Back to Top
Inc. 5000 analyzed. Most fail basic email security. Where do you stand? [2026 Report]
Authentication
Authentication

Email authentication,
managed end to end

Covers the full authentication stack from SPF and DKIM to DMARC and BIMI. Provides centralized visibility, policy management, and a structured path to enforcement across every domain and sending source in your environment.

What Authentication provides

Capabilities covering the operational surface of email authentication, from raw reporting through to managed policy and monitoring.

DMARC reporting

Compliance reports with daily, weekly, and monthly views. Sending source table with expandable breakdowns. Geolocation maps, failure forensics with EML download, TLS-RPT reporting, XML viewer for individual aggregate reports, and BIMI brand impression analytics.

DMARC reporting

Managed authentication

CNAME-based managed records for DMARC, SPF, DKIM, and BIMI. Each protocol has its own activation flow with provider-specific instructions. EasySPF auto-detects sources from DNS and aggregate data. Managed DKIM supports multiple selectors with key strength monitoring.

Managed authentication

Enforcement tracking

Per-source compliance rates and pending actions, SPF gaps, DKIM rotation requirements, and DMARC misalignment surfaced per domain. Policy progression tooling with none / quarantine / reject configuration and impact visibility before each step is applied.

Enforcement tracking

Monitoring & alerting

Security alerts for unauthorized senders, compliance drops, policy changes, and DKIM rotation. Unified alert log combining DMARC, sender, and platform events. Notification channels: Email, Slack, Teams, Google Chat, Webhooks. Scheduled reporting with MSP white-label support.

Monitoring & alerting

How the Email Trust Platform Address It

Observe → Assess → Control

Authentication runs the platform's three-layer operating model across the full email authentication surface.

OBSERVE

Ingest and classify

DMARC aggregate and failure reports ingested across all connected domains. Raw XML processed into structured sending source data with compliance status, volume, and geographic distribution per source and per domain.

ASSESS

Identify gaps and measure compliance

Sending sources classified by type. Authentication gaps identified per source. Compliance rates calculated at the source level, not just in aggregate. Enforcement blockers surfaced with the specific records and configurations causing misalignment.

CONTROL

Enforce and maintain

Managed authentication records (DMARC, SPF, DKIM, BIMI) configurable and changeable through the platform. Policy changes applied without direct DNS access. Alerts fire on unauthorized senders, compliance drops, and policy drift.

Email Trust Platform

Interconnected across the Email Trust Platform

How Authentication connects to the rest of the platform.

Authentication connects
CONNECTS TO

DNS Manager

SPF, DKIM, and DMARC records live in DNS zones managed by DNS Manager. Changes to those records, whether made inside or outside the platform affect authentication compliance. DNS Manager's drift detection surfaces out-of-band changes.

CONNECTS TO

Sender Insights

Authentication compliance status per sending source feeds into Sender Insights delivery analysis. When a source's compliance drops, its delivery performance data in Sender Insights provides the operational context for the change.

CONNECTS TO

Threat Intelligence

Unauthorized senders identified in Authentication surface as threat signals in Threat Intelligence. Authentication enforcement status, whether a domain is at p=reject, determines how exposed the domain is to impersonation.

Email authentication, managed end to end