Your email, protected and proven.
Email is the number-one fraud vector against SMEs: domain spoofing, CEO fraud, invoice theft. We protect it — and we prove it to you with data, report after report.
Evidence, not promises: a periodic report per domain.
We implement and manage SPF, DKIM and DMARC, the three standards that verify that an email sent in your name really is yours, across all your company's domains — including the defensive ones, the domains you have registered but don't use, so that nobody can spoof them.
We don't publish three DNS records and call the job done: this is DMARC, monitored and operated. We receive and analyse the reports from receiving servers — with the help of automation and AI — we detect unrecognised sources and spoofing attempts, and we harden the policy in phases (none: observe only; quarantine: anything suspicious held back; reject: outright rejection), verifying each batch before moving on. Zero legitimate email blocked, checked batch by batch.
And you receive the deliverable periodically: a PDF report per domain showing who sends in your name, from where, and how many spoofing attempts have been blocked. On our private email platform, we also cross-check the reports against the server's actual logs: double visibility. Security you can't show doesn't exist.
It's one more layer of our managed cybersecurity. And what exactly is DMARC? Explained for anyone →. The back story: we have been auditing and protecting email since 2007, with the same perimeter discipline we were already applying in 2004.
Email security: the three fronts of fraud.
Domain authentication
SPF, DKIM and DMARC managed end to end, including the correct integration of newsletter and e-signature platforms.
A verifiable periodic report
One PDF per domain: legitimate traffic, sending sources and blocked spoofing attempts. Evidence, report after report.
Defensive domains
Your unused domains, armoured with a reject policy: registering them isn't enough if anyone can send in their name.
CEO fraud (BEC)
Our own rules that detect someone writing under an executive's name from an external address. We have intercepted an attempted transfer of €45,000.
Forensic analysis
With active email archiving we know what went out, when and where to — including hidden forwarding rules that exfiltrate information. Relevant under the GDPR too.
Credential defence
Automatic blocking of brute-force campaigns — thousands of attempts a day from hundreds of IPs — and implementation of two-factor authentication as the decisive defence.
- False positives
- 0 — not one legitimate email blocked, verified batch by batch
- DMARC authentication
- 95–100% of email authenticated across the managed domains
- Our own DNS zones
- 263 zones on elstir's authoritative servers
- Attacks blocked
- Up to 11,000 illegitimate access attempts a month at a single client
- Fraud intercepted
- An attempted transfer of €45,000 stopped before payment
A free DMARC audit of your domain.
Any domain's DMARC protection can be checked in seconds — and most SMEs discover that theirs doesn't exist or is misconfigured. Write to us with your domain and we'll send you the diagnosis: what you have, what you're missing and what risk it carries. Request your audit →
Shall we talk about your infrastructure?
An initial audit with no obligation. Tailored solutions, with a single point of contact who knows your business.