ActiScan

Compliance posture

A baseline for the questions you keep getting asked

Email authentication shows up in more security questionnaires, insurance forms and vendor requirements every year. Have a real, dated answer with evidence behind it, not a guess.

evidence / northfield-cpa · Q3

Northfield CPA

Email authentication evidence · Jul 1 to Sep 30

PDF · CSV
SPFPass
DMARCp=reject
DKIMPass
MTA-STSEnforced
DNSSECNot signed

4 record changes · 6 fixes and approvals · 3 findings resolved, each dated

Evidence you can hand over

A documented baseline

SPF, DMARC, DKIM, BIMI, MTA-STS, TLS-RPT, DNSSEC and 7-blacklist status, graded and dated: something concrete to show when someone asks about email security.

Tracked over time

An activity log and change alerts show that email security is actively watched, not checked once and forgotten.

Evidence packs

A PDF or CSV for any client and period: posture, record changes, fixes and approvals, and findings, each dated, ready to hand to an auditor, insurer or questionnaire.

Events in your SIEM

Findings, fixes and DNS changes flow to Splunk, Microsoft Sentinel, a webhook or CEF syslog, where audits already look.

The exact gap, and the fix

Each finding comes with the specific DNS record to publish, for when the step after "you need DMARC" is publishing a correct one.

Enforcement you can show

A dated path from p=none to p=reject, one step at a time, so you can show where each client stands and when it changed.

Where it shows up

Where email authentication comes up

Only the Google, Yahoo and Microsoft bulk-sender rules actually name SPF, DKIM and DMARC. The rest require technical safeguards or risk management broad enough that email authentication is commonly considered part of the picture, not a box any of them name directly.

RegulationWhat it requiresRegionWho it applies to
Google & Yahoo bulk-sender rulesPublished, valid SPF, DKIM and DMARC for any domain sending 5,000+ messages a day to Gmail or Yahoo addresses.Global (enforced since Feb 2024)Any business sending bulk email to Gmail or Yahoo inboxes
Microsoft bulk-sender rulesSPF, DKIM and DMARC for high-volume senders to Outlook, Hotmail and Live addresses.Global, phased in through 2025Businesses sending bulk email to Microsoft consumer inboxes
HIPAA Security Rule"Reasonable and appropriate" technical safeguards protecting the transmission of health information.United StatesHealthcare providers, health plans and their business associates
GLBA Safeguards RuleFinancial institutions to maintain an information security program protecting customer financial data.United StatesBanks, lenders, insurers and financial advisers
PCI DSS 4.0Anti-phishing mechanisms for staff with access to the cardholder data environment (new in 4.0).GlobalAny business that processes, stores or transmits payment card data
GDPR"Appropriate technical measures" protecting the personal data of EU residents.EU (and anywhere handling EU residents' data)All industries handling EU personal data
NIS2 DirectiveRisk-management measures against common attack vectors, including social engineering, for in-scope entities.EUEnergy, healthcare, transport, digital infrastructure and more
DORAICT risk-management and incident-reporting requirements for the financial sector.EUBanks, insurers and investment firms

Being direct about this

A passing grade from ActiScan is an assessment based on the checks we run at the time of the scan. It is not a guarantee of compliance with any law, regulation or industry standard (see our Terms). What it is: a fast, real, dated way to show your email-authentication baseline and that you're actively watching it, not a substitute for reading whatever specific requirement someone is asking about.

Questions

Does a passing ActiScan grade mean I'm "compliant"?+

No. A grade is an assessment based on the checks ActiScan runs at the time of the scan. It's not a guarantee of compliance with any law, regulation, industry standard or vendor questionnaire, which often ask for things ActiScan doesn't independently verify. Treat it as a real, dated baseline you can point to, not a certification.

Does this satisfy Google and Yahoo's bulk-sender requirements?+

Google and Yahoo require a published DMARC record for bulk senders, and ActiScan checks for exactly that, including whether it's enforcing rather than just present. Whether your sending volume and setup meet their full requirements is worth confirming against their own current documentation, not assuming from a grade.

Will this help with a cyber-insurance application or security questionnaire?+

Email authentication shows up in more of these than it used to. ActiScan gives you a real answer with dated evidence behind it instead of a guess, but it doesn't replace reading the specific questionnaire or policy, which can ask for things beyond DNS-level checks.

See your own baseline right now

Scan any domain free, or add your clients and keep dated evidence for every one. Free for 30 days.