← Google Workspace audit scope

DNS & Email Authentication

10 checks · 2 sub-categories

If your domain isn't properly authenticated, anyone on the internet can send email that appears to come from your business — to your customers, your suppliers and your own staff. This is the cheapest, highest-impact area in the entire audit, and it is wrong or incomplete in the clear majority of Australian small businesses we look at.

Sender authentication

  • SPF record present, valid and not over the lookup limit

    We validate the syntax, count DNS lookups against the 10-lookup ceiling, and check the policy is ~all or -all rather than the permissive +all.

    • ACSC email hardening guidance
    • CIS GW 3.7
  • DKIM signing enabled with a 2048-bit key

    Google generates a DKIM key but does not publish or activate it for you. We check the key exists, is published in DNS, is authenticating, and is 2048-bit rather than 1024.

    • ACSC email hardening guidance
    • CIS GW 3.8
  • DMARC record published with an enforcing policy

    A p=none record collects data but blocks nothing. We report your current policy, alignment mode and whether you're ready to move to quarantine or reject.

    • ACSC email hardening guidance
    • SCuBA GWS.GMAIL
    • Essential Eight (supporting)
  • DMARC aggregate reporting going somewhere useful

    An rua address nobody reads means spoofing goes unnoticed. We check reporting is configured and that the destination is monitored.

  • Sub-domains and parked domains covered

    Attackers happily spoof invoice.yourbusiness.com.au. We check sp= policy on the parent and authentication records on secondary and parked domains.

Transport and domain hygiene

  • MTA-STS and TLS reporting configured

    MTA-STS forces inbound mail to be delivered over TLS and defeats downgrade interception. We check the policy file, DNS record and TLS-RPT destination.

  • Secure transport (TLS) compliance rules in Gmail

    Where a customer or regulator requires encrypted transport with a specific partner, Gmail can enforce it. We check whether required-TLS rules exist for sensitive counterparties.

  • MX records point only to Google

    Stray or legacy MX entries indicate old hosting, shadow relays or a partial migration. Every record is listed and explained.

  • Domain registrar lock and DNSSEC status

    Domain hijacking bypasses every email control you own. We check registrar lock, expiry date and whether DNSSEC is enabled.

  • Look-alike domain exposure

    We check for obvious registered look-alikes of your domain — the ones used to invoice your customers while pretending to be you.

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.