DNS & Email Authentication
10 checks · 2 sub-categories
If your domain isn't properly authenticated, anyone on the internet can send email that appears to come from your business — to your customers, your suppliers and your own staff. This is the cheapest, highest-impact area in the entire audit, and it is wrong or incomplete in the clear majority of Australian small businesses we look at.
Sender authentication
SPF record present, valid and not over the lookup limit
We validate the syntax, count DNS lookups against the 10-lookup ceiling, and check the policy is ~all or -all rather than the permissive +all.
- ACSC email hardening guidance
- CIS GW 3.7
DKIM signing enabled with a 2048-bit key
Google generates a DKIM key but does not publish or activate it for you. We check the key exists, is published in DNS, is authenticating, and is 2048-bit rather than 1024.
- ACSC email hardening guidance
- CIS GW 3.8
DMARC record published with an enforcing policy
A p=none record collects data but blocks nothing. We report your current policy, alignment mode and whether you're ready to move to quarantine or reject.
- ACSC email hardening guidance
- SCuBA GWS.GMAIL
- Essential Eight (supporting)
DMARC aggregate reporting going somewhere useful
An rua address nobody reads means spoofing goes unnoticed. We check reporting is configured and that the destination is monitored.
Sub-domains and parked domains covered
Attackers happily spoof invoice.yourbusiness.com.au. We check sp= policy on the parent and authentication records on secondary and parked domains.
Transport and domain hygiene
MTA-STS and TLS reporting configured
MTA-STS forces inbound mail to be delivered over TLS and defeats downgrade interception. We check the policy file, DNS record and TLS-RPT destination.
Secure transport (TLS) compliance rules in Gmail
Where a customer or regulator requires encrypted transport with a specific partner, Gmail can enforce it. We check whether required-TLS rules exist for sensitive counterparties.
MX records point only to Google
Stray or legacy MX entries indicate old hosting, shadow relays or a partial migration. Every record is listed and explained.
Domain registrar lock and DNSSEC status
Domain hijacking bypasses every email control you own. We check registrar lock, expiry date and whether DNSSEC is enabled.
Look-alike domain exposure
We check for obvious registered look-alikes of your domain — the ones used to invoice your customers while pretending to be you.
Want to know where you actually stand?
Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.