Email authentication is three DNS records that most companies publish once and never read again. They are usually present. They are also usually set to watch rather than to reject, which means a forged message from your own domain still arrives in somebody's inbox looking exactly right.
Email authentication is three DNS records, and the question is never whether they exist but whether they bite. We read SPF, DKIM and DMARC and tell you whether the policy rejects a forged message or merely files a report about it, then find the domains and subdomains where nothing enforces at all.
A forwarding rule set up years ago will still be running today, and nobody gets a reminder. We find rules that send mail automatically to an address outside the company, and we list who holds delegated access to somebody else's mailbox.
The controls that stop a message are separate from the ones that authenticate it, and they fail quietly. We check whether malicious attachments are actually blocked rather than merely flagged, and whether a suspicious link is examined before somebody clicks it.
Those questions are the shape of it, not the inventory. Underneath them is a larger set of individual settings we read on each platform, and it moves every time a platform ships something new.
Where a CIS safeguard fits the evidence, the finding carries it, so the answer you give an auditor is the answer we already gave you. Where none fits, we leave it unmapped rather than claim a control we cannot stand behind.
A finding names the record or the mailbox, not just the control it belongs to.
Every change is prepared for you, made only once you approve it, logged, and reversible where the platform allows. How that works
Today we read mail settings from Google Workspace, and the records your domains publish in DNS, including through Cloudflare. More platforms are in development.