Features

Features in detail

Mailsecurity24 combines DMARC analysis, sender analysis, DNS checks, blacklist monitoring and alerting in one portal. Here is what each feature actually does.

Analyse DMARC reports automatically

Mailbox providers such as Google, Microsoft and Yahoo send daily reports on which servers sent under your domain and whether those messages passed SPF and DKIM. The reports arrive as compressed XML – we receive, unpack and analyse them for you.

Good to know: Files are processed safely: size and decompression limits block manipulated archives, and the XML reader never loads external content.

Analyse and classify senders

The key question before a strict policy is: which services actually send on your behalf? Newsletter tool, accounting, ticket system, web shop – often more than you think.

Path to p=reject and monthly protection report

The goal of every DMARC rollout is the strict policy “p=reject”: spoofed emails are rejected while your own keep arriving. Mailsecurity24 shows you whether your domain is ready – and what still needs fixing first.

Good to know: The protection report summarises checked messages, blocked spoofing, the DMARC rate over time, all domains and what has been achieved and what is still open on a single page – ideal for passing on to management. In the Agency plan it carries your own name and logo.

DNS checks for SPF, DKIM, DMARC and MX

Checks run daily and can be triggered at any time. Every finding is explained clearly – together with what to do about it.

Learn more:All about SPF →All about DKIM →

Good to know: SPF allows at most ten DNS lookups. Beyond that limit many receivers treat SPF as failed – even if the record looks correct at first glance.

Mail encryption: TLS, MTA-STS and TLS reports

DMARC protects your sender name – but does your email also arrive encrypted? Mailsecurity24 checks the transport encryption of your mail servers every day and shows whether other servers can deliver to you securely.

Learn more:All about MTA-STS →All about TLS-RPT →

BIMI: your logo in the inbox

With BIMI (Brand Indicators for Message Identification), your brand logo appears right next to your emails in the inbox – a visible mark of authenticity that forgers cannot copy. It requires an enforced DMARC policy. Mailsecurity24 checks your BIMI record, shows the published logo and guides you safely to p=reject with the DMARC analysis – the key step on the way to BIMI. The BIMI logo studio converts your logo straight into the required SVG Tiny PS format and checks it against every requirement – three logos per month on Basic, no fixed limit and hosting from Premium.

Learn more:All about BIMI →

Good to know: Gmail and Apple Mail only show BIMI logos with a mark certificate (VMC or CMC). Without a certificate the logo currently appears at Yahoo, among others. The logo must be available as an SVG in Tiny PS format over HTTPS – exactly the format the BIMI logo studio creates, with hosting included from Premium.

Blacklist monitoring

If a sending server is blacklisted, messages never reach many recipients. We check your senders regularly and report new listings right away.

Good to know: A listing on a shared server does not automatically mean you did something wrong. What matters is whether it is your own sending server.

Alerts and notifications

Learn about problems before your customers notice – without an email every minute.

Overview and guided setup

You don’t need to be an email security expert. The domain list shows at a glance where everything is fine and what still needs doing – and the guided view takes you step by step to full protection.

Team, security and privacy

Mailsecurity24 is built for teams and service providers – and secured the way we recommend for your domains.

Frequently asked questions about SPF, DKIM, BIMI and MTA-STS

SPF defines which servers may send email for your domain. DKIM signs every message cryptographically so recipients can detect changes. DMARC links both to the visible sender address, decides what happens to forgeries and delivers daily reports. Mailsecurity24 analyses these reports and checks all three records continuously.

BIMI shows your brand logo next to your emails in the inbox. You need a DMARC policy with p=quarantine or p=reject, a logo in SVG Tiny PS format at an HTTPS address and a BIMI record in DNS. Gmail and Apple Mail additionally require a mark certificate (VMC or CMC). Mailsecurity24 checks the record, shows the logo and guides you safely to p=reject. You can create a matching logo in SVG Tiny PS format with the BIMI logo studio – and try it for free on our website.

MTA-STS (SMTP MTA Strict Transport Security) specifies that other mail servers deliver email to your domain only encrypted and only to your genuine mail servers. This stops attackers from quietly stripping encryption. Mailsecurity24 checks MTA-STS on every plan; from Premium we monitor record, policy and mail servers daily, warn about errors and help with a setup generator.

With TLS-RPT (SMTP TLS Reporting), Google, Microsoft and other providers report daily whether they could deliver email to your domain encrypted and where errors occurred. From Premium, Mailsecurity24 analyses these reports clearly and shows problems with certificates or the MTA-STS policy at a glance.

Yes. Every day we check whether your mail servers accept encrypted connections (STARTTLS), which TLS version they use and whether their certificate is valid. You get an alert before a certificate expires and when encryption is missing or outdated.

We automatically check common selectors of major providers and also pick up every selector that appears in your DMARC reports. You can store your own selectors per domain. Messages without a DKIM signature of your domain are detected as “not signed”.

Ready for secure email?

Try Mailsecurity24 free for 14 days. No payment details required.