Connect your Email
Email is both the dominant attack channel and a configuration surface — SPF, DKIM, DMARC. TruSecure's email connector pulls security configuration and phishing-report data, so email controls are tested against tenant state.
What the connector pulls
| Source system | What TruSecure pulls | Feeds governance |
|---|---|---|
| Authentication | SPF, DKIM, DMARC policies and enforcement level | Control Library · CIS Controls email measures |
| Tenant configuration | External sender flags, impersonation protection, rules | Control Library · hardening measures |
| Phishing reports | User report volume, verdict outcomes | Incident and Resilience Workflows · detection triggers |
| Quarantine state | Blocked volume, false-positive handling | Evidence Automation · effectiveness metrics |
Evidence produced from Email data
One control test pulled from live Email state — not a manual export, not a screenshot, but a verified query result with provenance:
- Control tested
- DMARC at enforcement (p=reject) on owned domains
- Email source
- Microsoft 365 · 6 owned domains
- Test
- re-perform · DNS records vs enforcement policy
- Sample
- 6 domains · 5 at p=reject, 1 at p=quarantine
- Result
- pass with exceptions · 1 domain pending 30-day monitor window
- Evidence
- DNS + tenant query · timestamped 2026-08-22T09:05:31Z
- Export
- sealed · sha256:d4a8...7f2b
Setup and scope model
- Read-only, scoped permission
Connector requires read-only access to tenant configuration and report metadata. No write permissions, no ability to change policies, purge mail, or read message content.
- Data filtered by entity
Domains and tenants scoped to the entity context; groups with several mail tenants keep evidence per entity.
- Continuous sync
Configuration drift detected on each test — a policy loosened last night fails the control this morning.
Commercial packaging
Email connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.
How integration works
A demo with your actual Email environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.