21 June 2026 · 2 min read
Every email provider, without exception. This is the part that surprises people, so it is worth explaining why. DMARC, SPF, DKIM, MTA-STS and BIMI are not features of your mailbox or your sending platform: they are records that live in your domain's DNS. When a receiving server (Gmail, Outlook, Yahoo and the rest) decides whether to trust a message from your domain, it looks up those records in DNS and checks the message against them. We manage that DNS-side policy. Your provider keeps doing exactly what it does today, which is sending and receiving your actual email. The two layers sit side by side and never compete, so there is nothing on your provider's end to switch, migrate or break.
In practice that means the big mailbox hosts and every sending platform we have seen are covered. That includes Google Workspace and Microsoft 365 for your day-to-day staff mail, and the long list of services that send on your behalf: SendGrid, Mailchimp, Amazon SES, Postmark, Brevo (formerly Sendinblue), Klaviyo, HubSpot, Salesforce, Zendesk, Intercom, Zoho, Mailgun, ActiveCampaign, your CRM, your billing system, your help desk and your marketing automation. Most domains send through five to fifteen of these without anyone realising it. Our job during onboarding is to find all of them by reading your real DMARC reports, then make sure each one is correctly authorised in SPF and signing with DKIM, so that nothing legitimate gets caught when we tighten your policy.
You keep your current provider, full stop. We do not ask you to move mailboxes, change your MX records, route mail through us, or hand over your sending platform. Concretely, here is what stays with you and what we handle:
- Your mailboxes and MX: untouched. Google Workspace or Microsoft 365 stays exactly where it is, and inbound mail keeps flowing through your existing MX records.
- Your sending platforms: untouched. Your ESPs and apps carry on sending; we just make sure each one is authenticated so it passes DMARC.
- The DNS authentication layer: this is the part we look after, either by hosting delegated records for you or by handing you the exact records to publish, then monitoring them.
The only thing we genuinely need is the ability to manage the relevant DNS records for your domain, because that is where authentication is enforced. If a new tool joins your stack later, for example you adopt a new newsletter platform or a fresh invoicing service, it shows up in your monitoring and we authorise it before it can cause a failure. You can confirm any of this yourself right now without signing up: run your domain through the free DMARC checker, SPF checker and DKIM checker to see the current DNS-side picture, and read the requirements for what Google and Microsoft now expect from senders. If you would like the full walkthrough of how we take a domain from p=none to p=reject safely, see our managed DMARC product.