EmailAuth DMARC & BIMI Consultant
EmailAuth is an email authentication platform covering DMARC and BIMI, and its own tagline is "DMARC and BIMI in one shot". The platform is the easy part. Finding every system that sends mail as your domain, authenticating each one, and then actually reaching an enforcement policy is the work. UAE and GCC clients get a consultant who takes a domain from p=none to reject without breaking the invoicing run.
- Sending source discovery and authentication
- Staged path from p=none to p=reject
- UAE & GCC regulatory context
What is EmailAuth?
EmailAuth is an email authentication platform focused on DMARC and BIMI. Its published capabilities cover DMARC deployment and reporting, DKIM setup with a DKIM record checker, SPF, BIMI, a DMARC record generator, DMARC setup guides, and a compliance checker for the Google and Yahoo bulk sender requirements. That is a tightly scoped product set, and the scope is the point: this is a tool for getting email authentication right, not a mail gateway and not a phishing defence suite. I would rather describe honestly what it does than pad the list, so the rest of this page is mostly about the problem, because that is where projects actually succeed or fail.
Start with what the three records really do, because they are constantly conflated. SPF is an authorisation list published as a DNS TXT record. It names the IP addresses and hosts allowed to send mail for your domain, and a receiving server compares the connecting IP against that list. Crucially, SPF checks the envelope sender, the address used during the SMTP conversation, which is not the address a human sees in the message. DKIM is a cryptographic signature. The sending system signs selected headers and the body with a private key, publishes the matching public key in DNS under a selector, and the receiver verifies the signature. That proves the message came from a system holding your key and that the signed content was not modified. Neither record, on its own, says anything about the From address the recipient reads.
DMARC is the layer that closes that gap. It introduces alignment: the domain that passed SPF or DKIM must match the domain in the visible From header. It then publishes a policy telling receiving servers what to do when nothing aligns, and it requests reports back so you can see who is sending as you. The policy values are the whole journey. p=none monitors and blocks nothing. p=quarantine asks receivers to treat unaligned mail as suspicious, usually junk-foldering it. p=reject asks receivers to refuse it outright. Only quarantine and reject are enforcement. A domain sitting at p=none has visibility and no protection, and a great many organisations that believe they have implemented DMARC are in exactly that state.
Two technical details cause more failed projects than anything else. The first is the SPF ten DNS lookup limit. Every include, redirect, a, mx, ptr and exists mechanism in your SPF record costs a DNS lookup, and those nest, so one cloud provider include can quietly consume several. Exceed ten and the record returns a permanent error, at which point SPF fails for legitimate mail, not just for attackers. Large estates hit this quickly because every new SaaS platform that sends on your behalf wants another include. The fix is flattening, consolidation, moving senders onto subdomains, or leaning on DKIM for sources that cannot be accommodated. The second is the reports. DMARC aggregate reports, the RUA feed, arrive as compressed XML from every receiving provider, several times a day, describing message counts by source IP and authentication result. They are machine output, and reading them by hand across even a modest estate is not realistic. This is precisely the gap a DMARC platform fills: parsing, source identification and trending. Without tooling, most organisations publish a RUA address, collect the XML in a mailbox nobody opens, and stop there.
BIMI is the brand payoff and it sits at the end of the road, not the start. To display your logo in supporting inboxes you need DMARC at enforcement, a logo in the specific square SVG Tiny Portable/Secure profile, a BIMI record in DNS, and for the major mailbox providers a Verified Mark Certificate from an approved authority, which normally requires a registered trademark and an organisational verification process with an annual cost. It is worth wanting, but it is not a shortcut and no platform can grant it without the underlying enforcement being real.
What DMARC Does Not Do
This matters more than any feature list, and it belongs in the open rather than in a footnote. DMARC only protects domains you own, and it only stops exact-domain spoofing. It does nothing about a lookalike domain such as a near-miss spelling of your company name, because that domain is not yours and its owner can publish perfectly valid SPF, DKIM and DMARC records of their own. It does nothing about display-name spoofing, where the attacker sends from a free webmail account but sets the display name to your finance director. It does nothing about a genuinely compromised mailbox, because that mail is authentic by every measure the standard checks. And it says nothing about attachments, links or payloads. DMARC at enforcement is a necessary control and one of the highest-value ones available, but it is not a complete answer to phishing. It belongs alongside a secure email gateway and user awareness training, not instead of them.
Official Product Portfolio
Where I Can Help
Publishing a DMARC record takes ten minutes. Reaching enforcement without breaking legitimate mail is a project, and it is almost entirely about discovery, sequencing and stakeholder patience. These are the areas I cover.
Sending Source Discovery
Building the inventory of every system that sends mail as your domain, which is always longer than the list IT hands over on day one. Marketing platforms, CRM and ERP notifications, HR and payroll, ticketing, invoicing services, office multifunction devices, regional relays and whatever a department bought on a card. Nothing else in the programme can proceed until this list is genuinely complete, and the aggregate reports are what make it complete.
SPF Design Within the Ten Lookup Limit
Designing an SPF record that stays valid as the estate grows. Counting the real lookup cost of nested includes rather than the visible ones, flattening or consolidating where it is safe, moving bulk and transactional senders onto their own subdomains, choosing between softfail and hardfail deliberately, and documenting the record so the next person to add a SaaS platform does not silently push it past ten and break authentication for everyone.
DKIM Signing & Key Management
Getting DKIM signing switched on and aligned at every source that supports it, which is the more durable half of DMARC because it survives forwarding in a way SPF does not. Selector naming that leaves room for more than one platform, key length choices, publishing and verifying the public records, and a rotation process that is written down rather than remembered, so a key change does not take authentication down on a Friday.
