Mail monitoring · Email
Today, someone could send an invoice in your company's name.
And you would only hear about it from the customer who paid it. Mailbewaking shows who is sending email on behalf of your domain, keeps your own mail arriving, and warns you the moment that changes.
Why you want this
For most businesses email is the most important channel to the outside world — and the only one nobody can tell you is still configured correctly.
Invoice fraud carries your name
Without the right settings anyone can send email that appears to come from your company. A fraudster sends your customer an invoice that looks exactly like the ones they are used to, with one difference: the account number. Your customer pays in good faith.
- The money is gone, and the argument about who carries that starts with you
- Your customer trusts your mail less afterwards — and that lingers
- You did not see it happen; nothing reports it to you
Your most important mail quietly fails to arrive
Quotes, invoices and reminders end up in the spam folder or get refused. No error comes back: on the other end it is simply silent, and you assume your message was read.
- Invoices paid late because they were never read
- Customers who think you are not responding
- Enquiries you miss without ever knowing they existed
People are starting to ask about it
Supplier questionnaires, insurers and tenders now want to know whether your email is set up correctly. And the large mail providers keep tightening up on this: mail from a domain that has not sorted this out lands in the spam folder more often, or is refused without notice.
- A question in a tender you cannot answer today
- Mail to large providers being delayed or refused
- An insurer attaching stricter conditions
One price for all your domains
Much of this market charges per domain per month. If you have more than one — your company name, a trading name, an old name you still hold on to, or your customers' domains — that adds up quickly. With us it is a single amount: €9,00 per month for up to 10 domains. Your first one is free.
What we do not do
Watching email sounds like somebody reading along. That is not what happens here, and it is a design choice rather than a promise.
We do not read your email
We ask for no access to your mailbox and we see no messages. What we receive are the daily summaries that receiving mail servers send back of their own accord: counts, domains and IP addresses. No subjects, no content, no attachments.
No forensic reports
There is a second kind of report that does contain fragments of real messages from real people. We neither request nor process those. That saves you a processing of personal data you would rather not have.
A Dutch company on European servers
We are not an American provider with a European tickbox. Emerald Elephant Solutions is a Dutch company, Dutch law applies, and the data processing agreement is yours to download from your own environment. The service runs on European servers, and backups are encrypted here before they go to storage in Amsterdam — the key does not travel with them.
Your data stays yours
Export whenever you like, cancel monthly, and delete it yourself — after which it really is gone. No conversation with an account manager to get out.
So what is it?
Your domain name carries three settings that together say who may send email on your behalf: SPF, DKIM and DMARC. Get them right and your customer's mail server can tell your mail apart from a forgery — and throws the forgery away.
Get them wrong and one of two things happens. Your own mail is distrusted. Or somebody else's is not.
The awkward part is that you notice neither. No warning light comes on. The receiving mail servers do know, and they send a report about it every day — but that report is not readable by a human. It is a technical file full of numbers, which is why almost nobody looks at it.
Mailbewaking collects those reports and turns them into plain language.
What it does for you
- Shows who is sending email on behalf of your domain — including the parties you had forgotten, such as your newsletter tool or your accounting package.
- Checks daily that your settings are still correct, including after somebody changed something in your DNS.
- Flags it when mail is sent in your name that does not pass the checks.
- Explains in plain language what is wrong, what it means for your customers, and what the next step is.
- Tells you when it is back in order too, so you are not left wondering.
Getting started
-
1
Add your domain
You type in your domain name. That is the whole first step.
-
2
Two lines in your DNS
We hand you two ready-made lines: one that proves the domain is yours, and one that sends the reports our way. Not managing your own DNS? Forward them to your hosting provider or web developer — for them this is five minutes of work.
-
3
Done
The first reports arrive within a day and your overview fills itself. After that there is nothing left to do: you hear from us when something needs attention.
Nothing to install, and nothing to change about your website or your mail server.
For those who want the details
This last block is for your system administrator or web developer.
- SPF: syntax, the include chain and the ten-DNS-lookup limit. Exceeding it yields a permerror, which in practice works out the same as having no SPF at all.
- DKIM: presence and usability of the selectors you provide. Selectors we encounter in incoming reports are added automatically.
- DMARC: the policy as receivers apply it, not just what p= says. With t=y (test mode) they treat reject as quarantine and quarantine as none — we account for that. We also read sp and np, the rules for existing and non-existent subdomains, and report it when those sit weaker than your main policy.
- Reporting address: we check that your DMARC record still sends the reports to us. If our address disappears from it — a move, or someone rewriting the record — the reports stop without anything breaking. You hear it from us instead of finding out six months later.
- Alignment: the reports tell us per sending source whether SPF or DKIM was aligned, which is what the "got through or not" overview rests on. The alignment settings in your own record (adkim, aspf) we do not check.
- Reports: aggregate (rua) only, gzip/zip XML. The format was in RFC 7489 and, since May 2026, in RFC 9990 — which together with RFC 9989 (the protocol) and RFC 9991 (failure reports) replaced the old standard. Every domain gets its own reporting address, so a report always maps to exactly one domain.
- Failure reports (ruf, RFC 9991) we deliberately do not process. They carry fragments of real messages from real people; that is not something we want to hold, and the standard warns about it itself.
- The external destination authorisation required by RFC 9990 §4 is published on our side. You do not need an extra record for it.
- Reports we cannot read or cannot attribute do not vanish quietly: they go to a quarantine with the reason attached.
- Retention: raw reports for thirty days, then daily aggregates that stay for thirteen months.