Email security monitoring

See who sends email as your domains. In the EU, on your terms.

Mail receivers already generate daily reports about email sent using your domain name. norppa.io receives those DMARC and TLS-RPT reports at a unique EU address, turns them into clear analytics, and flags active spoofing as prioritised findings.

In every plan: one domain free, all your domains with a subscription.

How it works

1

Add your domain

In the dashboard, add the domain you want to monitor. You get a unique reporting address.

2

Publish two DNS records

Add the address to your DMARC record (rua) and your TLS-RPT record. We give you both, ready to copy. Your IT team or DNS provider adds them in minutes; we never touch your DNS.

3

Reports become findings

Mail receivers send aggregate reports about once a day. They flow into pass-rate analytics and a sender inventory, and abusive sources become prioritised findings with alerts.

What you get

DMARC report analytics

Authentication pass rate over time and an inventory of every source that sends email as your domain. Each source is named after the service behind it, such as Microsoft 365 or your newsletter tool, whenever the reports allow it.

Every sender, labelled

Each sending source is labelled so you can read a low pass rate at a glance: Authorized (aligned and legitimate), Forwarded (your legitimate mail relayed through a recipient's security gateway), Alignment gap (your own sender that just needs SPF or DKIM), Unconfirmed (a recognisable service nothing shows to be yours, so you are asked), or Unauthenticated (an unrecognised source worth reviewing). No guessing whether a failing source is benign forwarding or a real threat.

Enforcement readiness

DMARC's goal is enforcement (p=reject), where nobody can spoof your domain. From the labelled senders, norppa.io tells you when it is safe to get there and exactly which senders to align first, so you reach full protection without losing legitimate mail.

Spoofing and lookalike detection

Failing sources no legitimate service explains are flagged, enriched with network ownership and abuse context, and raised as findings. Sources on known abuse feeds escalate to critical. Domains that look like yours are checked every day (weekly on the free plan), and you get an email when one is set up for email.

Email encryption monitoring (TLS-RPT)

See whether mail sent to your domain actually arrives over encrypted TLS, and get findings when certificates or policies break delivery security. It also tells you when it is safe to enforce MTA-STS (mode=enforce) without bouncing mail.

Blocklist & reputation monitoring

Daily checks of your and your suppliers' mail servers against spam blocklists and abuse-reputation sources, with a listed/delisted timeline.

Email setup analyzer

A live, read-only check of any domain: SPF lookup budget with the include tree, DMARC enforcement level, BIMI readiness, MTA-STS and TLS-RPT presence. Advisory only; we never host or change your records.

New senders, missing suppliers

When a service starts sending as your domain, you get an email within a day of the first report showing it, and your suppliers page marks it as new. If nothing shows the service is yours, the email asks whether it is. Services that send as you, or that your DNS records and website reveal, are suggested for your supplier list when they are missing from it, each with the evidence behind it.

NIS2-mapped evidence

Every finding is mapped to the relevant NIS2 article and flows into alerts, the weekly digest and your audit-ready reports.

Built in the EU, stays in the EU

Your supply-chain risk map never leaves the EU

norppa.io is a European company. Your suppliers, findings and NIS2 evidence are stored and processed in the EU, under EU jurisdiction, with no third-country transfer of your supplier data.

  • EU company, Norteris Oy in Helsinki
  • Fully Finnish-owned: every shareholder is Finnish and based in Finland
  • EU data residency, Frankfurt region
  • EU jurisdiction: your contract is under EU law only
  • EU support, based in Finland

A NIS2 risk register is sensitive in itself: it is a map of where your supply chain breaks. Before you choose a supply-chain platform, ask one question. Where does it send yours?

Aggregate data only. Never your email.

DMARC and TLS-RPT reports contain counts and sending-source metadata, never the subject, body or attachments of any message. We process aggregate reports only, hosted in the EU.

Email security is one layer of norppa.io. The services found sending as your domain lead straight to your supplier list, and the same platform monitors each supplier's external security posture for NIS2 supply-chain compliance.

Frequently asked questions

What is DMARC monitoring?⌄

DMARC (Domain-based Message Authentication, Reporting and Conformance) lets you control who can send email using your domain. Mail receivers report daily on every source that sent email as your domain; norppa.io receives and analyses those reports so you can separate legitimate senders from spoofing and brand impersonation.

Can you tell which services send email as my domain?⌄

For most sources, yes. A source is named from the domains in the report itself, such as the one in the DKIM signature. For mail that passed SPF for your domain, the address ranges the service publishes can name it too. Mail relayed by a recipient's security gateway, and sources nothing identifies, stay unnamed rather than guessed.

What if someone sends as us through a real email service?⌄

An attacker can open an account at a well-known sending service and send as your domain. The reports cannot tell that account from your own, so norppa.io does not assume it is yours. A failing service counts as yours only if your SPF record includes it, its mail has passed DMARC for your domain before, or it is on your supplier list. Otherwise you are asked. If you answer that it is not yours, it stops blocking the move to p=reject, which is what stops its mail.

Do you change or host my DNS records?⌄

No. You publish two TXT records in your own DNS (we give you the exact values to copy), and everything else is read-only analysis. norppa.io never hosts, edits or serves your DNS.

What data do you store, and where?⌄

Only the aggregate reports mail receivers generate: session counts, source IPs and authentication results. Never message content or attachments. Data is processed and stored in the EU.

Which plans include email security monitoring?⌄

All of them. DMARC analytics, TLS-RPT, spoofing detection and blocklist monitoring are base features on every norppa.io plan: one domain free, all your domains with a subscription.

Read the guide: vendor impersonation, CEO-fraud and DMARC under NIS2 →

See how EU sectors score on these checks in our live hygiene index →

Free · no credit card · no expiry

Free plan: the 41-question NIS2 questionnaire for up to 10 suppliers, public checks on your own domain, and DMARC monitoring for one domain.