Genharden
Free check

Managed email security · Free check

Email spoofing? We'll handle it.

A dedicated consultant handles the analysis and monitoring. We get your domain to DMARC p=reject, the policy that rejects forged mail, in 4 to 6 weeks.

All you need is an email address. The report arrives by email.

The problem

Anyone can send mail using your exact domain

This is not about lookalike addresses. An impostor can write your domain, spelled exactly right.

Your mail server

From: ceo@example.co.kr

Impostor's server

From: ceo@example.co.kr
Received by FinanceSpoofing example
C

CEO <ceo@example.co.kr>

To: Finance team

Urgent transfer request

The supplier's bank details have changed.

Please send today's payment to the account below.

Two servers wrote the same address, and the recipient sees one message. No account had to be hacked.

Mail from your own server, from your agency, from an impostor. To Gmail all three look identical, because it has no way of knowing which vendors you hired.

So your sending arrangements have to be published in DNS: the allowed servers, a signing key, a policy for mail that fails, and an address for the results. Without those four, receivers accept forged mail too.

In early 2026, of about 930,000 domains with a DMARC record, only 10.7% had reached p=reject.

The cause

Four lines that belong in your DNS

Receiving servers look up the sender's DNS for every message. What they find there decides whether a forged message is rejected.

SPF
The list of servers allowed to send mail for your domain. The -all at the end tells receivers to reject everyone else.
DKIM
A digital signature on every message. Receivers verify it against this public key.
DMARC
What receivers should do with mail that fails SPF and DKIM: reject it or send it to spam. p=reject is the goal.
RUA
Where receivers send their result reports. Reading them is how you find out who is sending as your domain.
example.co.kr · DNS
  1. @TXT
    v=spf1 include:_spf.google.com ip4:203.0.113.10 -all
    SPF

    Allowed sending servers

  2. google._domainkeyTXT
    v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A…
    DKIM

    Public key for signatures

  3. _dmarcTXT
    v=DMARC1; p=reject; rua=mailto:example@rua.genharden.com
    DMARC

    Policy for failed mail

  4. example._report._dmarc.rua.genharden.comTXT
    v=DMARC1
    RUA

    Report address

The fix

Three ways to stop spoofing

Secure your DNS records, monitor lookalike domains, and review your mail server settings regularly.

Spoofing your own domain

Stopped by DNS records

We identify legitimate senders from the reports, add them to SPF and DKIM, and raise the policy from none to quarantine to reject. Low-traffic subdomains go first so real mail keeps flowing.

  1. p=none · Watch. Collect reports only
  2. p=quarantine · Send failures to spam
  3. p=reject · Reject failures. Mission done

Lookalike domain spoofing

Alerts on new registrations

A domain that swaps rn for m is beyond DMARC's reach. We check typo, homoglyph and TLD variants daily, alert you to new registrations and help with takedown requests. We also track your own domain's expiry date.

Watchingexample.co.kr
  • exarnple.co.krNew
  • example-kr.comNew
  • examp1e.co.krNew
Domain expiry2027-03-01D-166 alert

Your own mail server

Keep your server from relaying spam

One missing line in Postfix or Exim turns a mail server into an open relay. We check what is visible from outside, including TLS certificate expiry, then fix the configuration together after signing.

mail.example.co.kr:25
  • FAIL

    Open relay

    relays outside mail without authentication

  • WARN

    STARTTLS

    TLS 1.0 allowed

  • WARN

    TLS certificate

    expires in 12 days, no auto-renewal

  • FAIL

    Plaintext auth

    accepts logins before encryption

Does not apply if you only use Google Workspace or Microsoft 365.

How it works

The 4 to 6 week mission, week by week

All you do is apply the DNS records. Your consultant reads the reports and decides what to change.

  1. Week 1

    Assessment and report address

    We count your sending sources and confirm which vendors support DKIM. You get a clear go or no-go on the deadline first.

    p=none; rua=…
  2. Weeks 2–3

    Sort out the senders

    We classify legitimate sources from the reports and hand you SPF and DKIM records for each service. You paste them into DNS.

