Skip to main content
Email security

Email security built in, not bolted on

Every Airfree Mail account ships with the full stack of modern email authentication and encryption — SPF, DKIM, DMARC, TLS, and ML-powered spam filtering — configured for you from day one.

SPF

Sender Policy Framework

SPF tells receiving mail servers which IP addresses are authorised to send email on behalf of your domain. Without it, anyone can forge your domain in the From: header — a technique used in phishing attacks.

Airfree automatically publishes the correct SPF record in your domain's DNS when you set up mail. You can extend it at any time to include other sending services.

Your SPF record (auto-configured)

v=spf1 include:mail.airfreeclouds.com ~all

DKIM signature in an email header

DKIM-Signature: v=1; a=rsa-sha256;
c=relaxed/relaxed; d=example.com;
s=airfree2026; h=from:to:subject:date;
bh=47DEQpj8HBSa+/TImW+5JCeuQeR...
b=abc123...
DKIM

DomainKeys Identified Mail

DKIM adds a cryptographic signature to every outgoing message. The receiving server looks up the public key in your DNS and verifies that the message body has not been tampered with in transit.

We generate a 2048-bit RSA key pair for your domain, publish the public key to DNS automatically, and sign every outgoing message. Key rotation happens annually with no downtime.

DMARC

Domain-based Message Authentication

DMARC ties SPF and DKIM together with a policy that tells receiving servers what to do when authentication fails.

p=none

Monitor

Start here. Authentication failures are reported to you via daily aggregate reports. No mail is rejected yet. Use this phase to understand your sending infrastructure.

p=quarantine

Quarantine

Messages that fail DMARC are moved to the spam folder instead of the inbox. Legitimate mail is not lost, but spoofed mail is suppressed.

p=reject

Reject

The strongest policy. Servers that receive a message failing DMARC reject it outright. Your domain cannot be spoofed. This is the target state for every domain.

Airfree sets p=none for new domains and guides you through tightening the policy via your control panel.

Encryption

In-transit and at-rest

TLS 1.3 in transit

All SMTP connections between mail servers use opportunistic TLS. Connections to our webmail and IMAP/SMTP endpoints require TLS 1.2 minimum; TLS 1.3 preferred.

AES-256 at rest

Mailbox data is encrypted at rest using AES-256. Encryption keys are managed in our HSM-backed key management service and rotated annually.

Spam & phishing

Multi-layer filtering

Inbound messages pass through four filtering layers before reaching your inbox.

1

RBL / DNSBL checks

Sending IP is checked against real-time block lists (Spamhaus, SURBL). Connections from listed IPs are refused at the SMTP gateway.

2

Header & envelope analysis

SPF, DKIM, and DMARC results are combined. Messages failing all three receive a high spam score.

3

Bayesian content filter

Message content is analysed against a trained corpus of spam and ham. Suspicious patterns raise the score.

4

ML threat classifier

A machine-learning model trained on recent phishing campaigns classifies messages in real time, catching novel threats that pattern matching misses.

Compliance

Built for regulated industries

GDPR

Email data for EU customers is processed and stored in Frankfurt, Germany. We act as a data processor under your instruction and provide a DPA upon request.

ISO 27001

We are building our mail infrastructure's information security management system to align with ISO/IEC 27001:2022, and working toward independent certification.

Data residency

Choose EU (Frankfurt) or AU (Sydney) data residency for your mail data. All data stays within your chosen region at rest.

Secure email from day one

Every Airfree Mail account gets the full security stack — no extra config required.