About
A signet ring sealed a letter so the person receiving it knew who sent it.
That is the whole problem, and it is four thousand years old. Email inherited it without a solution. SPF, DKIM and DMARC are the retrofit. They work, but only if they are configured correctly, watched continuously, and kept that way.
Those three things are usually sold as three products: an authentication tool, a fraud defence platform, and a DMARC report reader. Buying all three and wiring them together is how most companies end up with none of them working. Signet is the one system: it authenticates every service you have authorised to send for you, detects anyone who is not you, and hosts the records so it stays true.
Built and operated by eSec Forte Technologies, and released to the community.
Why it is free
A tool for the community, from a security firm that kept seeing the same problem.
eSec Forte Technologies spends most of its time inside other organisations on security engagements. Across those engagements one finding repeated itself, regardless of size or sector: almost every organisation struggles to keep its email deliverability and authentication infrastructure in order, and almost none of the reasons are technical.
The records themselves are not hard. What is hard is that the tooling around them is unnecessarily complex and unnecessarily expensive, so the work ends up owned by nobody, done once, and left to drift. Signet is our answer to that: one system, plainly worded, that reads what your domain declares, watches what actually happens, and keeps the records true.
We are releasing it free for the community to use and to manage their own data. Deliverability and authentication will always be free on this platform.
What we commit to
Three things this product will not do.
Every one of these is a decision that made the product harder to build and easier to trust. They are the reason to use it over something cheaper.
We will not flatten your SPF record.
Flattening replaces the services you authorised with the IP addresses behind them on the day it ran. When a provider changes IPs, as they do, mail you meant to send starts failing, silently, and the record no longer says what you meant. We count your lookups honestly against the limit of 10 and tell you which include to remove.
We will not alert you about forwarding.
Most DMARC failures are messages forwarded by a mailing list or a redirect. They are not attacks and there is nothing to fix. Alerting on them is how monitoring tools get muted inside a fortnight, and a muted tool protects nobody. Forwarding is identified, classified, and left alone.
We will not call your own platform an attacker.
Before anything is reported as unauthorised it has to fail on network evidence and on signature evidence together. An early build called a Marketo-signed source spoofing purely because its IP was unfamiliar. A false accusation costs you more than a missed one, so the classifier now needs two independent reasons before it will say it.
Deliberately absent
What we chose not to hold.
No passwords stored
Sign-in is a magic link. There is no password database to leak.
Forensic samples redacted on write
Recipient data is stripped before it reaches disk, not before it reaches a screen.
No mailbox access
There is no integration that reads your mail and there never will be. Aggregate reports carry counts and IP addresses, and that is all we hold about your traffic.