes and any next action in plain English.
Email authentication reduces direct domain spoofing risk. It is not presented as a guarantee against every phishing or fraud technique.
If the free check found something to review — or you just want the setup checked properly — send the basics below. For standard domains, SenderShield Secure starts at £99 one-off.
Run the free public-record check first. It takes seconds and needs no login.
No. Public DNS settings show how your domain is configured. A weak or monitoring-only policy can justify attention, but it is not evidence of compromise.
It can if it is changed carelessly. A proper rollout identifies legitimate senders first and progresses policy in stages. SenderShield should not jump a complex domain straight to strict enforcement without checking what sends on its behalf.
Not reliably from a domain name alone in every case because DKIM uses selectors that are not universally discoverable. We verify DKIM during onboarding when the sending systems/selectors are known.
No. SenderShield Secure is a one-off service for businesses that want the setup fixed properly. SenderShield Protect is optional ongoing monitoring for businesses that want alerts and support when their email environment changes.
The DMARC record may stay unchanged, but the systems around it do not. Businesses add CRMs, invoicing tools, newsletter services, website forms and other senders. SPF, DKIM alignment and DNS settings can also change. Monitoring is designed to catch those changes rather than charge you for repeatedly checking an unchanged line of DNS.
No. Correct authentication can reduce avoidable delivery problems, but inbox placement also depends on sender reputation, complaints, content and the receiving provider. SenderShield does not promise inbox placement.
No. Email authentication helps reduce direct spoofing of your domain, but it cannot prevent every form of phishing, mailbox compromise or lookalike-domain fraud. SenderShield is one layer of protection, not a guarantee against financial loss.