Create Accountor Login

Email Authentication

Email Authentication: proving the mail is really from you, and keeping it that way

Most domains have authentication that is half finished: an SPF record that grew past its lookup limit, DKIM missing on one sender, DMARC published but set to do nothing. Receivers notice, even when you do not.

With Cascadia you get

  • SPF set up properly
  • DKIM signing on your domain
  • DMARC enforced when it is safe
  • Reports read for you
  • Watched every day
  • Set up once, kept right

Why teams start here

Enforcement when it is safe

DMARC only helps once it is enforced, and enforcing it too early bounces your own invoices. We move it to quarantine, and then to reject, only when the reports show your real mail passing.

Set up properly, once

We find every service that sends as you, put one clean SPF record in place, sign each sender with DKIM, and publish DMARC. Then we read the reports each week so an unauthorized sender is something you hear about from us.

Reports read for you

DMARC reports arrive as XML nobody opens. We gather and parse them, keep 90 days of history day by day, and each week tell you in plain words what passed, what failed, and which services are sending as you.

What you get

Everything Email Authentication covers

All of these come with Email Authentication, set up and looked after by our team.

SPF

  • Every sender that mails as you, found first
  • One SPF record, inside its lookup limit
  • Third-party senders included, not forgotten
  • Flattened when it grows too long
  • Checked daily for changes

DKIM

  • DKIM signing set up for each sender
  • Keys published in your DNS by us
  • Selectors checked daily for resolution
  • Rotation handled when a provider requires it
  • Told the day a signature stops validating

DMARC

  • DMARC published, starting at monitoring
  • Reports gathered and parsed automatically
  • Moved to quarantine, then reject, when clean
  • Alignment problems explained in plain words
  • Nothing enforced before your real mail passes

Watching

  • Unauthorized senders using your domain, surfaced
  • A weekly read of what the reports say
  • 90 days of history, day by day
  • Every published record checked daily for changes
  • A ticket naming what changed and what it was

What sets it apart

  • Enforcement when it is safe
  • Set up properly, once
  • Reports read for you
  • Email specialists, not a helpdesk
  • Nothing published without checking what it breaks
  • Your domain stays yours

Want your email proven to be yours?

Tell us your domain and we will find everything that sends as you.

What a plugin sets up, and what it leaves out

A plugin will publish a record. The useful part is further in: finding every sender first, keeping SPF inside its limit, and knowing when it is safe to enforce.

What to compareA plugin that publishes recordsEmail Authentication
SPFAppended to until it breaksOne record, kept inside its lookup limit
DKIMOne sender signed, the rest forgottenEvery sender found before anything is published
DMARCPublished at none, foreverRecords checked daily, not once
ReportsXML nobody readsReports parsed weekly, automatically
ChangesNoticed eventuallyA ticket the day a record or signature changes
UpkeepSet once, never revisitedReviewed as your senders change

What clients say about working with Cascadia

“I’ve always dreaded website management, but Cascadia has done an incredible job with my WordPress site, making it one less thing for me to worry about.”
Alex R.Cascadia client

Want your email proven to be yours?

Talk to us

Who Email Authentication fits best

Teams with more senders than anyone can list

An SPF record that grew past its lookup limit, DKIM missing on one sender, mail going out from a tool nobody remembers adding. We find every service that sends as you, put one clean record in place, and sign each sender.

Get started

Domains with authentication half set up

Receivers decide in milliseconds whether to trust your mail, and they decide on what your domain publishes. Half-finished authentication is treated as no authentication.

Get started

Agencies reporting this for their clients

You can sell the outcome without hiring for it. We run the technical and content work under your brand, deliver reporting you can pass straight to a client, and stay out of the relationship.

Get started

Ready to stop reading DMARC reports?

We read your DMARC reports so you do not have to, and tell you what needs attention.

How it works

1. We find everything that sends as you

We start by reading what your domain publishes today and what actually sends as you. Most businesses are surprised by at least one entry in that list.

Get started

2. We publish the records properly

Records are published in the right order: SPF flattened and inside its lookup limit, DKIM signing for every sender, then DMARC at monitoring. Nothing is enforced until the reports show your real mail passing.

Get started

3. You get the picture every month

After that it runs itself. The reports are parsed each week, the records are checked daily, and you hear from us when something changes or when it is safe to move to enforcement.

Get started

Pricing

What Email Authentication costs

$29/mo per domain

Get startedWe reply within two business days.

Ask us

Answers to common Email Authentication questions

Weighing us against another option? Our comparisons take the main ones in turn.

See the comparisons
What does Email Authentication cover?

SPF, DKIM and DMARC for every service that sends as you, published in your DNS by us and checked every day.

Why does this matter?

Gmail and Outlook decide whether to trust your mail on what your domain publishes. Half-finished records are treated as none at all.

Is this worth doing before anything has gone wrong?

Yes. Authentication is what stops someone else sending invoices in your name, and it is the single biggest factor in whether Gmail and Outlook trust you at all.

Do you need access to our website or our mailboxes?

We need your DNS, which is usually an invitation to your Cloudflare account. Nothing is installed on your website and no access to your mailboxes is needed.

What is DMARC and why start at monitoring?

DMARC tells receivers what to do with mail that fails. Started at monitoring it does nothing but gather reports, which is exactly what you want until your real mail passes.

When do you move to enforcement?

Only when the reports show your real mail passing. Enforcing DMARC too early bounces your own invoices, so it goes to quarantine first and then to reject.

Who reads the reports?

We do, weekly. They arrive as XML that nobody reads, which is why most businesses publish DMARC and learn nothing from it.

Will I know if someone spoofs my domain?

Yes. Unauthorized senders show up in the reports, and you hear about it from us rather than from a customer.

What do you need from me?

Access to your DNS, and ten minutes to tell us which services send email as you.

Will this break my existing email?

No. Nothing is published without checking what it breaks. The records go in order: SPF flattened and inside its lookup limit, then DKIM signing for every sender, then DMARC at monitoring.

How is this different from Deliverability Monitoring?

This proves the mail is yours. Deliverability Monitoring watches whether it is arriving. They solve different halves of the same problem.

Do I need this if I use Google Workspace?

Yes. Workspace signs its own mail, and it knows nothing about your invoicing system, your CRM or your website forms.

How long do you keep the history?

Ninety days, day by day, so you can see what a record said on any date in that window.

Can I stop at any time?

Yes. It is monthly, and the records stay published in your DNS.

Ask Us Anything

We’d love to hear from you!