A dedicated consultant handles the analysis and monitoring.
We get your domain to DMARC p=reject, the policy that rejects forged mail, in 4 to 6 weeks.
All you need is an email address. The report arrives by email.
Free check report
example.co.kr
1/3
passed
PASSSPFrecord found
FAILDKIMno signing key found
FAILDMARCp=none · no report address
Current DMARC policy
v=DMARC1; p=none · fakes are not filtered
Spoofable
The problem
Anyone can send mail using your exact domain
This is not about lookalike addresses.
An impostor can write your domain, spelled exactly right.
Your mail server
From: ceo@example.co.kr
Impostor's server
From: ceo@example.co.kr
Received by FinanceSpoofing example
C
CEO <ceo@example.co.kr>
To: Finance team
Urgent transfer request
The supplier's bank details have changed.
Please send today's payment to the account below.
Two servers wrote the same address, and the recipient sees one message. No account had to be hacked.
Mail from your own server, from your agency, from an impostor. To Gmail all three look identical, because it has no way of knowing which vendors you hired.
So your sending arrangements have to be published in DNS: the allowed servers, a signing key, a policy for mail that fails, and an address for the results. Without those four, receivers accept forged mail too.
In early 2026, of about 930,000 domains with a DMARC record, only 10.7% had reached p=reject.
The cause
Four lines that belong in your DNS
Receiving servers look up the sender's DNS for every message.
What they find there decides whether a forged message is rejected.
SPF
The list of servers allowed to send mail for your domain. The -all at the end tells receivers to reject everyone else.
DKIM
A digital signature on every message. Receivers verify it against this public key.
DMARC
What receivers should do with mail that fails SPF and DKIM: reject it or send it to spam. p=reject is the goal.
RUA
Where receivers send their result reports. Reading them is how you find out who is sending as your domain.
Secure your DNS records, monitor lookalike domains,
and review your mail server settings regularly.
Spoofing your own domain
Stopped by DNS records
We identify legitimate senders from the reports, add them to SPF and DKIM, and raise the policy from none to quarantine to reject. Low-traffic subdomains go first so real mail keeps flowing.
p=none · Watch. Collect reports only
p=quarantine · Send failures to spam
p=reject · Reject failures. Mission done
Lookalike domain spoofing
Alerts on new registrations
A domain that swaps rn for m is beyond DMARC's reach. We check typo, homoglyph and TLD variants daily, alert you to new registrations and help with takedown requests. We also track your own domain's expiry date.
Watchingexample.co.kr
exarnple.co.krNew
example-kr.comNew
examp1e.co.krNew
Domain expiry2027-03-01D-166 alert
Your own mail server
Keep your server from relaying spam
One missing line in Postfix or Exim turns a mail server into an open relay. We check what is visible from outside, including TLS certificate expiry, then fix the configuration together after signing.
mail.example.co.kr:25
FAIL
Open relay
relays outside mail without authentication
WARN
STARTTLS
TLS 1.0 allowed
WARN
TLS certificate
expires in 12 days, no auto-renewal
FAIL
Plaintext auth
accepts logins before encryption
Does not apply if you only use Google Workspace or Microsoft 365.
How it works
The 4 to 6 week mission, week by week
All you do is apply the DNS records.
Your consultant reads the reports and decides what to change.
1
Week 1
Assessment and report address
We count your sending sources and confirm which vendors support DKIM. You get a clear go or no-go on the deadline first.
p=none; rua=…
2
Weeks 2–3
Sort out the senders
We classify legitimate sources from the reports and hand you SPF and DKIM records for each service. You paste them into DNS.
SPF -all, DKIM 2048
3
Week 4
Quarantine
Failed mail goes to spam. If a real sender gets caught, we roll back the same day.
p=quarantine
4
Weeks 5–6
Reject. Mission complete
Failed mail is rejected and you get a completion note. Ongoing monitoring takes over.
p=reject; sp=reject
What you do
Apply DNS records and confirm your vendor list. Under 30 minutes a week.
What the consultant does
Read reports, classify senders, write records, decide when to move up, talk DKIM with vendors.
What you get every week
A one-page report: pass rate trend, new senders, next week's to-do.
Monitoring
Once you sign, we check two things every day
The reports receivers send about your domain, and the mail
that goes out to your customers. A person reads both, every day.
Who is sending mail as your domain
DMARC aggregate reports from Gmail, Naver and other receivers arrive at a rua address issued by Genharden. Your consultant classifies senders and failures daily.
Track unknown senders
Find why legitimate mail fails
Decide when p=reject is ready
example.co.krLast 7 days
MonTueWedThuFriSatSun
PassedFailed
1 unknown sender found. Your consultant is checking it.
Counts are illustrative. Coverage depends on participating receivers.
We receive the same mail your customers do
You get a test customer address. Register it for signups, orders and newsletters, and we keep checking the authentication and headers of everything that arrives.
SPF, DKIM and DMARC alignment
One-click unsubscribe header on marketing mail
Message headers and body links
Test customer inboxaudit-7f3k@inbox.genharden.com
What's new this week
Newsletter
09:41
Your order is confirmed
Order notification
09:34
Verify your email address
Account signup
09:27
Authentication
Passed
Unsubscribe header
Present
Body links
Checked
This samples one inbox. It does not guarantee every customer's inbox placement.
If your mail lands in spam
Fix authentication and mail stops landing in spam
Without authentication, Gmail cannot tell your mail from a forgery. It treats the message as unauthenticated and may send it to spam or reject it.
Major providers require the items below from bulk senders. Miss one and legitimate mail lands in spam; keep missing it and your domain's reputation drops.
