Managed DMARC, SPF and MTA-STS

Email Authentication, Built and Monitored by AOIT

Email spoofing is one of the most common techniques used by cybercriminals, and attackers do not need to compromise your systems to send convincing emails in your name. We run our own custom-built platform to configure and manage DMARC, SPF and MTA-STS for your domain, so your email is properly authenticated and protected.

Your Domain Could Be Sending Emails You Never Wrote

Without proper authentication records in place, attackers can send emails that appear to come from your domain to anyone, tricking recipients into clicking malicious links or handing over sensitive information, even if your own systems are never compromised.

DKIM, SPF and DMARC verify that emails claiming to come from your domain were genuinely sent by you, and instruct receiving mail servers on what to do with messages that fail that verification. MTA-STS goes a step further, enforcing encrypted delivery so your email cannot be intercepted or downgraded in transit.

Getting this configuration right requires technical precision. We built our own platform to manage it properly, rather than relying on a generic third-party tool.

Industry-wide data from the last 18 months

86% of businesses had staff click a phishing link
68% of breaches involve human error
$125K average financial loss per business email compromise attack

SPF and DKIM, Correctly Configured

SPF tells receiving servers which systems are authorised to send email on behalf of your domain. DKIM adds a digital signature to your outgoing emails that proves they have not been tampered with in transit.

DMARC Policy That Protects Your Reputation

DMARC ties your SPF and DKIM records together and gives you control over what happens when an email fails authentication.

Encrypted Delivery With MTA-STS

MTA-STS enforces encrypted connections for incoming mail, protecting your email from interception or downgrade attacks in transit.

A Platform We Built, Not a Third-Party Tool

Our DMARC, SPF and MTA-STS platform is built and maintained in-house, giving us full visibility and control over your email authentication setup rather than relying on a generic reseller tool.

DMARC generates detailed reports on every email sent using your domain. We monitor these reports on an ongoing basis and adjust your configuration as your email environment changes.

About Us

What Our Partners Say

Kings Church Gateshead

Unparalleled Customer Service

As a charity it was of great importance to us that we had customer support in regards to the choice of services. AOIT Networks have gone above and beyond to ensure a seamless hosting, service transfer and guidance along the way. In addition to services we applied for through AOIT, they advised we applied for a Microsoft 365 NonProfit license, then aided the set up and provided training to our administration.

Read More

Smashdown Consultants

There to help even if you're not sure what to do!

AOIT are always there to help, even when I wasn't sure what the solution is! A few weeks ago, I tried to call a contact. The outbound call didn't work, so I dropped them a text, and they were unable to reach me either. Having worked with Andrew a few times previously, I decided to get in touch with him, even though it was none of his equipment causing issues.

Read More

Real Reviews From Real Partners

  • Every review here is unedited, pulled directly from Trustpilot
  • From real AOIT clients across the UK, not hand-picked quotes
  • Good or bad, it's all there, because that's the point of transparency
Read All Reviews on Trustpilot

Frequently Asked Questions

DKIM, SPF and DMARC are email authentication records that verify emails claiming to come from your domain were genuinely sent by you. MTA-STS enforces encrypted delivery for incoming mail, protecting it from interception in transit.

Domain spoofing does not require your systems to be compromised. Without these records, attackers can impersonate your domain regardless of how secure your own environment is.

We built and manage this platform ourselves, which gives us full visibility and control over your configuration rather than relying on a generic third-party service.

We roll out DMARC policy gradually, starting with monitoring only, so we can confirm all legitimate mail is passing authentication before enforcing stricter policies.

DMARC reporting shows every email sent using your domain, including attempts that fail authentication. We monitor these reports and adjust your configuration as needed.

Yes. DKIM, SPF, DMARC and MTA-STS are relevant regardless of whether you use Microsoft 365, Google Workspace or another email platform.

A policy of none only monitors and reports on email sent using your domain, without affecting delivery. Quarantine sends messages that fail authentication to the recipient junk folder. Reject blocks them outright. We move your domain through these stages gradually, starting with monitoring so we can confirm all your legitimate mail passes authentication before tightening the policy to quarantine and then reject.

Yes. Attackers can target subdomains even when the main domain is properly protected, so we configure a policy that covers subdomains as well, either by extending the main record or publishing separate subdomain records where needed.

Has Your Domain Already Been Compromised?

Without DMARC reporting in place, you would have no way of knowing. Get in touch and we will audit your current email authentication setup and put the right records in place.

Contact Us