Every term you will meet when someone talks about email security, explained for business owners rather than technicians.
Terms are grouped so each builds on the one before it, rather than listed alphabetically.
Domain. Your address on the internet. Your website lives on it and your email sends from it. An asset you own.
DNS. The internet’s public address book. It tells other systems where your domain lives, and it carries the security settings described here.
DNS record. A single entry in that address book. Some point to your website, some route your email, and some declare who may send email in your name.
Mail platform. The system running your day-to-day mailboxes. Usually the main sender on a domain, but rarely the only one.
Sender. Any system sending email using your domain name. Your mail platform, your newsletter tool, your invoicing software, your booking system, often your website’s forms. Most businesses have more than they realise.
Spoofing. Sending email that pretends to come from your domain. Without protection, anybody can, and the receiving mailbox cannot reliably tell.
Phishing. What spoofing is usually used for: a fraudulent email designed to trick the reader into paying a false invoice, clicking a dangerous link, or handing over details.
Lookalike domain. A domain registered to resemble yours. Protection stops exact impersonation; watching for lookalikes catches the near misses.
Deliverability. Whether your legitimate email actually arrives, rather than landing in spam. Poor authentication is a common and fixable cause of poor deliverability.
Email authentication. The umbrella term for SPF, DKIM and DMARC working together.
SPF. A record listing which systems may send in your name. The approved-senders list.
DKIM. A tamper-proof signature on your outgoing mail, verified against a key published on your domain. The wax seal.
DMARC. The policy that ties the two together, telling receiving systems what to do with mail that fails, and asking them for reports.
Policy levels. Monitor, which watches and reports but delivers everything. Quarantine, which treats failures as suspicious. Reject, which refuses them outright.
Enforcement. Having the policy at quarantine or reject. The finish line. A domain at monitor is collecting information but is not protected.
Alignment. The requirement that the domain passing authentication matches the domain the reader sees. What stops a technicality passing while the visible sender is forged.
Aggregate reports. The activity summaries receiving providers send back once DMARC asks for them. How genuine senders are confirmed and impostors spotted.
MTA-STS. Requires other systems to deliver mail to you over encrypted connections.
TLS-RPT. Reporting on whether those encrypted connections are working.
DNSSEC. Signs your DNS entries so they cannot be quietly forged or tampered with.
BIMI. Your registered logo displayed beside your emails in supporting inboxes. Requires enforcement first.
Email readiness check. A free, no obligation look at where a domain currently stands: what is configured, what is actually enforced, and what that means in plain English. Nothing is installed and nothing changes. The lighter, faster cousin of the deliverability audit.
Deliverability audit. A fixed-scope assessment: grade, full sender inventory, findings with business impact, and a prioritised path to enforcement.
Staged rollout. Tightening one step at a time, confirming with evidence between each. The method that prevents a business blocking its own mail.
Monitoring. The ongoing half. An audit is a photograph; monitoring is the security camera.
Managed DNS. Having the domain’s records looked after professionally, so nothing lapses and changes are made safely.
The email readiness check is free, and the domain and email protection page walks through exactly how it all works.