Cybersecurity › Email Security
Business email security.
SPF, DKIM, DMARC, BIMI and MTA-STS.
Over 90% of cyber attacks begin with an email. Phishing, spoofing and Business Email Compromise (BEC) exploit domains that lack proper authentication. SPF, DKIM, DMARC, BIMI, MTA-STS and TLS-RPT form a layered defence that verifies every message, blocks forgeries and gives you full visibility into who sends email on your behalf.
Why email authentication is essential
Email was designed without built-in authentication: anyone can send a message claiming to come from your domain. Email authentication protocols (SPF, DKIM, DMARC) fix this by letting receiving servers verify the legitimacy of every message. Without them, your domain is exposed to phishing, spoofing and reputation damage.
More than 90% of successful cyber attacks start with a phishing email. Business Email Compromise (BEC) alone caused over $2.9 billion in losses in 2023 according to the FBI IC3 report. Email authentication is the first line of defence.
Only a DMARC policy set to reject actually blocks spoofed emails. Many organisations stop at p=none (monitoring only), leaving their domain unprotected. We guide you to full enforcement with zero disruption to legitimate mail flows.
Email authentication is a requirement for NIS2, ISO/IEC 27001, 27017, 27018 and ISO 9001. Google and Yahoo now require SPF, DKIM and DMARC for bulk senders. Non-compliance means delivery failures and security gaps.
How we secure your email domain
We don’t just publish DNS records: we design, implement and monitor a complete email authentication architecture tailored to your domain, your sending sources and your compliance requirements.
We analyse your current SPF, DKIM and DMARC configuration, identify all legitimate sending sources (mail servers, marketing platforms, CRM, ticketing systems) and map the gaps.
We configure SPF with correct include mechanisms, DKIM signing for every sending source, DMARC with aggregate and forensic reporting, MTA-STS for transport encryption and TLS-RPT for delivery monitoring.
We progressively tighten DMARC policy from none to quarantine to reject, monitoring reports at every stage to protect legitimate email flows. Once at reject, we add BIMI for brand visibility in inboxes. Our managed DMARC monitoring reads the reports every hour and keeps the domain at reject.
The six pillars of email security
SPF (Sender Policy Framework)
DKIM (DomainKeys Identified Mail)
DMARC (Domain-based Message Authentication)
BIMI (Brand Indicators for Message Identification)
MTA-STS (Mail Transfer Agent Strict Transport Security)
TLS-RPT (TLS Reporting)
Why buying a solution is not enough
Misconfigured records are worse than none
Email ecosystems change constantly
Compliance requires evidence, not just records
Beyond authentication: Email Security Gateway
Libraesva EmailSecurity
Independent email gateway with 14 levels of analysis, Avira and Bitdefender engines, proprietary URLSand and QuickSand technologies. 99.99% catch rate (Virus Bulletin since 2010). BEC (Business Email Compromise) protection and behavioural attachment analysis. AtWorkStudio is a Certified Partner of Libraesva. The service is qualified by the Italian National Cybersecurity Agency (ACN).
Microsoft Defender for Office 365
Two layers, one strategy
MIMIT Cloud and Cybersecurity Voucher 2026
This service is eligible for the voucher: a 50% non-repayable grant.
AtWorkStudio is an approved supplier. The grant covers 50% of the expenditure, up to €20,000, as a direct purchase or a subscription of at least 24 months. The application must be submitted before buying: drafting opens on 20 October 2026, submissions from 10 November 2026 to 20 January 2027, first come first served.
Codes to enter in the application
VCCFA2600000145-B9
Protect your domain from phishing and email spoofing
Contact us for an email security audit: we analyse your current SPF, DKIM and DMARC configuration and build a roadmap to full enforcement. You can also check your domain right now with our DNS management tools.