Keep your domain yours
and your inbox honest
Publish the records that prove your mail is yours. Every message that arrives comes scored, with the sender checks and the reasons on it.
Copy each record into your DNS. The domain verifies once all of them are found.
Where it starts
What this looks like today.
Nothing stops mail sent as you
Your domain publishes no policy, so a forgery and a real invoice arrive looking the same.
A look-alike got through
One letter was different in the sending domain, and the person who read it had no way to tell.
Senders learn when you opened it
An invisible image loads as the message is drawn and reports the moment back to whoever sent it.
How it works
Running in four steps.
- 01
Add your domain
Add it in Settings, Domains, and ownership, signing and routing records are generated with a starter policy.
- 02
Publish the records
Paste them at your DNS host, or sync them in one press where that host is supported.
- 03
Read the verdict, then block
Four tiles score every message, so open one for the reasons and block one address or a whole domain.
- 04
Set the roles and two-factor
An invitation carries the role and the addresses, and anyone without two-factor meets a lockout.
What it runs on
The parts doing the work.
The parts this runs on: what your domain publishes, what happens to a message on arrival, and what a reader gives away by opening one.
A starter p=none record, printed to copy or written by a sync, never tightened for you.
v=DMARC1; p=none; rua=…
A mark beside the sender when the sending domain’s published records line up.
Mail the sending domain itself disowns lands in Spam rather than the inbox.
One address, or everything from a domain, stopped before it reaches you.
Mail carrying the words you do not want to read does not open in front of you.
Mail moves over TLS on the hops we run, and transport alone never turns the padlock green, because nothing on this backend can read the transport off a delivery.
Wire transfer approved, details attached.
Every field of a message sealed before it is written down (body, subject, addresses and attachment bytes), so a copy of the database is ciphertext rather than mail.
Wire transfer approved, details attached.
In practice
Every piece, walked through.
Four shorter pages, each a single job inside it: the domain records, the verdict on a message, who may read what, and reading without being counted.
Publish the records that prove your mail is yours, and check what your domain says in public.
Every message arrives scored, with the sender checks, the reasons and the look-alike domain named on it.
Questions
Asked before signing up.
Will this stop someone sending as our domain?
Only partly. OpenEmail generates the ownership, signing and routing records and a starter DMARC record at p=none, which asks for nothing to be rejected. Tightening it is your decision at your DNS host.
What does the verdict on a message check?
Sender authentication, links, attachments, wording and look-alike domains. The result is four tiles on the message: sender, safety, privacy and writing. Open one to read the reasons behind it.
Is our mail encrypted where it is stored?
Not yet. Mail moves over TLS on the hops OpenEmail runs, and the credentials you hand over are sealed, but message bodies, subjects and attachments are stored as they arrived.
Nearby
Other jobs for the same mailbox.
Addresses for people and for roles, all on one domain. Each has its own people, keeps the shared sign-off, and stays put when somebody leaves.