EU-FIRST DMARC REMEDIATION

Move to p=reject without breaking legitimate email.

Identify every authorised sender, understand why authentication fails, track remediation and verify when enforcement is safe.

EU-hosted · Self-hosted option planned · No charge for spoofed traffic

Report viewers stop too early

A report viewer is only the beginning.

Ordinary platforms can show what arrived in aggregate reports. The hard work starts when an administrator has to decide whether a sender is legitimate, broken, unknown or safe to block.

Viewer output

Useful, but incomplete.

  • Source IP address
  • Message volume
  • SPF result
  • DKIM result
  • Receiver disposition

SenderLedger layer

Answers that change policy.

  • Is this sender legitimate?
  • Who owns it?
  • Why is alignment failing?
  • What must be changed?
  • Did the fix work?
  • Will p=reject block legitimate mail?

Core workflow

From unknown sender to verified fix.

SenderLedger turns aggregate reports into an explainable remediation process that ends with evidence, not guesswork.

01

Discover

Group raw report records into understandable sending services.

02

Understand

Explain SPF, DKIM and alignment failures in direct technical language.

03

Remediate

Turn legitimate failures into owned remediation cases with next actions.

04

Verify

Use later reports to confirm that changes actually worked.

05

Enforce

Calculate readiness for quarantine or reject with evidence and confidence.

Differentiators

Built for remediation, not pie charts.

The product is designed around the work that blocks enforcement: sender ownership, vendor fixes, DNS changes, verification and regression detection.

Sender intelligence

Do not force administrators to manage a list of anonymous IP addresses. SenderLedger groups reports into logical sender entities with vendor or system name, source IPs, authentication domains, first seen, last seen, message volume, internal owner and authorisation status.

Identification may occasionally require confirmation. SenderLedger should communicate confidence and uncertainty rather than pretending every source is known perfectly.

Remediation cases

Each authorised failing sender becomes trackable work. Cases can move through investigating, waiting on vendor, waiting on DNS, ready for verification and resolved.

Automatic verification

A case is not healthy merely because someone clicked done. SenderLedger waits for later aggregate reports and confirms that aligned traffic appears consistently.

New sender and regression detection

SenderLedger continuously detects new sending sources, new IPs for known senders, authentication changes, resolved failures returning and unplanned changes introduced by other departments.

Flagship assessment

Know exactly what prevents p=reject.

The safe-to-reject assessment is evidence-based. It lists the authorised senders that would fail, the legitimate volume at risk and the next action required.

Not ready for p=reject

Three authorised senders still fail DMARC. They represent approximately 8,420 legitimate messages over the last 30 days.

Evidence-based assessment
Blocker Next action Owner
HubSpot DKIM alignment Add vendor CNAME and verify selector Marketing
Salesforce bounce domain Update envelope sender configuration Revenue ops
Finance mail relay Confirm ownership and DKIM support Finance IT

For MSPs and MSSPs

Make DMARC a manageable service, not a monthly report.

Manage customer remediation work without manually inspecting every domain every month. Prioritise risk, assign technicians and report progress without losing tenant separation.

Portfolio-wide enforcement readiness
Proper customer isolation
Technician assignments
White-labelled customer reporting
Bulk onboarding
Predictable per-domain expansion
API and export capability
EU-hosted and self-hosted deployment choices

EU sovereignty and deployment

Deployment choices for privacy-conscious teams.

SenderLedger treats sovereignty as operational clarity: where data is processed, how long it is retained, how it can be exported and how it can be deleted.

Planned private access

EU-hosted

Reports and application data processed in European infrastructure, with clear subprocessors and configurable retention.

Planned

Self-hosted

Operate the full system yourself when policy or procurement requires complete control.

Planned

Hybrid collector

Run the report collector yourself while the hosted control plane receives only required normalised findings.

No use of customer reports for general AI training.

Complete export and straightforward deletion are product principles.

No difficult cancellation process or forced sales call to leave.

Fair pricing principles

Pay for legitimate active sending domains.

Do not pay more because someone is spoofing your domain. Inactive defensive domains do not consume the plan, and there are no automatic surprise overage bills.

Product guidance is included in paid plans. Human implementation work is priced separately. Cancellation is self-service, and complete data export is a product principle.

Team

Best for internal IT teams

For internal IT teams managing several domains.

€49 / month

Monthly billing, excluding VAT

  • 15 active sending domains
  • One million legitimate messages per month
  • One-year history
  • Five users
  • Everything in Starter
  • Work assignment
  • Audit timeline
  • Policy simulation
  • API access (planned)
  • Priority email support

MSP

Predictable domain expansion

For providers managing customers separately.

€149 / month

Monthly billing, excluding VAT

  • 50 customer domains
  • Multi-tenant customer isolation
  • Portfolio readiness view
  • Technician assignment
  • White-labelled reports
  • Bulk onboarding
  • Partner onboarding
  • API and configuration export
  • Additional domains at €2/month or €20/year

Questions technical teams ask before enforcement.

Short answers for teams evaluating DMARC remediation, deployment, pricing and portability.

A sending domain is a domain that legitimately sends mail or appears in DMARC reporting for mail you own. SenderLedger prices around legitimate active sending domains, not abusive spoofing volume.

Subdomains count when they are actively managed as separate sending identities. Defensive or inactive domains do not consume active-domain allowances.

No. Spoofed, fraudulent and clearly forwarded traffic does not consume the legitimate message allowance.

SenderLedger helps you understand and remediate outbound email authentication. It does not promise inbox placement and does not replace deliverability work.

Not by default. SenderLedger explains what must change and tracks the work. Controlled DNS integrations are planned for customers who explicitly enable them.

Self-hosted and hybrid deployment options are planned. Request early access if this is a requirement for your organisation.

Yes. The MSP plan is designed around customer isolation, portfolio readiness, technician assignments, white-labelled reports and bulk onboarding.

There are no automatic surprise overage bills. A 20% temporary grace allowance applies, and customers are contacted after sustained legitimate usage beyond the plan.

SenderLedger is being built around current DMARC semantics and will document RFC-specific behavior before general availability. Ask about RFC support during early access if this affects your deployment.

Complete export is a product principle. Configuration export is included in Business and MSP plans, with broader portability work planned for early access.

Monitoring shows report results. Remediation turns legitimate failures into owned work, keeps them open, and verifies later reports before enforcement.

p=reject tells receivers to reject unauthenticated mail that fails DMARC. It is the strongest published DMARC policy, but should only be used when legitimate senders are aligned.

Next enforcement decision

Find out what is stopping your domain from reaching enforcement.

Request access and tell us whether you are trying to identify senders, fix authentication failures, manage customers or prepare for p=reject.