Skip to content
Signet

Questions

Every question we are asked.

Answered without hedging. Where the answer is unflattering, such as how long reports take or what a scan cannot see, it says so.

Will turning this on affect my email?
No. Monitoring changes nothing about how your mail is delivered. You publish a DMARC record asking receivers to send reports, and they carry on treating your mail exactly as before. Delivery only changes when you decide to move to p=quarantine or p=reject, and that is your decision, taken after the reports show it is safe.
How long before I see anything?
Aggregate reports arrive on the mailbox providers' schedule, not ours, usually within 48 hours, sometimes longer for a low-volume domain. The scan is instant, but the useful picture of who is sending as you builds over the first week.
What if something is sending as us that is not in our SPF record?
The scan will not see it, and no scan of any kind could. A scan reads DNS, so it can only show what you have authorised: your SPF includes and your MX hosts. Something sending as you without that authorisation leaves no trace in your DNS at all. It does leave a trace in DMARC aggregate reports, which is why monitoring is a separate thing from scanning. The scan tells you what you have declared; the reports tell you what is actually happening. You need both, and the first one is free.
Is this a security tool or a deliverability tool?
Both, because they are the same records. SPF, DKIM and DMARC decide whether a receiver can prove a message is yours, which is what stops impersonation, and the mailbox providers now use that same proof to decide whether to accept your mail at all. Signet verifies the whole set, tells you what Gmail, Yahoo and Outlook.com require of it, and is explicit about the parts it cannot see from outside: complaint rate, unsubscribe handling and inbox placement.
Someone connected an AI agent or a new tool that sends as us. Will I know?
Yes, in two ways. If the tool sends mail, it appears in aggregate reports as a source, and Signet classifies it rather than burying it in a list of IPs: your infrastructure, an authorised service, a forwarder, or unknown. If someone also edited your SPF or DMARC record to make the tool work, that change is re-read and raised as an alert with what it authorised and what it cost in lookups. What Signet cannot do is see the OAuth grant or the agent registration itself; that stays in your Google or Microsoft admin console, where it belongs.
Can you read my email?
No. We never touch your mailbox and there is no integration that would let us. DMARC aggregate reports contain counts and IP addresses, not messages. Forensic reports can contain fragments, so those are redacted before they are written to disk rather than before they are shown to you.
Do you flatten SPF records?
Never. Flattening replaces the services you authorised with the IP addresses behind them on the day it ran, and when a provider moves, mail you meant to send starts failing silently. We count your lookups against the limit of 10 and tell you which include to drop instead.
We use custom DKIM selectors. Does that break the scan?
No, and it is not treated as a failure. Signet checks each recognised service against its documented default selectors; if those are absent it says exactly that rather than declaring DKIM missing, because a selector cannot be enumerated from DNS. Add yours under the domain field and they are verified alongside the defaults.
What happens if a report says one of our own tools is spoofing us?
It should not, and preventing that was a deliberate design decision. A source has to fail on network evidence and on signature evidence together before it is reported as unauthorised. Forwarding is identified separately and never alerts, because most DMARC failures are forwarding and alerting on them is how these tools get muted.
What does it cost?
Deliverability and authentication are free on this platform and will stay free. That is the reason Signet exists: eSec Forte kept finding the same unowned, drifting records on engagement after engagement, and the tools meant to fix them were needlessly complex and expensive. Pricing for anything beyond that, such as longer retention or a large number of domains, is not published yet. If you need numbers before that lands, get in touch and we will give you the ones we are working to rather than a placeholder.

What the scan reads

Twelve record types. One identity.

Your sending identity is not one record, it is twelve that have to agree. Most tools check them one at a time. The findings that matter only appear when they are read against each other: an MTA-STS policy naming hosts your MX no longer uses, a DMARC record pointing at a mailbox that cannot receive, an SPF include for a service that stopped signing months ago.

Identity

Who is allowed to send as you

  • SPF

    Every include followed and counted against the limit of 10

  • DKIM

    Default selectors per service, plus any custom selector you name

  • DMARC

    Policy, alignment, percentage, and whether reports can reach you

  • BIMI

    Logo record, its certificate tag, and whether your policy is strict enough

Delivery

Where your mail actually lands

  • MX

    Hosts, priorities and who operates them

  • A / AAAA

    What each mail host resolves to

  • PTR

    Reverse DNS, and whether it forward-confirms to the same address

Transport

Whether the connection is protected

  • MTA-STS

    The DNS record and the policy file, checked against live MX

  • TLS-RPT

    Whether transport failures are being reported to anyone

  • DANE / TLSA

    Certificate pinning, and whether DNSSEC actually protects it

Foundation

Whether the zone itself can be trusted

  • DNSSEC

    Whether the zone is signed and the chain genuinely validates

  • CAA

    Which authorities may issue certificates for you

How selectors are found

Most tools guess at selectors.Signet knows whose they are.

Your SPF record and MX hosts name the services allowed to send for you. Signet takes that list and checks each provider’s documented default selectors, rather than brute-forcing a generic wordlist.

When those defaults are not there, that is not a verdict. Plenty of teams sign with their own custom selectors, which is entirely normal and entirely correct. So Signet says exactly what it found, names the service, and asks you for the selector it should be checking instead.

Finding · needs input

Mailchimp is authorised to send as you. Its default selectors are not published.

Authorised
include:servers.mcsv.net
Defaults
k1._domainkey · k2._domainkey
Found
neither

If you sign this service’s mail with a custom selector, add it and Signet will verify that instead. If you do not, mail sent through it cannot pass DKIM.

Agents send mail now

Your sender list used to change when IT signed a contract. Now it changes when someone connects an agent.

AI assistants can send from a mailbox with one approval, and increasingly with none. Agent platforms issue agents their own identities and their own inboxes. Outreach tools send thousands of messages with no person on each one. Every one of these is a new thing sending as your domain, and none of them files a ticket.

Every new source is surfaced, not just spoofing

Aggregate reports name every IP that sent as you. Signet classifies each one as your infrastructure, an authorised service, a forwarder, or unknown, and raises the unknown ones before they become a policy failure or a reputation problem.

Source classification on every report, with two signals before it is called spoofing

Record changes are alerts, not surprises

An agent, a contractor or a well-meaning colleague adds an include or a selector to get a tool working. Signet re-reads your records and tells you what changed, when, and what it did to your lookup budget and your policy.

SPF and DMARC change alerts, weakened-policy alerts, score-drop alerts

Approval belongs to a person

Signet does not publish a change on your behalf. It shows you the exact record, what it will authorise, and what it costs. Agent identities from Microsoft Entra or Google Workspace stay yours to govern; Signet shows you the mail they produce.

Hosted records are published by you, with a testing period before enforcement

The question none of these answers is what your own domain says.