Anyone can send emails that look like they come from your address
The most common scam is a fake invoice or a “change of bank details” email sent to your clients in your name. We prepare the DMARC policy for you, ready to paste in, which gets Gmail, Outlook and Yahoo to reject those emails: you or whoever manages your site adds it, and your mailbox is never touched.
For businesses with email on their own domain, with any provider: Aruba, Register, Google, Microsoft and others. The monthly check is optional, at €9/month.
1No DMARC policy
Nobody tells mail servers what to do with a fake email sent in your name.
2Policy in monitor-only mode
Servers see that the email is fake, but still deliver it.
3The policy rejects fake emails
Gmail, Outlook and Yahoo reject them. This is where your domain ends up, with the records we prepare for you.
If we wrote to you, the email said which of the first two states your domain was in, read that day from the public DNS.
What we do, step by step
The records are ready within 2 working days of your go-ahead, and full protection is in place within 3–5 weeks: before tightening the policy we read the reports, until all your genuine emails get through.
Who is sending in your name
Your email provider, your management or invoicing software, newsletters, your website’s contact form. We work it out from the public DNS and the first DMARC reports.
The records, ready to paste in
A correct SPF record, DKIM switched on by your provider, DMARC in monitor-only mode with the reports sent to us, and a one-page guide for your control panel: Aruba, Register, OVH, GoDaddy, Squarespace, Google or Microsoft. You or whoever manages your site adds them.
The policy is tightened
When the reports show that all your genuine emails get through, usually after 2–4 weeks, the policy moves fake emails to quarantine, then rejects them. Every step can be checked on the public DNS by anyone, even without us.
A closing report (in Italian)
The date from which your domain rejects fake emails, who sends in your name, and what to do if you add a new piece of software.
The price, and the limits stated up front
A fixed-price job, with the final report. The monthly check is added only if you want it.
Securing your domain
€149 one-off
With a 4% surcharge for INPS, Italy’s social security institute (rivalsa INPS), €154.96 in total. Paid by bank transfer, on order.
Who sends in your name, from the DNS and the reports
The records, ready to go, and the guide for your control panel
The policy tightened until it rejects fake emails
The final report (in Italian), with the date from which your domain is protected
Every month we read your domain’s DMARC reports: who sent in your name, what was rejected, whether a new piece of software of yours stops getting through. A one-page report (in Italian), and an email straight away if someone unrelated tries to use your domain.
One record correction a month is included, for a change of provider or a new piece of software. Monthly cancellation; paid month by month, in advance.
The limits
We do not get into your systems. You or whoever manages your site adds the records, with our guide. If you want us to do it with temporary access, we decide that together case by case.
We do not read your email. DMARC reports contain server addresses and counts, not the messages.
We do not manage mailboxes, passwords or your email provider.
We protect your domain from anyone using it to impersonate you. Phishing that reaches you from other domains is a different service, and we do not promise it here.
Protection applies to your exact domain, not to ones that look similar to it (is4lct.com instead of is4ict.com).
If your provider does not allow DKIM on the plan you have, we tell you in writing before starting.
Everything in writing: no phone calls, no on-call cover at night or on public holidays.
Prices are in euro. No VAT is charged (flat-rate regime, regime forfettario); a 4% INPS surcharge (rivalsa INPS) is added to the invoice. “Fixed price” means the job never costs more than what is written. We invoice clients in Italy; elsewhere in the European Union, only businesses with a valid VAT number in VIES, the EU’s VAT validation system.
Do you need to get into our website or domain control panel?
No. We prepare the records and a guide; you or whoever manages your site pastes them in. If you would rather we did it, with temporary access, we decide that together case by case.
Do you read our email?
No. DMARC reports say who sent in your name and what happened, not the content of the messages.
Have we been attacked?
We do not know, and we will not say so without evidence: we only tell you what the public DNS of your domain shows today.
Does it also protect domains that look like ours?
No: the policy covers your exact domain. A domain that looks like yours (for example with one letter changed) is a different domain, with its own rules.
Is the monthly check compulsory?
No. Securing your domain costs €149 one-off, with the final report; if you also want ongoing monitoring you add €9 a month, and if you don’t, you just pay the €149.
Can we talk about it on the phone?
For now we work entirely in writing: you tell us what you need and we reply within one working day.
Where to start
A couple of lines to progetti@is4ict.com: who manages your domain and whether you’d like to go ahead. We reply within one working day; the records to paste in, with the guide, arrive within 2 working days of your go-ahead.