Email authentication, without the DNS degree

SentraDMARC gets receiving servers to reject mail that forges your domain, and keeps the mail you actually send out of spam. We host the records and keep them correct as your senders change.

Why it exists

I came to this from the security side, reading incident write-ups. The same opening move kept appearing: an email that looked like it came from someone the recipient already trusted.

The protocols that stop it have existed for years and are well specified. The tooling around them is the problem. It is priced on a call, scoped by a sales cycle, and configured by somebody else, and the failure mode is silent, so nobody finds out they got it wrong. Nothing bounces. You just quietly stop being trusted.

So the deal here is the opposite: published pricing, a scan that runs before you have an account, and no call to book. The application and every report we hold run on European infrastructure, and the people who wrote this answer the support email.

What it costs

The attack this prevents is not exotic. It is an invoice, from an address the recipient already trusts.

$3.05B
Lost to business email compromise in a single year. Second only to investment fraud, and ahead of ransomware.
FBI Internet Crime Complaint Center · 2025 Annual Report
$123,005
Average loss per reported incident, across 24,768 complaints. It is rarely one large theft; it is an invoice that looked right.
Derived from IC3 2025 figures · $3,046,598,558 ÷ 24,768

The attack is the same everywhere; the reporting is not. IC3 is the FBI's complaint centre and publishes the only hard numbers on it, from more than 200 countries in 2025, with France, Germany and the UK among its largest sources outside the US. Europol's IOCTA 2025 names business email compromise and CEO fraud as live threats across the EU without putting a figure on them, and most countries publish nothing at all.

What changed

Authentication used to be something you could postpone. Two dates ended that.

  • February 2024

    Google and Yahoo set a floor

    Bulk senders, meaning roughly 5,000 messages a day or more, were required to authenticate with SPF, DKIM and DMARC. Unauthenticated mail started being rejected rather than filtered.

  • March 2025

    PCI DSS 4.0 became mandatory

    Anti-phishing controls moved from best practice to requirement for anyone handling cardholder data. DMARC stopped being a security preference and became an audit line.

How we build it

  • Find the senders first

    Before anything is enforced, the reports have to say who is sending as you. Every source resolved to the service behind it: Stripe, HubSpot, a payroll system nobody remembered, because you cannot approve a policy against a list you have not seen.

  • Never move the policy for you

    Domains start at p=none and stay there while real mail is still failing. The step to reject is one approval, made when the data says it is safe. A tool that enforced on a schedule would eventually delete somebody’s invoices.

  • Say what we actually do

    We host DNS records. We do not send your mail and cannot sign it. Your provider does that, and holds the key. Products in this category are vague about that line, and a customer who misreads it can reach enforcement believing they are protected when they are not.

Built in Lyon, France

A small team working in email security. Built here, used anywhere: SPF, DKIM and DMARC are open standards, and a domain is a domain wherever it is registered. What Europe buys you is where your data lives, not permission to use the product.

If you want to know what your own domain looks like right now, the scan takes about four seconds and needs no account.

Scan my domain