    SPF -all, DKIM 2048
  3. Week 4

    Quarantine

    Failed mail goes to spam. If a real sender gets caught, we roll back the same day.

    p=quarantine
  4. Weeks 5–6

    Reject. Mission complete

    Failed mail is rejected and you get a completion note. Ongoing monitoring takes over.

    p=reject; sp=reject

What you do

Apply DNS records and confirm your vendor list. Under 30 minutes a week.

What the consultant does

Read reports, classify senders, write records, decide when to move up, talk DKIM with vendors.

What you get every week

A one-page report: pass rate trend, new senders, next week's to-do.

Monitoring

Once you sign, we check two things every day

The reports receivers send about your domain, and the mail that goes out to your customers. A person reads both, every day.

Who is sending mail as your domain

DMARC aggregate reports from Gmail, Naver and other receivers arrive at a rua address issued by Genharden. Your consultant classifies senders and failures daily.

  • Track unknown senders
  • Find why legitimate mail fails
  • Decide when p=reject is ready
example.co.krLast 7 days
MonTueWedThuFriSatSun
PassedFailed
1 unknown sender found. Your consultant is checking it.

Counts are illustrative. Coverage depends on participating receivers.

We receive the same mail your customers do

You get a test customer address. Register it for signups, orders and newsletters, and we keep checking the authentication and headers of everything that arrives.

  • SPF, DKIM and DMARC alignment
  • One-click unsubscribe header on marketing mail
  • Message headers and body links
Test customer inboxaudit-7f3k@inbox.genharden.com
  • What's new this week

    Newsletter

    09:41
  • Your order is confirmed

    Order notification

    09:34
  • Verify your email address

    Account signup

    09:27

Authentication

Passed

Unsubscribe header

Present

Body links

Checked

This samples one inbox. It does not guarantee every customer's inbox placement.

If your mail lands in spam

Fix authentication and mail stops landing in spam

Without authentication, Gmail cannot tell your mail from a forgery. It treats the message as unauthenticated and may send it to spam or reject it.

Major providers require the items below from bulk senders. Miss one and legitimate mail lands in spam; keep missing it and your domain's reputation drops.

  • SPF and DKIM authentication plus a DMARC policy
  • From address aligned with the authenticated domain
  • One-click unsubscribe header, honored within 2 days
  • Spam complaint rate under 0.3%
  • Reverse DNS (PTR) matching the sending IP
  • Delivery over a TLS connection

Each provider's rules and start dates are listed below.

Before58%42%After96%4%InboxSpam or rejected

Illustration only. Real numbers depend on your domain and sending history.

Provider requirements

Unauthenticated mail goes to the spam folder

Gmail, Yahoo and Naver have required sender authentication since 2024, and Outlook since 2025.

  • Gmail2024-02

    Above 5,000 messages a day you need SPF, DKIM and DMARC. Since November 2025, non-compliant mail is rejected.

  • Yahoo2024-02

    Same rules as Gmail. The spam complaint rate must stay under 0.3%.

  • Outlook2025-05

    Above 5,000 messages a day you need SPF, DKIM and DMARC. Non-compliant mail goes to junk first, then gets rejected.

  • Naver2024-07

    Mail without SPF, or failing it, may be blocked. Bulk senders also need PTR and DMARC.

Sources: Google Email sender guidelines, Yahoo Sender Requirements, Microsoft Outlook high-volume sender requirements, Naver Mail notice.

Genharden

Handled by a team that operates email at scale

Genharden operates SigninID, an email service. Every day we filter forged mail as a receiver and meet the major providers' rules as a sender.

Genharden Email Security applies that experience to outbound mail alone. Instead of a dashboard, a person reads your reports and writes back.

1M+

SigninID users

20M+

messages handled

Self-managed vs managed

Dashboard tools

Reports pile up, but reading them, making decisions and contacting vendors is still your job.

Genharden Email Security

Your consultant reads, decides and makes the calls. You apply DNS changes and skim a weekly report.

Services

Free checks. Managed service when you need more

The free check shows where your domain stands. The managed service fixes it and keeps watching.

