SentraDMARC gets receiving servers to reject mail that forges your domain, and keeps the mail you actually send out of spam. We host the records and keep them correct as your senders change.
I came to this from the security side, reading incident write-ups. The same opening move kept appearing: an email that looked like it came from someone the recipient already trusted.
The protocols that stop it have existed for years and are well specified. The tooling around them is the problem. It is priced on a call, scoped by a sales cycle, and configured by somebody else, and the failure mode is silent, so nobody finds out they got it wrong. Nothing bounces. You just quietly stop being trusted.
So the deal here is the opposite: published pricing, a scan that runs before you have an account, and no call to book. The application and every report we hold run on European infrastructure, and the people who wrote this answer the support email.
The attack this prevents is not exotic. It is an invoice, from an address the recipient already trusts.
The attack is the same everywhere; the reporting is not. IC3 is the FBI's complaint centre and publishes the only hard numbers on it, from more than 200 countries in 2025, with France, Germany and the UK among its largest sources outside the US. Europol's IOCTA 2025 names business email compromise and CEO fraud as live threats across the EU without putting a figure on them, and most countries publish nothing at all.
Authentication used to be something you could postpone. Two dates ended that.
Bulk senders, meaning roughly 5,000 messages a day or more, were required to authenticate with SPF, DKIM and DMARC. Unauthenticated mail started being rejected rather than filtered.
Anti-phishing controls moved from best practice to requirement for anyone handling cardholder data. DMARC stopped being a security preference and became an audit line.
Before anything is enforced, the reports have to say who is sending as you. Every source resolved to the service behind it: Stripe, HubSpot, a payroll system nobody remembered, because you cannot approve a policy against a list you have not seen.
Domains start at p=none and stay there while real mail is still failing. The step to reject is one approval, made when the data says it is safe. A tool that enforced on a schedule would eventually delete somebody’s invoices.
We host DNS records. We do not send your mail and cannot sign it. Your provider does that, and holds the key. Products in this category are vague about that line, and a customer who misreads it can reach enforcement believing they are protected when they are not.
A small team working in email security. Built here, used anywhere: SPF, DKIM and DMARC are open standards, and a domain is a domain wherever it is registered. What Europe buys you is where your data lives, not permission to use the product.
If you want to know what your own domain looks like right now, the scan takes about four seconds and needs no account.
Scan my domain