DMARC stops spoofing. It doesn't stop eavesdropping.
A domain with perfect DMARC enforcement can still have every message readable to anyone on the wrong network path. grimDMARC Hosted MTA-STS keeps the policy, the certificate and the TLS-RPT pipeline maintained for you — so that gap doesn't stay open just because nobody had time to manage a second DNS record and a hosted text file.
Get early accessThe problem: everyone pushes DMARC, almost nobody mentions transport
Every mailbox provider, every compliance checklist and every vendor conversation about email security leads with SPF, DKIM and DMARC. None of that says anything about whether the connection carrying the message was actually encrypted. Standard SMTP encryption is opportunistic — a network attacker between two mail servers can strip it, and the sending server will silently deliver the message in plain text rather than refuse to send it.
A domain sitting at p=reject can feel fully protected. It isn't, if MTA-STS and TLS-RPT were never set up — the mail just can't be forged. It can still be read.
The solution: grimDMARC Hosted MTA-STS
We host the policy file, keep it reachable over valid HTTPS, keep its mx: list in sync when your mail infrastructure changes, and manage the move from mode: testing to mode: enforce based on real TLS-RPT data instead of a guess. Publishing the DNS records is a one-time change; staying correct as things evolve is the part we take off your plate.
Be first in line when Hosted MTA-STS launches
We're onboarding early access customers ahead of general availability. Leave your email and we'll reach out when it's your turn.