DomainScores
> Guides
Domain & Email Security Guides
Practical guides behind your domain trust score: SPF, DKIM, DMARC, DNS security, TLS and email authentication, explained in plain English.
Email Security and Domain Protection: How Cloudflare Shields Your Brand. — Domain hijacking and email spoofing can destroy a business's reputation overnight. How Cloudflare's DNS, DNSSEC, and SPF/DKIM/DMARC protect Irish businesses.
Email Security Beyond Spam Filters: DMARC, DKIM, and SPF Explained. — Spam filters alone do not stop email spoofing. DMARC, DKIM, and SPF are the technical controls Irish SMEs need. Here is how they work and how to implement them.
Email Security for Irish Businesses: SPF, DKIM and DMARC Explained. — BEC and phishing attacks are costing Irish SMEs millions. Here is how SPF, DKIM, and DMARC stop email impersonation and how to implement them for your business.
Someone Is Sending Emails From Your Domain Right Now. Here Is How to Stop Them. — Without DMARC, anyone can send emails pretending to be your business.
Free SSL/TLS Certificates: Why Your Irish Business Website Needs HTTPS. — Sites without HTTPS lose customers and risk GDPR fines. Cloudflare provides free SSL certificates with automatic renewal for any Irish business website.
Email Security Beyond the Spam Filter: What Irish SMEs Actually Need. — The built-in Microsoft 365 spam filter is not enough for Irish SMEs. Here is what dedicated email security, DMARC, and staff training actually prevent.
How to Add DMARC to Your Irish Business Email: A Step-by-Step Guide. — A plain-English guide to adding a DMARC record for Irish businesses using Microsoft 365, Google Workspace, or any DNS provider. Takes 5 minutes and costs nothing.
DNS Security: The Overlooked Protection Layer for Small Businesses. — DNS security is one of the most cost-effective protections available to Irish SMEs. Here is what DNS filtering does, why it matters, and how to implement it.
We Took the DigitalTrust.ie Test - Here's What We Learned and How We Fixed It. — We ran DigitalTrust.ie against our own domain, scored a C, and fixed every finding to reach an A. A practical walkthrough for Irish SMEs wanting to improve their score.
Why are my emails going to spam? Causes and fixes — Why are my emails going to spam? The real causes for small businesses: missing SPF, DKIM and DMARC, poor sender reputation or a blacklisting, plus fixes.
Invoice redirection fraud and BEC: how to stop it — Invoice redirection fraud and Business Email Compromise cost Irish SMEs millions. Learn how the scam works and the practical, low-cost steps that stop it.
Email spoofing explained: how attackers fake your domain — Email spoofing lets attackers fake your domain in the From address to send phishing in your name. Learn how it works and how SPF, DKIM and DMARC block it.
DMARC: Stop Criminals Sending Email as Your Business — Without DMARC enforcement, anyone can send email from your exact domain address. 89% of domains have this gap. Here's what it costs, and how to close it.
SPF Records Explained: Authorise Your Email Senders — SPF tells the world which servers are authorised to send on your behalf. Without it, your legitimate emails get junked and criminals can impersonate you.
DKIM: The Digital Seal That Proves Your Emails Are Genuine — DKIM cryptographically signs every email you send. Without it, Google and Yahoo increasingly treat your mail as suspicious, and buyers flag the risk.
HTTPS: Your Website Is Telling Visitors 'Not Secure' — A missing or broken HTTPS setup costs you visitors, Google ranking, and enterprise deals. Here's what it means for your business and how to fix it fast.
DNSSEC: Prevent Attackers Redirecting Your Domain — Without DNSSEC, attackers can poison DNS caches and redirect your website and email to servers they control, invisibly. Only 1.99% of domains are protected.
HSTS: Stop Attackers Intercepting Your First Connection — HSTS forces browsers to always use HTTPS, closing the unencrypted window on every first connection. Required by enterprise buyers and most insurers.
Old TLS Versions: The Encryption Gap on Your Server — TLS 1.0 and 1.1 are deprecated and exploitable. If your server still accepts them, browsers flag it, insurers notice, and enterprise questionnaires fail you.
SSL Certificate Errors: Fix 'Connection Is Not Private' — A browser certificate warning stops visitors dead. 8.21% of HTTPS sites have invalid certificates, costing leads, sales, and trust on every visit.
CAA Records: Control Who Can Issue Your SSL Certificates — Without CAA records, any of 200+ certificate authorities could issue a certificate for your domain. It takes 5 minutes to lock this down.
Can Someone Spoof Your Email Domain? Probably. Check Now — 89% of domains have no enforcement stopping criminals from sending email as them. Invoice fraud, CEO impersonation, and supplier scams all start here.
Emails Going to Spam? Diagnose SPF, DKIM and DMARC Failures — Email landing in junk is almost always an SPF, DKIM, or DMARC problem. Here's how to diagnose which one is failing, and what it's costing you.
NIS2 and Email Security: What Irish Businesses Need in Place — NIS2 requires demonstrable email security controls. DMARC enforcement is what regulators reference. Here's what Irish businesses need, and what's at stake.
Cyber Insurance: What Underwriters Check on Your Domain — Irish cyber insurers check DMARC, TLS, and DNS security on every application. Only 3.87% of domains pass the full baseline. Gaps mean higher premiums.
DMARC Policies Compared: p=none vs quarantine vs reject — 24.89% of domains publish DMARC but most use p=none, which provides zero protection. Here's what each policy level does, and which one your business needs.
Google & Yahoo Email Sender Rules 2026: Are You Ready? — Google and Yahoo now require SPF, DKIM, and DMARC for all senders. Most Irish business domains aren't compliant. Here's what happens if you're not.
Domain Hijacking: How Attacks Work and How to Prevent Them — Domain hijacking redirects your website and email to an attacker's servers. The free protections take minutes to enable. Most domains skip them.