A comprehensive platform for Secure Government Email requirements

Set up and monitor the DMARC, SPF, DKIM, TLS-RPT, MTA-STS and parked domain controls in SGE from one dashboard. VerifyDMARC is an approved supplier on the New Zealand Government Marketplace.

New Zealand owned and operated, based in Auckland, with support in New Zealand business hours.

Start Free Trial

SGE technologies, line by line

SGE lists the technologies agencies need to deploy. Here is what VerifyDMARC does for each one.

SGE technology Set up with VerifyDMARC Monitored by VerifyDMARC
TLS Reporting (TLS-RPT) Receive feedback on issues with encrypted email delivery.
  • TLS-RPT record generator and check, so reports start arriving and keep arriving.
  • Ingests, enriches and stores the SMTP TLS reports from hosts delivering mail to your domain.
  • TLS Failure Alerts by email when a report contains failures.
Sender Policy Framework (SPF) Only authorised servers and services send as your domain.
  • SPF Record Checker flags issues and misconfigurations, rechecked hourly.
  • Observed usage shows which SPF mechanisms match real traffic, so you can remove the ones that do not.
  • Regression Alerts if an SPF record weakens or the lookup limit is exceeded.
DomainKeys Identified Mail (DKIM) Messages are signed and unaltered in transit.
  • A report of senders passing SPF but not DKIM, so you can see which sources still need signing.
  • DKIM Selector Alerts when a known selector starts failing verification, an early signal of a broken or rotated key.
DMARC Ties SPF and DKIM together with policy and reporting. SGE states a DMARC reporting tool is required.
  • DMARC Record Generator and check for a best-practice record on every domain.
  • Actionable report insights on sending source DMARC compliance.
  • RUA report processing with source enrichment, so every source sending as your domain is named, not just an IP address.
  • Enforcement status across every domain on one dashboard, with Subdomain Detection and Regression Alerts.
  • Scheduled Digest emails summarising domains needing action and enforcement posture.
MTA-STS Enforce encryption on inbound mail and prevent downgrade attacks.
  • MTA-STS Setup Validation checks the DNS record exists and the policy file is reachable over HTTPS and valid.
  • The current mode is shown on the dashboard, so a policy left in testing mode does not go unnoticed.
  • Regression Alerts if DNS MX records are no longer aligned with the policy, or if the policy file cannot be reached or is invalid.
Transport Layer Security (TLS 1.2 minimum, implicit TLS) This is mail platform functionality. Out of scope for VerifyDMARC.
Data Loss Prevention (DLP) This is mail platform functionality. Out of scope for VerifyDMARC.

Parked domains, also required by SGE

Domains that never send email still need a reject policy and an empty SPF record.

Set up with VerifyDMARC

  • High domain limits on every plan, so every parked domain can be onboarded rather than left unmonitored.

Monitored by VerifyDMARC

  • Automated checks that each parked domain has a DMARC reject policy and an empty SPF record.
  • Parked domains unpark automatically, with an alert email, if compliant mail is reported or the policy weakens.

Every capability above is included on every plan. See the full feature list for detail. Refer to the official Secure Government Email Common Implementation Framework for your agency's exact obligations.

SGE compliance verification in one view

The dashboard confirms the sending and receiving position of every domain at a glance, so compliance checks stop being a manual DNS exercise.

VerifyDMARC dashboard showing DMARC reject policies, compliance mix, MTA-STS enforcement and parked domains across four domains
  • Confirmation that a DMARC reject policy applies to every domain, with any record errors reflected in the Status symbol.
  • The DKIM and SPF compliance mix per domain, so you can confirm most mail is DKIM and SPF or DKIM only compliant.
  • Confirmation that MTA-STS is enforcing and the policy file is valid, with any errors reflected in the TLS Status symbol.
  • Parked domains that meet the reject and empty SPF requirements are shown or hidden with one toggle.
  • Drill down to individual DMARC senders or TLS reporters per domain.

Procurement

VerifyDMARC Limited is an approved supplier on the New Zealand Government Marketplace for Secure Email Management and Administration services.

Agencies registered on Marketplace can email sales@verifydmarc.com to discuss requirements and pricing under Marketplace commercial terms. Alternatively, start a 30-day free trial from the pricing page.

Working with a New Zealand supplier

  • Incorporated in New Zealand, with our team in Auckland and support in New Zealand business hours.
  • Compute and storage for the reporting service is in the European Union.
  • Report data is currently retained for 90 days. See our privacy policy for the full retention terms.
  • DMARC and TLS reports contain technical data such as domains, source IP addresses, authentication results and message counts. They do not contain sender or recipient addresses, subject lines or message bodies.

For MSPs serving agencies

If an agency works through you, VerifyDMARC gives you generous domain limits, unlimited admin users, bulk import by CSV or API, and one dashboard across every client domain. See the MSP page.

Talk to us or try it first

For procurement questions or pricing for a larger domain count, email sales@verifydmarc.com. Or start the free trial and see it with your own domains first. No credit card is required until the trial ends.