DKIM
Every message is signed with your domain's key, so a receiver can prove it really came from you.
The seal
Delivery is not a setting you hope was configured once. Records are checked continuously and their state is visible inside your admin centre.
Every message is signed with your domain's key, so a receiver can prove it really came from you.
Only our sending hosts are authorised for your domain. Nobody else can send in your name.
Alignment enforced with reporting, so spoofing attempts are rejected and visible.
Encrypted in transit on modern ciphers, with certificates renewed automatically.
Six records decide whether your company's mail is trusted. We watch all six for you and show the verdict in plain words — not a screenshot of a DNS console.
Live results for the whole platform are published on the status page.
The parts most providers leave to a policy page nobody reads.
On our own servers in the UK and EU, on encrypted disks, in racks we pay for. Your mail is not resold storage from a hyperscaler with our logo on the invoice.
Nobody. Support does not browse mailboxes, and there is no advertising or profiling system to feed. Any access to your workspace by us requires your written request and lands in your own audit log.
Every sign-in records device, location and time. Anything that looks impossible — two countries in ten minutes — is flagged, and you can end any session or device from your own security page in one click.
Mail is backed up continuously so a lost mailbox is recoverable. When you delete for real, the deletion flows into the backups too — deleted does not mean hidden.
Failures appear on the public status page from the same probes above, not after a customer complains. If mail is affected you get told, with what happened and what changed.
One click exports everything in standard formats, on every plan. Security includes the freedom to walk away with your own data intact.