Email Trust Status helps business owners replace assumptions about their email security with a documented record. Many rely on their IT provider for reassurance, especially when email appears to be working and no obvious problem has surfaced.
The problem is that reassurance is not the same as a record. There is a practical difference between believing your email security is in order and having a structured document that shows how your domain actually presents itself to the outside world. Email Trust Status turns that visibility into a clear Governance Record.
In 2025, the FBI’s Internet Crime Complaint Center recorded more than $3 billion in reported losses from business email compromise attacks across nearly 25,000 complaints. South Africa is not exempt: SABRIC, the banking industry’s crime risk body, reports that social engineering and AI-generated impersonation scams are driving a sharp rise in fraud targeting local businesses and banking customers. These attacks often rely on impersonation, trust and payment instruction fraud. Your email domain is part of your business identity, and its public trust signals exist whether you have reviewed them or not.
What Is Email Trust Status?
Email Trust Status is a point-in-time check of your domain’s publicly visible email authentication posture. It reviews the DNS records linked to your domain and translates them into a clear Email Enforcement Classification that a non-technical reader can understand and use.
In plain terms, it answers a question that most organisations have never formally asked: what does your domain instruct external mail systems to do when a suspicious email claims to come from your business?
You do not need to provide access to inboxes, passwords, mail servers or internal systems. The check reviews only what is already publicly visible and records that visibility in a structured Governance Record. You only need to provide the domain name.
That makes it accessible and useful for a broad range of people: business owners, financial services providers, attorneys, brokers, directors, and compliance teams. You do not need a technical background to read the record or understand what it says about your domain.
Why Assumption Is Not the Same as a Record
Many SMEs assume Microsoft 365, Google Workspace or a managed IT provider automatically protects their email domain. Those services can form part of a solid email environment, but they do not automatically confirm that your domain has the right public email authentication signals in place.
Your IT provider may be doing good work behind the scenes. The issue is that business leadership rarely has a simple external record to refer to. Without one, a director or compliance officer must rely on verbal assurance, which can be difficult to present to a broker, insurer or regulator asking for evidence of oversight.
Email Trust Status does not replace your IT provider or their work. It gives the business a credible external view that can support a better conversation with the right people, including IT, management, compliance advisers and insurers. You do not need to become technical to ask better questions about your own domain.
What Your Email Domain Tells the Outside World
Before anyone reads the content of your email, your domain has already sent a signal. That signal comes from public email authentication records that any external mail system can read.
Three main records shape this signal. SPF shows which services may send email for your domain. DKIM helps receiving systems check whether a message changed in transit. DMARC adds the enforcement layer: it tells receiving mail systems what to do when a message claims to come from your domain but fails authentication checks.
DMARC is the most significant of the three from an enforcement standpoint because it creates a visible, publicly readable instruction. A domain may have no DMARC record at all, a monitoring-only policy, a cautionary policy, or a rejection policy. Each of those positions means something different for how receiving mail systems are told to treat impersonation attempts.
This is where many organisations have a gap. They may have email protection in place, but leadership may never have formally recorded or reviewed the enforcement level.
What the Governance Record Shows
The Email Trust Status Governance Record documents whether your domain has visible email authentication signals and how strong those signals appear externally. It does not say your organisation is fully secure, and it does not assess anything inside your systems.
The record shows whether your domain has a DMARC record, whether the policy uses monitoring, quarantine or reject, and whether SPF and DKIM indicators appear publicly. It also notes observations such as subdomain policy and mail exchange records where relevant.
The result is an Enforcement Classification. If your domain has no DMARC record, external systems have no instruction from you about how to handle suspicious messages. With p=none, the domain is in monitoring mode, collecting data but not blocking anything. A p=quarantine policy asks receiving mail systems to treat failed messages with caution, often by placing them in spam or quarantine. A p=reject policy actively instructs external mail systems to block messages that fail authentication.
Understanding where your domain sits on that scale is the starting point for any informed conversation about email impersonation risk.
Who This Is Relevant For
Email trust is not only a technical concern. It affects client relationships, payment instructions, supplier communication and the credibility of your business identity.
For business owners and SMEs, your domain’s enforcement position gives you a factual starting point. The record may confirm a strong posture, or it may surface a gap that needs attention.
For FSPs, brokers, attorneys and professional firms, a documented authentication record supports oversight. It helps show that a specific digital communication risk was reviewed, not simply assumed to be in order.
How This Connects to South African Regulatory Expectations
South African regulatory frameworks do not prescribe specific technical controls in isolation. Instead, they expect responsible parties, governing bodies and management to identify relevant risks, consider them properly and address them proportionately. POPIA, FAIS and King V each point in that direction, whether through appropriate security safeguards, electronic data security oversight or governing body responsibility for digital risk.
Email Trust Status does not prove compliance with any of these frameworks. What it can do is provide documented evidence that a specific and relevant communication risk was reviewed, not just assumed to be covered. For many organisations, that is exactly the kind of record a governance discussion or compliance review calls for.
For more context, see our Regulatory Environment page.
What Email Trust Status Does Not Cover
Email Trust Status has an intentionally defined and limited scope. The review covers only publicly observable DNS based email authentication indicators. Internal email security systems, security monitoring and incident response capability fall outside its scope. The record also excludes phishing simulation, penetration testing, email delivery testing and continuous monitoring.
This clarity is deliberate. A defined scope makes the record more useful because it avoids overstatement. Business leaders can see what the review covered, what it excluded and who they should involve next.
Email Trust Status Frequently Asked Questions
Not automatically. Microsoft 365 can be configured as part of a strong email environment, but the public email authentication records for your domain still need to be set up and maintained separately. Some organisations using Microsoft 365 or Google Workspace may still have DMARC records in a monitoring-only state or no DMARC record at all. Email Trust Status shows you the actual external position of your domain, whatever platform you use.
No. Email Trust Status is not an audit, certification or legal opinion, and it does not confirm compliance with POPIA, FAIS, King V or any other framework. What it can do is provide documented evidence that a specific domain level email risk was reviewed, which is relevant to discussions around risk visibility, appropriate safeguards and governance oversight.
The Governance Record is not a pass or fail assessment. It documents what is visible. If the result shows a monitoring-only or absent DMARC position, that is useful information, and the appropriate response is a conversation with your IT provider or a DMARC specialist. Knowing the position is always more useful than not knowing it.
A Practical First Step
Most organisations have never formally documented how their email domain presents itself to the outside world. That is not a criticism. The question has simply never been framed in a way that makes it easy for non-technical leaders to act on.
Email Trust Status gives business owners, directors and compliance teams a clear, external, point-in-time record. It supports better decisions and better conversations, without requiring a technical background to interpret the result.
For SMEs and professional firms, it is a sensible first step in managing email impersonation risk with documented evidence rather than assumption.
Get your Governance Record today. All you need is your domain name.



