Email and Domain Security
Security decisions, made with clarity.
Business Email Compromise starts with a message that appears to come from your address. If your domain does not publicly declare which servers may send on its behalf, a receiving mail server has no basis to reject that message.
Enlistic Solutions monitors that configuration continuously, reports on it every month in plain language, and makes the DNS changes on your behalf. From R900 per domain per month.

Business Email Compromise begins with an email in your name
In a BEC attack, a client or supplier receives an invoice that appears to come from your address, and pays it into the wrong account. Unless a domain publicly declares which servers may send mail on its behalf, receiving mail servers have no basis to reject that message. This requires no sophistication. It succeeds because the domain was never configured to prevent it.
lost to BEC worldwide in 2025
FBI IC3 Internet Crime Report 2025
average loss per reported BEC incident
FBI IC3 Internet Crime Report 2025
lost to digital banking fraud in South Africa in 2024, up 74% in a year
SABRIC Annual Crime Statistics 2024
What we watch, continuously
Five controls, checked on an ongoing basis rather than once a year. Every finding arrives with the evidence behind it.
Sender authentication
Every message claiming to come from you is checked. Servers that are not yours get flagged, then rejected.
Encrypted delivery
We report on whether mail servers could encrypt when delivering to you, and make encryption mandatory.
Breach exposure
A weekly scan of breach data for your staff addresses, showing which breach and whether a usable password is exposed.
Lookalike domains
A weekly scan for registered copies of your name, and which of them are set up to receive mail.
Monthly report and actions
A branded PDF with the findings, the evidence and what to do, ordered by urgency. We make the changes for you.
What lands in your inbox every month
- Your policy status, and the share of mail it applies to
- Mail volume, and the share that authenticated correctly
- Which countries mail claiming to be from you was sent from
- Every sending server, with a pass or fail against your domain
- Encrypted-delivery health for mail arriving to you
- Staff addresses found in known breaches, with passwords masked
- Registered lookalike domains, and which of them accept mail
- Recommended actions, written so anyone can act on them
Nothing to install, and no change to how you send email. Setup is three DNS records. We publish them with you or your IT provider, confirm every service that legitimately sends as you, and only then switch enforcement on.
How setup works
Three steps, run at a pace that keeps your legitimate mail flowing throughout.
Publish the records
Three DNS records, published with you or your IT provider. Nothing changes in how you or your staff send mail.
Confirm your senders
We watch a full reporting cycle and confirm every service that legitimately sends as you, so nothing of yours is caught.
Switch enforcement on
Only once your senders are confirmed do we move the policy to reject. From then on, mail that is not yours is turned away.
Pricing
Per domain, per month. A once-off setup of R4 500 covers the records, the sender discovery and the move to enforcement.
Protect
R900 /month
Per domain, per month. R4 500 once-off setup.
Full monitoring and the monthly report, with us doing the work.
- Sender authentication monitored and taken to full enforcement
- Encrypted-delivery (TLS) reporting
- Weekly breach-exposure and lookalike-domain scans
- Branded monthly PDF with recommended actions
- DNS changes made on your behalf
- Quarterly review call
Complete
R1 200 /month
Per domain, per month. R4 500 once-off setup.
Everything in Protect, plus the items below. For firms that move money on email, or answer to an insurer or auditor.
- MTA-STS policy hosted and enforced for you
- Priority incident response
- Assistance with lookalike-domain takedowns
- Credential exposure review and reset coordination
- A named contact, same-day response
Evidence your auditor and insurer can use
Email and domain security forms part of a broader information-protection programme. A documented authentication policy, plus monthly evidence that it is enforced, supports programmes aligned with:
- POPIA
- GDPR
- NIST Cybersecurity Framework
- CIS Controls
- Industry and contractual security requirements
- Cyber insurance questionnaires
The monthly report is written to be handed over as it is, without translation. Enlistic Solutions is an independent assessment practice, not a reseller, so the findings carry no product agenda.
Find out what your domain publishes today
Send us your domain name and we will tell you what is published right now, what it allows, and what it would take to reach enforcement. There is no obligation, and nothing changes in your mail flow.

