Email Authentication

Email Authentication: proving the mail is really from you, and keeping it that way

Most domains have authentication that is half finished: an SPF record that grew past its lookup limit, DKIM missing on one sender, DMARC published but set to do nothing. Receivers notice, even when you do not.

With Cascadia you get

Enforcement when it is safe
Set up properly, once
Reports read for you
Email specialists, not a helpdesk
Nothing published without checking what it breaks
Your domain stays yours

Why teams start here

Enforcement when it is safe

DMARC only helps once it is enforced, and enforcing it too early bounces your own invoices. We move it to quarantine, and then to reject, only when the reports show your real mail passing.

Set up properly, once

We find every service that sends as you, put one clean SPF record in place, sign each sender with DKIM, and publish DMARC. Then we read the reports each week so an unauthorized sender is something you hear about from us.

Reports read for you

DMARC reports arrive as XML nobody opens. We gather and parse them, keep 90 days of history day by day, and each week tell you in plain words what passed, what failed, and which services are sending as you.

What you get

Everything Email Authentication covers

All of these come with Email Authentication, set up and looked after by our team.

SPF

  • Every sender that mails as you, found first
  • One SPF record, inside its lookup limit
  • Third-party senders included, not forgotten
  • Flattened when it grows too long
  • Checked daily for changes

DKIM

  • DKIM signing set up for each sender
  • Keys published in your DNS by us
  • Selectors checked daily for resolution
  • Rotation handled when a provider requires it
  • Told the day a signature stops validating

DMARC

  • DMARC published, starting at monitoring
  • Reports gathered and parsed automatically
  • Moved to quarantine, then reject, when clean
  • Alignment problems explained in plain words
  • Nothing enforced before your real mail passes

Watching

  • Unauthorized senders using your domain, surfaced
  • A weekly read of what the reports say
  • 90 days of history, day by day
  • Every published record checked daily for changes
  • A ticket naming what changed and what it was

What sets it apart

  • Enforcement when it is safe
  • Set up properly, once
  • Reports read for you
  • Email specialists, not a helpdesk
  • Nothing published without checking what it breaks
  • Your domain stays yours

Want your email proven to be yours?

Tell us what you sell and we will start with the questions your buyers ask.

Get startedSee the comparisons

What a plugin sets up, and what it leaves out

A plugin will publish a record. The useful part is further in: finding every sender first, keeping SPF inside its limit, and knowing when it is safe to enforce.

A plugin that publishes recordsEmail Authentication
SPFAppended to until it breaksOne record, kept inside its lookup limit
DKIMOne sender signed, the rest forgottenEvery sender found before anything is published
DMARCPublished at none, foreverRecords checked daily, not once
ReportsXML nobody readsReports parsed weekly, automatically
ChangesNoticed eventuallyA ticket the day a record or signature changes
UpkeepSet once, never revisitedReviewed as your senders change

What clients say about working with Cascadia

“I’ve always dreaded website management, but Cascadia has done an incredible job with my WordPress site, making it one less thing for me to worry about.”
Alex R.
Cascadia client
“I’ve worked with Cascadia for several years now. They are always ready to help in any way I ask and can implement my ideas with ease. A company that values their clients!”
Liz D.
Cascadia client
“Cascadia has been great to work with! We recently needed some updates, and Cascadia was quick to get them completed! We highly recommend Cascadia Web Services.”
Naomi T.
Cascadia client
“Cascadia is very responsive and we’re happy with them as our primary IT vendor.”
Royle J.
Cascadia client
“They do great work, been using for years. Prompt responses to requests.”
Brian M.
Cascadia client

Want your email proven to be yours?

Talk to us

Who Email Authentication fits best

Teams with more senders than anyone can list

An SPF record that grew past its lookup limit, DKIM missing on one sender, mail going out from a tool nobody remembers adding. We find every service that sends as you, put one clean record in place, and sign each sender.

Domains with authentication half set up

Receivers decide in milliseconds whether to trust your mail, and they decide on what your domain publishes. Half-finished authentication is treated as no authentication.

Agencies reporting this for their clients

You can sell the outcome without hiring for it. We run the technical and content work under your brand, deliver reporting you can pass straight to a client, and stay out of the relationship.

Ready to stop reading DMARC reports?

We read your DMARC reports so you do not have to, and tell you what needs attention.

How it works

1. We find everything that sends as you

We start by reading what your domain publishes today and what actually sends as you. Most businesses are surprised by at least one entry in that list.

2. We publish the records properly

Records are published in the right order: SPF flattened and inside its lookup limit, DKIM signing for every sender, then DMARC at monitoring. Nothing is enforced until the reports show your real mail passing.

3. You get the picture every month

After that it runs itself. The reports are parsed each week, the records are checked daily, and you hear from us when something changes or when it is safe to move to enforcement.
Ask us

Answers to common Email Authentication questions

Weighing us against another option? Our comparisons take the main ones in turn.
What does Email Authentication cover?
SPF, DKIM and DMARC for every service that sends as you, published in your DNS by us and checked every day.
Gmail and Outlook decide whether to trust your mail on what your domain publishes. Half-finished records are treated as none at all.
Yes. Authentication is what stops someone else sending invoices in your name, and it is the single biggest factor in whether Gmail and Outlook trust you at all.
We need your DNS, which is usually an invitation to your Cloudflare account. Nothing is installed on your website and no access to your mailboxes is needed.
DMARC tells receivers what to do with mail that fails. Started at monitoring it does nothing but gather reports, which is exactly what you want until your real mail passes.
Only when the reports show your real mail passing. Enforcing DMARC too early bounces your own invoices, so it goes to quarantine first and then to reject.
We do, weekly. They arrive as XML that nobody reads, which is why most businesses publish DMARC and learn nothing from it.
Yes. Unauthorized senders show up in the reports, and you hear about it from us rather than from a customer.
Access to your DNS, and ten minutes to tell us which services send email as you.
No. Nothing is published without checking what it breaks. The records go in order: SPF flattened and inside its lookup limit, then DKIM signing for every sender, then DMARC at monitoring.
This proves the mail is yours. Deliverability Monitoring watches whether it is arriving. They solve different halves of the same problem.
Yes. Workspace signs its own mail, and it knows nothing about your invoicing system, your CRM or your website forms.
Ninety days, day by day, so you can see what a record said on any date in that window.
Yes. It is monthly, and the records stay published in your DNS.
Ask Us Anything
We’d love to hear from you!
Contact Form