Email security

Anyone can send an invoice in your company's name.

Unless your domain is configured to stop them. Most Kenyan businesses have no SPF, a broken DKIM setup and no DMARC at all — which means a stranger can email your customers as you, with your bank details swapped for theirs. The same misconfiguration is why your own quotes keep landing in spam.

We introduce you to a freelancer who has done this work before, and take no commission. You engage them directly.

The work

Four records. That's the whole job.

Email security is not a product you buy. It is a handful of DNS records that have to be correct, consistent and monitored. Here is what each one does.

MX — where your mail is delivered
The record that points your domain at your mailbox provider. Wrong or duplicated MX records mean mail bounces, arrives late, or quietly goes to an old provider you stopped paying for. We audit what is live, remove what is stale, and set the correct priorities.
SPF — who is allowed to send as you
A list of the servers permitted to send email using your domain. The common failures: no SPF at all, two SPF records on one domain (invalid — receivers ignore both), or a record that has silently dropped a tool you actually send from, so your newsletter and invoices fail authentication.
DKIM — a signature that can't be forged
Every message gets signed with a private key held by your mail provider; the matching public key sits in your DNS. If a single character of the message is altered in transit, the signature breaks and the receiver knows. Publishing the key is the easy part — keeping it valid through a provider migration is where it usually breaks.
DMARC — the policy, and the reports
DMARC tells the receiving server what to do when a message claiming to be from you fails SPF and DKIM: monitor it, quarantine it, or reject it outright. It also emails you daily reports of every server sending in your name. Those reports are how you discover the spoofing you never knew about — and they are why DMARC is a monthly discipline, not a one-off setup.
How it works

Introduced, not auctioned.

You don't sift through profiles or collect bids. We introduce one specialist who has done this work before, and they follow a fixed order — because jumping straight to a strict DMARC policy is how businesses end up blocking their own invoices.

01 · introduction

We introduce the specialist

You tell us your domain and what you send mail with. We introduce a freelancer whose email-security work we have checked — by name, by email, at no charge. From there you agree scope and price with them directly.

02 · audit

See what's actually published

They read the live MX, SPF, DKIM and DMARC records on your domain and write down every system that legitimately sends mail as you — your mailbox provider, your invoicing tool, your newsletter, your website forms.

03 · fix

Correct the records

One valid SPF record covering every real sender. DKIM signing switched on and published. DMARC started at monitoring only, so nothing legitimate gets blocked while evidence is gathered. Every change is written down before it is made.

04 · enforce

Read the reports, then tighten

DMARC reports arrive as raw XML that no business owner should have to read. A few weeks of them become a plain-language summary. Before the policy moves to quarantine and then to reject, every real sender must be confirmed passing — and you sign that step off in writing.

05 · monitor

Keep it that way

Records drift. A new marketing tool gets added, a provider rotates a key, someone edits DNS. Monthly monitoring catches it before your customers notice. This part is an ongoing arrangement — agree it with your specialist in writing at the start, and keep your own copy of the change record so you are never dependent on one person.

Who needs this

If you invoice by email, this is your problem.

You send invoices or quotes by email

Invoice fraud works by impersonating a supplier your customer already trusts. Without DMARC enforcement, nothing stops it.

Your email lands in spam

Gmail and Microsoft 365 now require authentication for bulk senders. Unauthenticated mail gets filtered — or refused.

You just moved provider or website

Migrations are where DKIM keys and SPF entries get lost. If mail started misbehaving after a change, this is usually why.

Access & accountability

You keep the keys to your own domain.

This is the one service where you would normally be asked to hand a stranger control of your DNS — the same records that run your website and your email. You aren't.

No credentials change hands
The specialist writes out the exact records to add, change or remove — hostname, type, value, TTL — and you apply them, or approve them one at a time. If you would rather grant temporary delegated access at your registrar, that is your call, and it is revoked when the work is signed off.
Every change is written down
You get a record of what your DNS looked like before, what changed, and why. If something breaks a month later, nobody has to guess. If you ever move to a different provider, that document goes with you — it is yours.
Nothing goes to enforcement without your sign-off
Moving DMARC to p=reject is the step that can silently stop your invoices from arriving. It should never happen on someone else's judgement alone. Ask to see the report summary, confirm every real sender passes, and approve the change in writing.
What Ujiajiri is — and isn't
We are an introduction service. We check a freelancer's email-security track record before we put their name in front of you, and we charge you nothing. We are not a party to the work: scope, price, timelines and any ongoing monitoring are agreed between you and the specialist. If an introduction doesn't work out, tell us — a freelancer who doesn't deliver stops getting introductions.
Next step

Find out what your domain is currently telling the world.

Tell us your domain and what you send email with. We introduce you to a specialist who audits your records and explains what they find — in plain language, not screenshots of DNS. No credentials handed over. Free to ask, and we take no commission.

Prefer to read first? Start with DNS records every freelancer must know.