SPF and DKIM authentication plus a DMARC policy
From address aligned with the authenticated domain
One-click unsubscribe header, honored within 2 days
Spam complaint rate under 0.3%
Reverse DNS (PTR) matching the sending IP
Delivery over a TLS connection
Each provider's rules and start dates are listed below.
Illustration only. Real numbers depend on your domain and sending history.
Provider requirements
Unauthenticated mail goes to the spam folder
Gmail, Yahoo and Naver have required sender authentication since 2024,
and Outlook since 2025.
Gmail2024-02
Above 5,000 messages a day you need SPF, DKIM and DMARC. Since November 2025, non-compliant mail is rejected.
Yahoo2024-02
Same rules as Gmail. The spam complaint rate must stay under 0.3%.
Outlook2025-05
Above 5,000 messages a day you need SPF, DKIM and DMARC. Non-compliant mail goes to junk first, then gets rejected.
Naver2024-07
Mail without SPF, or failing it, may be blocked. Bulk senders also need PTR and DMARC.
Sources: Google Email sender guidelines, Yahoo Sender Requirements, Microsoft Outlook high-volume sender requirements, Naver Mail notice.
Genharden
Handled by a team that operates email at scale
Genharden operates SigninID, an email service. Every day we filter forged mail as a receiver and meet the major providers' rules as a sender.
Genharden Email Security applies that experience to outbound mail alone. Instead of a dashboard, a person reads your reports and writes back.
1M+
SigninID users
20M+
messages handled
Self-managed vs managed
Dashboard tools
Reports pile up, but reading them, making decisions and contacting vendors is still your job.
Genharden Email Security
Your consultant reads, decides and makes the calls. You apply DNS changes and skim a weekly report.
Services
Free checks. Managed service when you need more
The free check shows where your domain stands. The managed service fixes it and keeps watching.
Item
Description
Free checkone-off · recurring
Managednamed consultant
SPF check
Record present, syntax, all qualifier, 10-lookup limit
Same items re-checked weekly or monthly, emailed to you
Included
Included
Transport encryption check
STARTTLS, TLS version, MTA-STS, TLS-RPT, DANE
Not included
Included
DNS and reputation check
MX, PTR, DNSSEC, blocklists
Not included
Included
Bulk sender requirements
Gmail, Yahoo, Outlook rules: alignment, unsubscribe header, spam rate
Not included
Included
Domain and certificate expiry alerts
Domain registration and TLS certificate expiry, renewal status
Not included
Included
Lookalike domain monitoring
New typo, homoglyph and TLD variants, alerts, takedown help
Not included
Included
Mail server external scan
Open relay, version disclosure, plaintext auth, STARTTLS
Not included
Included
RUA report address
Receive and store DMARC aggregate reports
Not included
Included
Report reading and sender classification
A person reads pass and fail per source
Not included
Included
Test customer inbox
A test address whose incoming mail is checked for authentication, headers and links
Not included
Included
SPF and DKIM setup support
Records per sending service, SPF cleanup, key rotation
Not included
Included
DMARC rollout
Plan and execution from none to quarantine to reject
Not included
Included
Transport encryption setup support
MTA-STS hosting, TLS-RPT collection, DANE
Not included
Included
Mail server hardening
Postfix and Exim relay limits, required auth, TLS, DKIM signing
Not included
Included
Weekly report and named consultant
Progress report, alerts, email and phone support
Not included
Included
4 to 6 week p=reject mission
Feasibility call, weekly plan, completion note
Not included
Included
Recurring checks start from the button inside your report.
Free check
See where your domain stands today
Give us a name, an email address and a domain. We check SPF, DKIM
and DMARC and email you a link to the report.
1
Request
Submit the form and you get a confirmation email.
2
Check
We read your SPF, DKIM and DMARC records from public DNS.
3
Report
PASS, WARN or FAIL per item with a one-line explanation, a demo link, and a button for recurring checks.
No DNS access or credentials. We only read public information.
No sales calls. Book a demo through the link whenever you want.
Reports usually arrive within one business day.
Frequently asked questions
The questions we hear most often in demos.
Do you really reach p=reject in 4 to 6 weeks?
With fewer than ten sending sources and vendors that support DKIM, usually under 4 weeks. Many sources or a vendor without DKIM can push it to 6. We give you a go or no-go during the free check, and the conditions go into the contract.
Could legitimate mail get blocked?
We start with p=none, collecting reports only, then apply quarantine and reject to low-traffic subdomains first. If a legitimate sender shows up as failing, we roll back the same day.
Does this work with Google Workspace or marketing tools?
Yes. We keep the SPF includes and DKIM selectors of common Korean and international services and hand you the records. Vendors not on the list, we contact ourselves.
Do I have to hand over DNS access?
No. We send record values and your team applies them, or we do it together over screen share. The free check only reads public information.
What does it cost?
It depends on the number of domains, sending sources, and whether you run your own mail server. We quote during the demo, after the free check. Free checks have no time limit.
What happens when you find a lookalike domain?
You get the registration date, name servers and MX status. If it is ready to send mail, we help with the registrar complaint and a staff notice. Registration itself cannot be prevented.
Do you also block phishing in incoming mail?
No. Genharden Email Security keeps your domain from being spoofed and gets your outgoing mail delivered. Gateways that scan incoming mail are out of scope.
Does p=reject stop all spoofing?
It stops mail that uses your exact domain. Lookalike domains, display-name tricks and hijacked accounts need other measures: monitoring for the first, staff notices and inbound security for the rest.
Does the free check sign me up for recurring mail?
No. You get one report. Recurring checks are opt-in from inside the report and can be stopped with a single link.
Email spoofing? We'll handle it.
Run the free check and see how exposed your domain is right now.