Email spoofing protection for your domain
Defensio Identity Shield is an email spoofing protection and DMARC monitoring service for SMEs and MSPs that turns raw DMARC reports into a readable list of who sends mail as your domain, tests your defences on a schedule, and watches for lookalike domains registered to impersonate you.
For an Italian manufacturing company running Microsoft 365 behind a mail-security gateway, we forged their CEO's address and sent it in. The message reached the IT manager's inbox — across three internal delivery paths and one external one.
Root cause: no DMARC policy. SPF correctly flagged the forgery, but with no DMARC policy published the receiver applied no action and delivered it anyway. Only DMARC in reject mode covers every path.
What is DMARC monitoring?
DMARC monitoring collects the aggregate reports that Google, Microsoft and other receivers send about mail claiming to come from your domain, and turns them into a readable picture: which sources passed authentication, which failed, and which unauthorised servers are sending as you. Without it, those XML reports are unreadable and the failures stay invisible.
DMARC monitoring
See every source sending as your domain, pass and fail trends over time, your current policy state, and a clear path from monitoring to enforcement.
Scheduled spoof testing
We forge mail from your domain to a seed mailbox you control, on a schedule, and tell you the moment a defence stops holding. Authorised, and never sent to anyone else.
Lookalike domain watch
We generate the misspellings an attacker would register, check which exist, and flag the ones that are armed — holding mail records, a TLS certificate, or a live site.
MTA-STS and TLS-RPT
Keep inbound mail encrypted in transit, catch a policy that no longer matches your real mail servers, and read the TLS failure reports receivers send back.
How do I stop someone sending email as my domain?
Publish a DMARC policy in reject mode, and keep it correct. Reject mode is the only control a receiver applies no matter which path the forged message took, so it is what closes exact-domain spoofing. Getting there safely needs visibility first: you must know every legitimate sender before you tell receivers to reject, or you will block your own mail. Identity Shield gives you that visibility, then proves the result by testing it.
What makes this different from a DMARC report reader?
Three things a report dashboard cannot do. We test your defences on a schedule instead of only reading reports, so a regression surfaces as an alert rather than as a real incident. We tell you whether a lookalike domain is armed, not merely registered — the difference between noise and a live threat. And your alerts land inside the Defensio SOC, alongside the rest of your security telemetry, watched by the same analysts.
Simple, transparent pricing
Identity Shield is priced per protected domain, per month, with every capability included in every tier.
All capabilities included on every paid plan. Prices exclude IVA.
Identity Shield
- DMARC monitoring
- Unauthorised sender view
- Monthly spoof test
- Lookalike registration watch
- MTA-STS + TLS-RPT
- Alerts inside the Defensio SOC
- 12 months history
Compliance
Everything in Identity Shield, plus:
- Weekly & on-demand tests
- Signed PDF evidence report
- Armed lookalike detection
- 24 months history, API, SSO
MSP & Volume
For resellers & organisations with 10+ domains
10 domains at Compliance level, then €19/domain (11–50), €14 (51+)
- Multi-tenant console
- White-label reports
- Per-client dashboards
- Single invoice
Price it for your domains
Set your domain counts and every plan above reprices, volume discount included — 30% off domains 2–5, 50% off from the 6th. We will tell you when a different plan becomes the better deal.
Volume discount is applied automatically and shown above. Beyond eight protected domains we quote by hand. EU reverse charge applies for VAT-registered businesses.
Questions
Will you send real spoofed email to my staff?
No. The test sends to a single seed mailbox that you register and control, never to your users, and never as a campaign. Every test message identifies itself as sanctioned in its headers, and a live send requires your written authorisation on file. Until then the test runs in dry-run mode.
Do I need to change my DNS?
Yes, one record. You add a DMARC record naming our reporting address, which is what makes receivers start sending the reports. Nothing about your mail flow changes, and no mail is routed through us. MTA-STS and TLS-RPT need one record each if you want those too.
What is a lookalike domain?
A domain registered to resemble yours — a missing letter, two letters swapped, a digit replacing a letter, or your name plus a word like “login”. Attackers use them for invoice fraud and credential phishing. We flag the ones that are armed with mail records, a certificate or a live site, because those are being prepared for use.
How fast will I see results?
The transport and lookalike checks run within a day of adding a domain. DMARC reports depend on the receivers: most send once every 24 hours, so expect a useful picture within two to three days and a reliable trend within a fortnight.
Do you support MSPs managing multiple clients?
Yes. The MSP plan includes ten domains with a multi-tenant console, per-client dashboards, white-label reports and a single invoice, then €19 per additional domain up to fifty and €14 beyond that.
Is this the same as my mail filter or gateway?
No, and they solve opposite problems. A gateway filters mail arriving at you. Identity Shield is about mail sent as you — to your customers, suppliers and staff — which your own gateway never sees.
Can I buy this without the rest of Defensio?
Yes. Identity Shield is sold on its own. If you already use Defensio SECaaS it appears as one extra entry in the menu you already sign in to, on the same account.
Find out who is sending as your domain
No mail is routed through us and nothing changes in your mail flow.