Enforcement when it is safe
DMARC only helps once it is enforced, and enforcing it too early bounces your own invoices. We move it to quarantine, and then to reject, only when the reports show your real mail passing.
Email Authentication
Most domains have authentication that is half finished: an SPF record that grew past its lookup limit, DKIM missing on one sender, DMARC published but set to do nothing. Receivers notice, even when you do not.
With Cascadia you get
DMARC only helps once it is enforced, and enforcing it too early bounces your own invoices. We move it to quarantine, and then to reject, only when the reports show your real mail passing.
We find every service that sends as you, put one clean SPF record in place, sign each sender with DKIM, and publish DMARC. Then we read the reports each week so an unauthorized sender is something you hear about from us.
DMARC reports arrive as XML nobody opens. We gather and parse them, keep 90 days of history day by day, and each week tell you in plain words what passed, what failed, and which services are sending as you.
What you get
All of these come with Email Authentication, set up and looked after by our team.
Tell us your domain and we will find everything that sends as you.
A plugin will publish a record. The useful part is further in: finding every sender first, keeping SPF inside its limit, and knowing when it is safe to enforce.
| What to compare | A plugin that publishes records | Email Authentication |
|---|---|---|
| SPF | Appended to until it breaks | One record, kept inside its lookup limit |
| DKIM | One sender signed, the rest forgotten | Every sender found before anything is published |
| DMARC | Published at none, forever | Records checked daily, not once |
| Reports | XML nobody reads | Reports parsed weekly, automatically |
| Changes | Noticed eventually | A ticket the day a record or signature changes |
| Upkeep | Set once, never revisited | Reviewed as your senders change |
“I’ve always dreaded website management, but Cascadia has done an incredible job with my WordPress site, making it one less thing for me to worry about.”
“I’ve worked with Cascadia for several years now. They are always ready to help in any way I ask and can implement my ideas with ease. A company that values their clients!”
“Cascadia has been great to work with! We recently needed some updates, and Cascadia was quick to get them completed! We highly recommend Cascadia Web Services.”
“Cascadia is very responsive and we’re happy with them as our primary IT vendor.”
“They do great work, been using for years. Prompt responses to requests.”
An SPF record that grew past its lookup limit, DKIM missing on one sender, mail going out from a tool nobody remembers adding. We find every service that sends as you, put one clean record in place, and sign each sender.
Get startedReceivers decide in milliseconds whether to trust your mail, and they decide on what your domain publishes. Half-finished authentication is treated as no authentication.
Get startedYou can sell the outcome without hiring for it. We run the technical and content work under your brand, deliver reporting you can pass straight to a client, and stay out of the relationship.
Get startedWe read your DMARC reports so you do not have to, and tell you what needs attention.
We start by reading what your domain publishes today and what actually sends as you. Most businesses are surprised by at least one entry in that list.
Get startedRecords are published in the right order: SPF flattened and inside its lookup limit, DKIM signing for every sender, then DMARC at monitoring. Nothing is enforced until the reports show your real mail passing.
Get startedAfter that it runs itself. The reports are parsed each week, the records are checked daily, and you hear from us when something changes or when it is safe to move to enforcement.
Get startedPricing
$29/mo per domain
Get startedWe reply within two business days.Ask us
Weighing us against another option? Our comparisons take the main ones in turn.
See the comparisonsSPF, DKIM and DMARC for every service that sends as you, published in your DNS by us and checked every day.
Gmail and Outlook decide whether to trust your mail on what your domain publishes. Half-finished records are treated as none at all.
Yes. Authentication is what stops someone else sending invoices in your name, and it is the single biggest factor in whether Gmail and Outlook trust you at all.
We need your DNS, which is usually an invitation to your Cloudflare account. Nothing is installed on your website and no access to your mailboxes is needed.
DMARC tells receivers what to do with mail that fails. Started at monitoring it does nothing but gather reports, which is exactly what you want until your real mail passes.
Only when the reports show your real mail passing. Enforcing DMARC too early bounces your own invoices, so it goes to quarantine first and then to reject.
We do, weekly. They arrive as XML that nobody reads, which is why most businesses publish DMARC and learn nothing from it.
Yes. Unauthorized senders show up in the reports, and you hear about it from us rather than from a customer.
Access to your DNS, and ten minutes to tell us which services send email as you.
No. Nothing is published without checking what it breaks. The records go in order: SPF flattened and inside its lookup limit, then DKIM signing for every sender, then DMARC at monitoring.
This proves the mail is yours. Deliverability Monitoring watches whether it is arriving. They solve different halves of the same problem.
Yes. Workspace signs its own mail, and it knows nothing about your invoicing system, your CRM or your website forms.
Ninety days, day by day, so you can see what a record said on any date in that window.
Yes. It is monthly, and the records stay published in your DNS.
We’d love to hear from you!