Verification

Email authentication and spoofing protection

CAVRIX makes sure nobody sends mail in your name and makes inbound forgeries visible. Rolled out step by step, without losing legitimate mail on the way.

The sender address is the easiest field in an email to fake, and it is exactly what your costliest day to day decisions rely on.

Why email fraud still works

People remain the decisive factor. The Verizon DBIR 2026 finds the human element in 62 percent of all breaches, phishing in 16 percent and pretexting in 6 percent of cases.

Without an enforced DMARC policy, anyone can send mail using your domain. Customers, suppliers and applicants receive messages that technically appear to come from you.

Inbound, the problem inverts: lookalike and typosquatting domains, and compromised supplier mailboxes, pass every technical check because they are formally correct.

What CAVRIX puts in place

Securing outbound mail

  • SPF, DKIM and DMARC set up properly, with every legitimate sending source accounted for
  • Policy raised step by step from p=none through p=quarantine to p=reject
  • SPF kept within the 10 DNS lookup limit, with alignment of envelope and header sender verified

Monitoring and hardening

  • DMARC report analysis so you can see who sends in your name
  • MTA-STS to protect transport encryption
  • BIMI as an optional step once the policy is enforcing

Detecting inbound threats

  • Detection of lookalike and typosquatting domains around your brand and your suppliers
  • Clear external sender marking directly in the mailbox
  • Detection of compromised supplier mailboxes from behavioural and contextual signals
What you get out of it
p=reject

Abuse of your domain gets rejected by receiving systems

Visibility

DMARC reports reveal every sending source, including those set up by business teams

Fewer bad clicks

External senders and lookalike domains are obvious in the mailbox

FAQ

Verification

  • Does DMARC fully protect us from spoofing?

    No. DMARC prevents abuse of your own domain, but not mail sent from a confusingly similar one. Anyone who registers a domain with swapped letters can configure valid SPF and DKIM on it. That is why domain monitoring and external sender marking belong in the same programme.

  • Can we go straight to p=reject?

    We advise against it. A policy enforced too early blocks legitimate mail from third party systems such as newsletter tools, applicant tracking, ERP or ticketing. The sequence matters: p=none with report analysis first, then p=quarantine, then p=reject.

  • Why does the 10 DNS lookup limit in SPF matter so much?

    Once the limit is exceeded, the receiving server treats the SPF check as a permanent error and the protection silently stops working. It happens easily when service providers have been added to the record over the years. We clean the record up and keep it under the limit permanently.

  • Are we legally required to implement this?

    No, there is no explicit legal obligation to deploy DMARC. What is relevant are the supply chain security and access control requirements in Sec. 30 (2) no. 4 and no. 9 BSIG, controls A.5.7 and A.5.17 of ISO 27001:2022, and Sec. 130 OWiG on management supervisory duties, with fines of up to 1 million euro. Separately, large mailbox providers increasingly downgrade senders without proper authentication.

  • How long does the rollout take?

    Mostly it depends on how many systems send in your name. We inventory every sending source first, set up authentication, and watch the reports before tightening the policy. Every step is reversible. Questions to info@cavrix.de.

Find out who is sending mail in your name today

We audit your domain, show you the open sending paths and plan the route to p=reject so that nothing legitimate gets lost.