Email security built in,
not bolted on
Every Airfree Mail account ships with the full stack of modern email authentication and encryption — SPF, DKIM, DMARC, TLS, and ML-powered spam filtering — configured for you from day one.
Sender Policy Framework
SPF tells receiving mail servers which IP addresses are authorised to send email on behalf of your domain. Without it, anyone can forge your domain in the From: header — a technique used in phishing attacks.
Airfree automatically publishes the correct SPF record in your domain's DNS when you set up mail. You can extend it at any time to include other sending services.
Your SPF record (auto-configured)
v=spf1 include:mail.airfreeclouds.com ~allDKIM signature in an email header
DKIM-Signature: v=1; a=rsa-sha256;
c=relaxed/relaxed; d=example.com;
s=airfree2026; h=from:to:subject:date;
bh=47DEQpj8HBSa+/TImW+5JCeuQeR...
b=abc123...DomainKeys Identified Mail
DKIM adds a cryptographic signature to every outgoing message. The receiving server looks up the public key in your DNS and verifies that the message body has not been tampered with in transit.
We generate a 2048-bit RSA key pair for your domain, publish the public key to DNS automatically, and sign every outgoing message. Key rotation happens annually with no downtime.
DMARC
Domain-based Message Authentication
DMARC ties SPF and DKIM together with a policy that tells receiving servers what to do when authentication fails.
p=noneMonitor
Start here. Authentication failures are reported to you via daily aggregate reports. No mail is rejected yet. Use this phase to understand your sending infrastructure.
p=quarantineQuarantine
Messages that fail DMARC are moved to the spam folder instead of the inbox. Legitimate mail is not lost, but spoofed mail is suppressed.
p=rejectReject
The strongest policy. Servers that receive a message failing DMARC reject it outright. Your domain cannot be spoofed. This is the target state for every domain.
Airfree sets p=none for new domains and guides you through tightening the policy via your control panel.
Encryption
In-transit and at-rest
TLS 1.3 in transit
All SMTP connections between mail servers use opportunistic TLS. Connections to our webmail and IMAP/SMTP endpoints require TLS 1.2 minimum; TLS 1.3 preferred.
AES-256 at rest
Mailbox data is encrypted at rest using AES-256. Encryption keys are managed in our HSM-backed key management service and rotated annually.
Spam & phishing
Multi-layer filtering
Inbound messages pass through four filtering layers before reaching your inbox.
RBL / DNSBL checks
Sending IP is checked against real-time block lists (Spamhaus, SURBL). Connections from listed IPs are refused at the SMTP gateway.
Header & envelope analysis
SPF, DKIM, and DMARC results are combined. Messages failing all three receive a high spam score.
Bayesian content filter
Message content is analysed against a trained corpus of spam and ham. Suspicious patterns raise the score.
ML threat classifier
A machine-learning model trained on recent phishing campaigns classifies messages in real time, catching novel threats that pattern matching misses.
Compliance
Built for regulated industries
GDPR
Email data for EU customers is processed and stored in Frankfurt, Germany. We act as a data processor under your instruction and provide a DPA upon request.
ISO 27001
We are building our mail infrastructure's information security management system to align with ISO/IEC 27001:2022, and working toward independent certification.
Data residency
Choose EU (Frankfurt) or AU (Sydney) data residency for your mail data. All data stays within your chosen region at rest.
Secure email from day one
Every Airfree Mail account gets the full security stack — no extra config required.