Email protection setup (SPF and DMARC)

Until SPF and DMARC are in place and switched to enforcing, anybody in the world can send mail claiming to be from your domain, and the servers receiving it have no instruction to refuse. It is the cheapest impersonation there is, and it is aimed at your customers and your finance team rather than at you. Our Baltic web audit measured how common the gap is: a domain is only genuinely protected, meaning DMARC enforced and SPF strict, on 8% of live Latvian domains, 9% of Estonian and 3% of Lithuanian. We set the records up properly, then move the policy to enforcement in stages so your real mail never stops arriving.

What we know about it

Enforcement is the whole point, and it is where this usually stops

Publishing a DMARC record and leaving it on the default policy blocks nothing at all: it watches and reports, and a forged sender still lands in the inbox. That is the normal state of the Baltic web. Among the domains that do publish DMARC, the policy is monitor-only on 53.6% in Latvia, 68.6% in Estonia and 77.9% in Lithuania. The record was published and the switch was never flipped, usually because nobody was reading the reports and nobody wanted to be the person who broke email.

Staged, because the failure mode is your own mail disappearing

Go straight to a rejecting policy and the first casualty is the invoicing tool nobody remembered, or the newsletter platform set up by a marketing agency three years ago. We publish in monitor mode, read several weeks of real reports to find every legitimate sender, fix the ones that fail, and only then tighten. The order matters more than the records themselves.

SPF has a hard limit that most setups quietly exceed

An SPF record is allowed ten DNS lookups, and every hosted service you include eats at least one. Add a mail host, a CRM, a newsletter tool and an invoicing platform and the record silently fails, which means it is doing nothing while looking correct in the DNS. We check the lookup count, flatten or delegate where needed, and verify the result against real mail rather than against a syntax checker.

What's included
  • Audit of your current SPF, DKIM and DMARC records
  • An inventory of everything that legitimately sends as you: mail host, CRM, invoicing, newsletters, website forms
  • SPF rewritten to cover all of them without breaking the ten-lookup limit
  • DKIM signing enabled and verified on every sending platform
  • DMARC published in monitor mode first, with the reports collected somewhere a human can read
  • Staged move to quarantine and then reject, once the reports come back clean
  • A written record of what is allowed to send as you, so the next tool somebody buys does not silently break it
  • Ongoing monitoring as a care-plan line item

Who this is forFor companies whose invoices, quotes and customer notifications go out by email, and who would rather not learn about a forged sender from the customer who paid the fake invoice.

Frequently asked questions
What are SPF, DKIM and DMARC in plain language?

SPF is a list of the servers allowed to send mail for your domain. DKIM is a signature that proves a message was not altered on the way. DMARC is the instruction that ties them together and tells receiving servers what to do when a message fails: nothing, put it in spam, or reject it outright. All three live in your DNS, not on your website, and none of them cost anything to publish.

Can someone really send email as our company right now?

If your domain has no DMARC record, or has one on the default policy, then yes, and it takes no skill. That is the majority of domains in the region: 70% of live Latvian domains have no DMARC record at all, 60% of Estonian and 72% of Lithuanian. The free check on our Baltic audit page tells you which group you are in, in one lookup.

Will this break our newsletters, CRM or invoicing?

It will if it is done in one step by somebody who did not inventory your senders first, which is exactly why we do not work that way. The monitor phase exists to find the systems nobody remembers, and those show up in the reports within days. We fix them before enforcement, not after.

We already have SPF. Is that not enough?

No, and this is the most common misunderstanding. SPF validates the technical envelope, not the From address a person actually reads on screen. Without DMARC, a message can pass SPF for a completely different domain and still display your company in the sender line. DMARC is the part that ties the visible name to the check.

How long does it take?

The records themselves are a day of work. Getting safely to an enforcing policy takes four to eight weeks, because most of that time is waiting for real mail to flow through and show up in the reports. Rushing that window is how legitimate mail gets blocked.

Do we need to keep paying for it once it is done?

The records stay valid on their own. What changes is your business: somebody signs up for a new email tool, a supplier starts sending on your behalf, a platform rotates its sending infrastructure. Any of those can start failing a policy that was correct last year. Monitoring is a small care-plan line rather than a project, and it is the part that keeps the thing working.

What does it cost?

It is a small fixed-price job for most companies, and the price depends almost entirely on how many systems send mail as you: a single mail host is quick, a company with a CRM, two marketing platforms and an ERP is a longer inventory. We audit what you have first and quote a fixed number before starting.

Tell us what’s broken.
We’ll tell you the truth.

Book a free call →
Reply within one business day · EN / LV
↑↓ navigate · ↵ open · esc close