Domain and email security audit
Denetta Domain and Email Security is the module that audits a company’s domains from the outside, using public information only: it evaluates SPF, DKIM, DMARC, MTA-STS and TLS-RPT records, MX servers’ STARTTLS support and certificates, web certificates, DNSSEC and CAA, and the domain registration expiry with 25 rules. The company’s devices are never contacted.
Which areas are audited?
Coverage is measured with a 52-item checklist based on email and DNS standards: SPF (RFC 7208), DMARC (RFC 7489), DKIM (RFC 6376), MTA-STS (RFC 8461) and TLS-RPT (RFC 8460).
| Area | Items |
|---|---|
| SPF | 6 |
| DMARC | 7 |
| DKIM | 5 |
| Mail transport security (STARTTLS, MTA-STS, TLS-RPT) | 8 |
| Web endpoints (certificate, TLS, HSTS) | 9 |
| Domain registration | 4 |
| DNS infrastructure (DNSSEC, CAA, name servers) | 6 |
| Reputation | 1 |
| Mail tenant configuration | 4 |
| Product features | 2 |
What does the audit do to a domain, and what not?
Only DNS queries, TLS handshakes, a HEAD request to the web server and EHLO → STARTTLS → QUIT to the MX server. No port scans, no email is sent, no open-relay tests. Connections are made to public IP addresses only.
DNS queries go to open resolvers that carry DNSSEC correctly; if a query stays ambiguous the result is “unknown”, never “unsigned”. Auditing a domain starts once that domain is included in the company’s signed consent document.
How are expiring certificates and domains tracked?
Checks run daily. For MX and web certificates and the domain registration, an alert is raised at 30, 14 and 7 days before expiry and on expiry; emails go out at 14 and 7 days and on expiry. Notifications carry only the name, type and days remaining.
How is it licensed?
Because a domain does not belong to a site, this module is licensed per company, not per site; a number of domains is included and additional domains are charged per domain. The current list price is on the pricing page.