Aggregate Report Analysis
Turning the RUA feed into decisions. Aggregate reports arrive as compressed XML from every receiving provider and are unreadable at volume without tooling, which is exactly what a platform such as EmailAuth is for. The work is interpreting the output: separating a forgotten legitimate sender from an actual spoofing attempt, tracking pass rates per source over time, and knowing when the data is clean enough to justify moving policy.
Staged Enforcement to p=reject
The step everyone stalls on. Moving from p=none to p=quarantine and then p=reject in controlled stages, using the percentage tag to enforce on a slice of traffic first, setting subdomain policy deliberately rather than by accident, agreeing a rollback trigger and who is allowed to pull it, and timing changes away from month-end invoicing and payroll runs. Enforcement is a change management exercise wearing a DNS record.
BIMI Readiness & Certificate Prerequisites
Getting the brand outcome once enforcement is real. Confirming the DMARC policy actually qualifies, preparing the logo in the square SVG Tiny Portable/Secure profile, publishing the BIMI record, and setting realistic expectations on the Verified Mark Certificate: it requires a registered trademark and an organisational verification process, carries an annual cost, and support differs between mailbox providers, so it is planned in weeks rather than promised for next sprint.
Why EmailAuth for UAE Organisations?
The regional case for email authentication is unusually concrete. Business email compromise and invoice fraud are among the most damaging attack types against UAE and GCC organisations, and they are damaging precisely because they involve no malware and no exploit. A supplier payment is redirected, a beneficiary account is changed, an urgent transfer is requested by someone who appears to be an executive, and the money leaves through a legitimate banking channel. DMARC at enforcement is the control that stops an attacker sending mail that appears to come from your own domain, which removes the most convincing version of that attack. Brand impersonation of banks and government entities is a live problem in this market, and every one of those campaigns depends on the recipient trusting the sender name they can see.
The compliance picture supports the same conclusion without needing to be overstated. The NESA information assurance standards expect controls over electronic messaging and protection of information in transit. CBUAE requirements push regulated financial institutions towards controls that reduce customer-facing fraud, and a bank whose domain can be spoofed is handing attackers a working phishing template. DESC in Dubai sets comparable expectations for entities in its scope, and the data protection regimes in ADGM and DIFC, together with the federal PDPL, rest on an obligation to apply appropriate technical measures. None of these frameworks name DMARC as a line item, and I would not claim otherwise, but domain spoofing is a direct route to both fraud loss and personal data compromise, so it is a control an assessor understands immediately once you show them the reports.
Then there is the commercial forcing function. The Google and Yahoo bulk sender requirements apply to senders exceeding roughly five thousand messages a day to their users, and they require SPF and DKIM authentication, a published DMARC record, alignment between the visible From domain and the authenticated domain, one-click unsubscribe on marketing mail, and a spam complaint rate kept below threshold. Be precise about what that means: the published minimum policy is p=none, so the rules make DMARC mandatory in the sense of having it, not enforcing it. Enforcement remains your security decision. But for UAE retail, banking, telecom, hospitality and government-facing services, where a large share of the customer base sits on consumer mailboxes, an unauthenticated domain is now a deliverability problem as well as a security one, and that is what moved this off the backlog. For the wider picture of how authentication fits with gateway controls and awareness training, see my email security services.
Talk to a DMARC Expert
Whether you are choosing a DMARC platform, stuck at p=none after a year of monitoring, fighting an SPF record that has run past ten lookups, or trying to work out what BIMI really costs, I can help.
- Free initial scoping call
- UAE & GCC regulatory context
- Vendor-neutral DMARC platform comparison
- Staged enforcement without breaking mail flow
- OSCP-certified security background
Frequently Asked Questions
Comparing DMARC Platforms?
EmailAuth is a focused DMARC and BIMI tool, and for many organisations that focus is exactly right. It is not the only route. Proofpoint Email Fraud Defense and Mimecast DMARC Analyzer cover the same ground from inside a broader email security suite, which suits you if that gateway is already in place and you would rather have one console and one contract. I work with those platforms too, so the comparison comes from having used them rather than from a datasheet. The right answer usually turns on whether you already own a gateway from the same vendor, not on the DMARC feature list.
Basim Ibrahim, DMARC and EmailAuth Consultant in Dubai
If you are searching for a DMARC consultant in Dubai, an EmailAuth implementation partner in the UAE, or an email authentication expert for GCC deployment, you have found the right person. I am Basim Ibrahim, a Dubai-based cybersecurity presales and technical consultant working across DMARC, SPF, DKIM and BIMI, including the EmailAuth platform for DMARC deployment, reporting, DKIM checking, record generation and Google and Yahoo bulk sender compliance.
I provide end-to-end DMARC implementation services in Dubai and the UAE, from sending source discovery through to enforcement. Whether you need an SPF record fixed within the ten DNS lookup limit, DKIM signing and key rotation set up across a mixed estate, DMARC aggregate report analysis that turns raw XML into a decision, a staged move from p=none to p=quarantine and p=reject that does not break invoicing or payroll mail, or BIMI readiness including the verified mark certificate prerequisites, I can deliver it.
Based in Dubai with hands-on experience across UAE and GCC enterprise environments, and comfortable framing email spoofing and business email compromise defence against NESA, CBUAE, DESC, ADGM, DIFC and PDPL expectations. I am also clear about the limits: DMARC stops exact-domain spoofing and nothing else, so it works alongside a gateway rather than replacing one. If you would rather run DMARC from inside an existing suite, I also work with Proofpoint Email Fraud Defense and Mimecast DMARC Analyzer, and all of it sits inside a single email security programme.