Business Marketing Systems

Domain and email protection

Your email arrives.

Nobody can send email pretending to be your exact domain. Set up carefully over four to six weeks, then monitored so it stays that way.

Three things go wrong with every unprotected domain

Every business runs on a domain name. Your website sits on it and your email comes from it. Three things go wrong with it, and all three are silent until they are not.

Your email stops arriving. Not all of it, and not obviously. Quotes and invoices land in spam folders, and you never hear about the ones that did. You conclude the client went elsewhere.

Anybody can send email as you. Not from a lookalike address. From your exact domain. Your clients cannot tell the difference, and neither can their mail systems, unless specific steps have been taken to make that impossible. What that enables is an email that appears to come from you, sent to your clients, asking them to pay an invoice to updated bank details.

The domain lapses. When it does, the website and the email fail together, usually without warning. The causes are mundane: a renewal notice sent to an address nobody monitors, a card that expired, a registration sitting with a supplier you parted ways with years ago.

Where most domains actually stand

Ask whoever looks after your technology: what is our DMARC policy currently set to? There are three possible settings. Monitor, which watches and reports but delivers everything regardless. Quarantine, which treats failures as suspicious. Reject, which refuses them outright. Only the last two protect anything. The first is a listening post.

If the answer is monitor, or “I would have to check”, or “we have that configured”, you are almost certainly not protected. Configured and protected are different things, and most domains stop at configured. We see businesses that have paid for a monitoring tool for years with the policy never moved off monitor. Everything looks correct. Nothing is protected.

The rules around this have tightened. Google and Yahoo introduced formal sender requirements in early 2024, and Microsoft followed in 2025 with outright rejection rather than spam placement for senders who do not meet them. The strictest rules apply to senders pushing more than 5,000 messages a day, far beyond what most small businesses send, but the baseline now applies to everyone, and the direction of travel is one way. Authentication has become a condition of good delivery rather than a nice extra.

What fixing it involves

1. Find out where you stand

Every system sending in your name, whether each is properly authorised, and what the policy is set to.

2. Turn the lights on

One small, safe change so the world's mail systems begin sending activity reports. Nothing about your mail flow changes.

3. Get every genuine sender recognised

Each legitimate system properly authorised and signed, using real evidence rather than assumption.

4. Tighten in stages

Monitor, to quarantine, to reject, confirming at each step that nothing legitimate is being caught.

5. Confirm and prove

The before and after, which is also the documentation an insurer will ask for.

6. Keep watch

Every new tool your business adds is a new sender, and unmanaged it either fails or forces the protection back down. Most of those weeks are not work. They are waiting for evidence, because that is how long real mail takes to build a reliable picture of who actually sends in your name. The slowness is the safety.

What we saw on our own domain

We ran this process on our own domain before offering it to anyone else. It started at a Grade F. It is now in the staged tightening phase, which is exactly the pace we describe above, and the monitoring window showed us something worth sharing.

During that window, 133 messages from 98 internet addresses across 21 countries attempted to send email as businessmarketingsystems.com.au. None of them were ours, and none of them passed authentication.

That was not an attack on our business. It is routine background abuse, the kind that reaches every unprotected domain continuously. The only unusual thing is that we could see it. If you are wondering why we were singled out, the honest answer is that we were not, and that is exactly the point. The same traffic is claiming to be your domain right now. The difference is whether anything is checking.

We work alongside your existing IT

If you have an IT provider, or a capable person in-house, the fair question is why this is not already fixed. The answer is structural, and it is not a criticism of them. Email authentication sits outside the security frameworks IT providers work to. The Australian Signals Directorate’s Essential Eight does not include it. Neither does ISO 27001 in its Annex A controls. A provider working diligently to those standards has completed everything they were asked to complete. Meanwhile, cyber insurers assess these controls directly at underwriting, and increasingly verify them rather than accept self-assessment.

That is the gap, and we work alongside your existing IT support to close it. Their role does not change. Your mail platform stays as it is. Your email addresses stay the same. Your website carries on untouched. Your DNS stays where it is, with whoever manages it today, unless you would rather we look after it. Any provider who requires you to hand your domain records over to them is worth questioning. Your own time across the whole engagement is typically under two hours.

Questions we are usually asked

No. Your mail platform, your email addresses, your website and the way everyone works stay exactly as they are. What changes is a small set of records published on your domain, and the policy setting.

No. Your DNS stays with whoever manages it today, and we specify each record exactly so there is nothing to interpret. If you would prefer us to manage the DNS, that is available, but it is an option rather than a requirement.

Around four to six weeks for a straightforward domain. Most of that time is waiting for evidence rather than work, and the waiting is what makes it safe to tighten without blocking your own mail.

Yes, without hesitation. This work sits outside the frameworks they are usually asked to deliver against, so it is a specialist layer alongside what they do, not a replacement for them. We tell them exactly what we need, which is DNS records and nothing more.

It is the setting on your domain that tells the world’s mail systems what to do with email that fails authentication. It has three settings, and only two of them protect anything, which is why “we have DMARC configured” and “we are protected” are different statements. Our plain language glossary explains it, and every other term on this page, without the jargon.

It stops impersonation of your exact domain. It does not stop somebody registering a similar looking domain, such as yourbusiness-au.com instead of yourbusiness.com.au, and using that instead. Watching for lookalike domains is a separate layer, and one worth asking us about. We would rather you knew the limit than discovered it.

Where to start

Two ways in, and both are free. Request a free email readiness check and we will tell you where you stand: what is configured, what is actually enforced, and what that means in plain English. Nothing is installed and nothing on your domain changes.

Setup from $395. Ongoing from $150 a year. Businesses with several sending platforms, or with compliance and insurance obligations, are priced individually. Introductory pricing. All figures exclude GST. If you want the full picture, with a grade and a complete inventory of every system sending in your name, ask us about a domain and email deliverability audit. If you go on to full protection with us, the audit fee is credited in full.

This field is for validation purposes and should be left unchanged.
Authorisation(Required)

Prefer to talk it through first?

A short, no-pressure call to walk through where your domain stands.