Community Cybersecurity Initiative
Helping Businesses Identify Basic Email and Domain Security Risks
MRTECH Computer Support® periodically reviews publicly available business-domain security records as part of a community cybersecurity awareness effort. This review may include publicly observable email-authentication controls such as SPF, DKIM, and DMARC. A domain’s DNS configuration — the public records that tell the internet how to route and verify a business’s email — can provide public signals about how that email is authenticated, and those signals are visible to anyone who knows where to look, not just to MRTECH.
If your business received an email from MRTECH referencing this initiative, this page explains why, what was actually reviewed, and how you can verify it yourself.
What MRTECH Does Not Access
This is important, so we want to be direct about it. As part of the Community Cybersecurity Initiative, MRTECH does not access:
- Email accounts
- Passwords
- Computers
- Servers
- Private files
- Internal networks
- Private cloud environments
The review is based only on publicly available information — the same kind of DNS records that any organization publishes on the internet so that mail servers around the world know how to handle its email. This is not penetration testing, vulnerability scanning, or any form of intrusion or unauthorized access. It is a review of information that is already public.
How the Initiative Works
1. Public Record Review
MRTECH reviews publicly available domain and email-authentication information, such as a domain’s published SPF, DKIM, and DMARC DNS records.
2. Potential Risk Identification
If a record such as SPF, DKIM, or DMARC appears missing, incomplete, or potentially misconfigured, MRTECH may flag it for awareness. A missing or incomplete record does not mean a business has been hacked, breached, or is completely unprotected — it means there is a publicly visible gap that may be worth a closer look.
3. Business Notification
MRTECH may contact the organization using publicly available business contact information to explain what was observed and why it may matter.
4. No Obligation
The notification is informational. The recipient is not required to purchase services from MRTECH. A business can verify or correct the issue independently, work with its existing IT provider, or contact MRTECH if it would like help.
Did You Receive an Email From MRTECH?
You may have received a message from MRTECH because our review identified a publicly observable email-authentication configuration that may deserve your attention. The message should describe what we observed and give you enough information to verify the finding independently — for example, by checking your own domain’s DNS records or asking your current IT provider to take a look.
We understand that an unexpected email about your domain’s security can raise questions. That’s the reason this page exists: so you have a straightforward place to understand why you were contacted, what was actually reviewed, and what your options are — with no pressure and no obligation.
If anything about a message you received seems unclear or you’d simply like to confirm it’s legitimate, contact MRTECH directly and we’re happy to walk through it with you.
What We May Review
These are the three publicly visible email-authentication records most often involved. Our Email Security page goes into more detail on how MRTECH helps businesses configure and maintain them on an ongoing basis.
SPF
Helps identify which mail systems are authorized to send email for a domain.
DKIM
Helps verify that an email message was signed by an authorized sending system and was not altered in transit.
DMARC
Provides a policy and reporting framework that builds on SPF and DKIM and can help reduce unauthorized use of a domain for email impersonation.
To be clear about what these findings do and don’t mean: a missing DMARC record does not mean an organization has been breached, and a missing SPF record does not automatically mean email has been compromised. Public DNS findings represent one part of an organization’s overall security posture — not the whole picture. Want to see where your own domain stands? Our free Domain & Email Audit checks these same records and explains the results in plain language.
Important Disclaimer
This public review is informational. It is not a penetration test and not a comprehensive cybersecurity assessment, and it does not guarantee that a domain is secure or insecure. Findings can change over time as DNS records and provider configurations change on either side. Organizations are encouraged to verify any finding with their own IT or security provider where appropriate. If you’d like a broader, no-obligation look at your overall technology risk, MRTECH’s free 5-Minute Risk Assessment is another way to get a general sense of where things stand.
Would You Like Help Reviewing Your Domain?
If you received a notification from MRTECH and would like help understanding the finding, contact us. There is no obligation to purchase services.