How SealedMail works

You don't need to understand DMARC to use SealedMail. You need to update two DNS records - or forward two lines of text to whoever manages your domain. SealedMail does the rest.

The six steps

1
Request your free health check

Before anything else, find out where you stand. The free health check audits your domain’s entire email authentication setup and sends you a scored certificate in plain English. No sign-up, no obligation.

2
Subscribe

When you’re ready, subscribe at £39 per domain, per month through Stripe. Within service hours, you’ll receive a welcome email containing the two SealedMail reporting addresses for your domain.

3
Update two DNS records

Add SealedMail’s addresses to your domain’s DMARC record (the RUA address) and TLS-RPT record. If you’ve never touched DNS, the Getting Started guide walks through it - or simply forward the welcome email to your IT provider. It’s five minutes’ work for anyone who manages DNS.

4
SealedMail starts receiving reports

Once the records are live, email receivers around the world - Google, Microsoft, Yahoo and thousands of others - begin sending their reports about your domain to SealedMail.

5
Your first weekly report arrives

The following Monday, your first SealedMail report lands in your inbox. It tells you, in plain English: who has been sending email as your domain, whether that email passed authentication, and whether anything needs your attention.

6
Ongoing: every Monday, without fail

Each weekly report also includes a refreshed health check, confirming your DNS records still point to SealedMail and your email authentication posture remains healthy. If something changes, you’ll read about it in plain English - not discover it months later.

What each part of the service does

DMARC monitoring

Your domain’s CCTV

Every major email receiver keeps a record of mail claiming to come from your domain - including mail you never sent. Without monitoring, those reports either go nowhere or pile up as unreadable XML. SealedMail receives them, interprets them, and tells you what they mean - not as a chart, but as a plain-English explanation of what happened and whether you need to act.

TLS reporting

Checking the locks on delivery

TLS-RPT reports tell you when other mail servers failed to deliver email to you securely. Most businesses have no idea these failures happen. Without TLS reporting you are, at best, protected but blind. SealedMail flags anomalies and explains them in the same weekly report.

Weekly health check

Nothing drifts unnoticed

DNS records get edited, migrations happen, suppliers change things. Every weekly report re-checks your DMARC, SPF, DKIM, MTA-STS, TLS-RPT, BIMI and blacklist status, so configuration drift is caught within days, not discovered during an audit.

“I don’t know anything about this - is that a problem?”

No. It’s who SealedMail is built for. You will never be asked to read raw data, learn a dashboard, or interpret a chart. The only technical task in the entire process is a one-time DNS update, and you can hand that to anyone who manages your domain. From then on, your involvement is reading one short email a week.

See a sample report before you commit

Want to know exactly what lands in your inbox each Monday? Here is a full anonymised example of the weekly report, so you can see the format, the plain-English summary and the level of detail before you sign up.

See a sample weekly report

See where your domain stands today

Request your free health check in 30 seconds. Your expert-reviewed certificate lands within one working day. No sign-up, no sales call.