Governance

Cybersecurity = governing security, and proving it

Email security is usually described by what it blocks. That is half the subject. The other half comes down to three questions few organisations can answer: who is allowed to write in our name, what rights do administrators have, who decides, who manages what, and how do we demonstrate it to a third party?

Request a demo

Three questions, and the evidence to back them

That is what the word governance covers, once the hollow part is removed.

01

Who is allowed to write in your name?

The CRM sends. The invoicing tool sends. The emailing platform sends, so does the payroll provider — and the one you left two years ago is still in your SPF record. Governing means keeping that inventory current, declaring it in DNS, and withdrawing rights when a provider leaves.

DMARC reports are the tool that reveals this inventory: every source sending under your domain shows up there, legitimate or not.

See DMARC reports
02

Who decides what gets through, and who may deviate?

An administrator handling four hundred release requests a month is not exercising governance: they are running a service desk. The real question is the level at which each rule is set, and how much autonomy is left below it.

Rules are set by domain, by group or by user. Everyone manages their own quarantine and personal lists, within the frame set above them. Administration can be delegated too, in MSP mode or end-customer mode.

See the user workspace
03

How do you demonstrate it?

To an auditor, to a cyber insurer, to a customer running due diligence. A policy you cannot produce in writing, and whose application you cannot show, is worth little on the day someone asks.

Logs of inbound and outbound messages, automatic carbon copy of outgoing mail, DMARC reports received and issued, signatures and legal notices applied centrally. Data stays hosted in France.

Compliance and sovereignty

Deliverability is the same subject, seen from the other end

Governing means making sure what leaves in your name is legitimate. Deliverability means making sure what is legitimate actually arrives. Same DNS records, same reports, two readings.

On the governance side

A domain properly aligned on SPF, DKIM and DMARC can no longer be impersonated unnoticed. Your contacts stop receiving fraudulent invoices signed with your name.

On the deliverability side

That same alignment is what the major mail operators look at when deciding whether your mail lands in the inbox or in junk. Your quotes, invoices and campaigns arrive.

Which is why this work does not concern the IT department alone. A DMARC policy tightened without a prior inventory gets your own customer follow-ups rejected; a poorly aligned domain drops your invoices into spam. Either way, the consequence shows up in revenue before it shows up in a security log.

And on inbound mail

The same requirement applies to what you receive: knowing what was set aside, why, and under which rule.

  • Blocking broken down by reason — spam, virus, size, content, malformed header — rather than a single global counter
  • Tracking for every message, inbound and outbound, with its verdict and delivery status
  • Preview of a quarantined message with no risk of execution, before delivering it or blocking its sender
  • The ARC protocol, which preserves the original authentication result when we enrich a message in transit

What the console already does

None of the above is a roadmap item: these are production features, presented here through the lens of accountability rather than filtering.

In the consoleWhat it amounts to
Multi-domain managementGovernance perimeter
Rules by user, group or domainPolicy hierarchy
MSP mode and end-customer modeDelegated administration
User-managed quarantineBounded autonomy
Personal lists and company listsBounded exceptions
Centralised signatures, legal notices, warning bannersOutbound governance
Automatic carbon copy of outgoing mailTraceability
DMARC reports received — and issuedAccountability
Hosting in FranceData sovereignty

Where to start

The order is not incidental: tightening before taking inventory means blocking your own mail.

1

Observe

Publish a monitor-only policy and collect the reports. No message is set aside; you discover who sends under your domains.

2

Align

Fix the legitimate sources that fail — a misconfigured provider produces exactly the same authentication failure as an impersonator.

3

Tighten

Move to quarantine, then to reject, once the inventory has settled. Only then does impersonation become impossible.

Our teams support that progression: configuration alerts, guidance on DNS records, and ongoing reading of the reports.

Ready to test e-securemail on your current mail platform?

Our experts review your current setup and run a demonstration tailored to your mail platform.