How SealedMail works
You don't need to understand DMARC to use SealedMail. You need to update two DNS records - or forward two lines of text to whoever manages your domain. SealedMail does the rest.
The six steps
Before anything else, find out where you stand. The free health check audits your domain’s entire email authentication setup and sends you a scored certificate in plain English. No sign-up, no obligation.
When you’re ready, subscribe at £39 per domain, per month through Stripe. Within service hours, you’ll receive a welcome email containing the two SealedMail reporting addresses for your domain.
Add SealedMail’s addresses to your domain’s DMARC record (the RUA address) and TLS-RPT record. If you’ve never touched DNS, the Getting Started guide walks through it - or simply forward the welcome email to your IT provider. It’s five minutes’ work for anyone who manages DNS.
Once the records are live, email receivers around the world - Google, Microsoft, Yahoo and thousands of others - begin sending their reports about your domain to SealedMail.
The following Monday, your first SealedMail report lands in your inbox. It tells you, in plain English: who has been sending email as your domain, whether that email passed authentication, and whether anything needs your attention.
Each weekly report also includes a refreshed health check, confirming your DNS records still point to SealedMail and your email authentication posture remains healthy. If something changes, you’ll read about it in plain English - not discover it months later.
What each part of the service does
DMARC monitoring
Your domain’s CCTVEvery major email receiver keeps a record of mail claiming to come from your domain - including mail you never sent. Without monitoring, those reports either go nowhere or pile up as unreadable XML. SealedMail receives them, interprets them, and tells you what they mean - not as a chart, but as a plain-English explanation of what happened and whether you need to act.
TLS reporting
Checking the locks on deliveryTLS-RPT reports tell you when other mail servers failed to deliver email to you securely. Most businesses have no idea these failures happen. Without TLS reporting you are, at best, protected but blind. SealedMail flags anomalies and explains them in the same weekly report.
Weekly health check
Nothing drifts unnoticedDNS records get edited, migrations happen, suppliers change things. Every weekly report re-checks your DMARC, SPF, DKIM, MTA-STS, TLS-RPT, BIMI and blacklist status, so configuration drift is caught within days, not discovered during an audit.
“I don’t know anything about this - is that a problem?”
No. It’s who SealedMail is built for. You will never be asked to read raw data, learn a dashboard, or interpret a chart. The only technical task in the entire process is a one-time DNS update, and you can hand that to anyone who manages your domain. From then on, your involvement is reading one short email a week.
Want to know exactly what lands in your inbox each Monday? Here is a full anonymised example of the weekly report, so you can see the format, the plain-English summary and the level of detail before you sign up.
See a sample weekly reportSee where your domain stands today
Request your free health check in 30 seconds. Your expert-reviewed certificate lands within one working day. No sign-up, no sales call.