ItemDescriptionFree checkone-off · recurringManagednamed consultant
SPF checkRecord present, syntax, all qualifier, 10-lookup limitIncludedIncluded
DKIM checkSelectors for common services, key length, syntaxIncludedIncluded
DMARC checkPresent, syntax, policy, alignment options, rua addressIncludedIncluded
Recurring check reportsSame items re-checked weekly or monthly, emailed to youIncludedIncluded
Transport encryption checkSTARTTLS, TLS version, MTA-STS, TLS-RPT, DANENot includedIncluded
DNS and reputation checkMX, PTR, DNSSEC, blocklistsNot includedIncluded
Bulk sender requirementsGmail, Yahoo, Outlook rules: alignment, unsubscribe header, spam rateNot includedIncluded
Domain and certificate expiry alertsDomain registration and TLS certificate expiry, renewal statusNot includedIncluded
Lookalike domain monitoringNew typo, homoglyph and TLD variants, alerts, takedown helpNot includedIncluded
Mail server external scanOpen relay, version disclosure, plaintext auth, STARTTLSNot includedIncluded
RUA report addressReceive and store DMARC aggregate reportsNot includedIncluded
Report reading and sender classificationA person reads pass and fail per sourceNot includedIncluded
Test customer inboxA test address whose incoming mail is checked for authentication, headers and linksNot includedIncluded
SPF and DKIM setup supportRecords per sending service, SPF cleanup, key rotationNot includedIncluded
DMARC rolloutPlan and execution from none to quarantine to rejectNot includedIncluded
Transport encryption setup supportMTA-STS hosting, TLS-RPT collection, DANENot includedIncluded
Mail server hardeningPostfix and Exim relay limits, required auth, TLS, DKIM signingNot includedIncluded
Weekly report and named consultantProgress report, alerts, email and phone supportNot includedIncluded
4 to 6 week p=reject missionFeasibility call, weekly plan, completion noteNot includedIncluded

Recurring checks start from the button inside your report.

Free check

See where your domain stands today

Give us a name, an email address and a domain. We check SPF, DKIM and DMARC and email you a link to the report.

  1. 1

    Request

    Submit the form and you get a confirmation email.

  2. 2

    Check

    We read your SPF, DKIM and DMARC records from public DNS.

  3. 3

    Report

    PASS, WARN or FAIL per item with a one-line explanation, a demo link, and a button for recurring checks.

  • No DNS access or credentials. We only read public information.
  • No sales calls. Book a demo through the link whenever you want.
  • Reports usually arrive within one business day.

Filled from your email address. Change it to check a different domain.

This form uses Cloudflare Turnstile to filter bots.

Frequently asked questions

The questions we hear most often in demos.

Do you really reach p=reject in 4 to 6 weeks?

With fewer than ten sending sources and vendors that support DKIM, usually under 4 weeks. Many sources or a vendor without DKIM can push it to 6. We give you a go or no-go during the free check, and the conditions go into the contract.

Could legitimate mail get blocked?

We start with p=none, collecting reports only, then apply quarantine and reject to low-traffic subdomains first. If a legitimate sender shows up as failing, we roll back the same day.

Does this work with Google Workspace or marketing tools?

Yes. We keep the SPF includes and DKIM selectors of common Korean and international services and hand you the records. Vendors not on the list, we contact ourselves.

Do I have to hand over DNS access?

No. We send record values and your team applies them, or we do it together over screen share. The free check only reads public information.

What does it cost?

It depends on the number of domains, sending sources, and whether you run your own mail server. We quote during the demo, after the free check. Free checks have no time limit.

What happens when you find a lookalike domain?

You get the registration date, name servers and MX status. If it is ready to send mail, we help with the registrar complaint and a staff notice. Registration itself cannot be prevented.

Do you also block phishing in incoming mail?

No. Genharden Email Security keeps your domain from being spoofed and gets your outgoing mail delivered. Gateways that scan incoming mail are out of scope.

Does p=reject stop all spoofing?

It stops mail that uses your exact domain. Lookalike domains, display-name tricks and hijacked accounts need other measures: monitoring for the first, staff notices and inbound security for the rest.

Does the free check sign me up for recurring mail?

No. You get one report. Recurring checks are opt-in from inside the report and can be stopped with a single link.

Email spoofing? We'll handle it.

Run the free check and see how exposed your domain is right now.

Request the free check