DMCN replaces email's 1982 trust model with cryptographic identity: a message from an unverified sender is never delivered, and a message from a verified sender cannot be forged. Your mail is encrypted before it ever reaches us — and the keys stay with your organization, never with us.
lost to business email compromise in 2025 alone — roughly $123,000 per reported incident.
of unwanted email technically passed SPF, DKIM and/or DMARC. Authentication verifies domains — it has never verified people.
of 81.6 million real emails were end-to-end encrypted, in the largest study ever done. Pushing key custody onto end users killed every previous attempt.
The tools you already pay for filter fraud. They cannot make it impossible — the protocol underneath has no idea who anyone is. That is the part we replaced.
Every DMCN message carries its sender's cryptographic signature, verified before delivery. Impersonating your CEO, your bank or your suppliers isn't detected and filtered — it's structurally impossible.
Mail is end-to-end encrypted, and on a managed domain your own administrator — not us, not each employee — is the custodian. A lost laptop or a departure is recovered by your org in minutes. We can't read anything, ever.
The bridge keeps you emailing Gmail, Outlook and every legacy address from day one, with SPF, DKIM and DMARC alignment handled for you. Mail between DMCN inboxes is always end-to-end encrypted.
You keep your own DNS as the trust root and consent is mutual and revocable — we hold no zone and no keys, so we are structurally incapable of impersonating your domain or being compelled to hand over your mail.
Encrypted email failed for 25 years because key custody was dumped on end users. On a managed domain, your administrator is the custodian — never each employee, and never us. The provider can't read the mail; your organization can always recover it.
Publish two DNS records at your own domain. Your DNS stays the root of trust — we never touch your zone.
Your domain authorizes us to serve it; our fleet accepts your domain. Two explicit cryptographic consents — either side can revoke.
Your admin mints each mailbox and pairs employees' devices with a short verification code. Keys stay inside your organization.
Legacy mail flows through the bridge with authentication alignment handled for you. Mail between DMCN inboxes is end-to-end encrypted from the first message.
Your DNS stays the root of trust, consent is mutual and revocable, and your address book survives us. That's not a contract clause — it's the architecture.
Why sovereignty buyers pick DMCNWe don't ask you to believe the pitch — we ask you to watch the drills pass on your own domain, with your own admin holding the keys. Success criteria agreed up front, in writing.
Yes — that's what the bridge is for. Your team keeps emailing every normal address from day one, and we handle SPF, DKIM and DMARC alignment on outbound so your mail lands in inboxes. Every counterparty who adopts DMCN upgrades that channel to end-to-end encryption automatically. You buy it for what it does inside your organization today; the network effect is upside, not a prerequisite.
That's the headline feature, not the fine print. On a managed domain your admin custodies the keys: a lost laptop is re-paired in minutes, and offboarding is a rotation that locks every device the departed employee holds out of the mailbox immediately. This is exactly the key-management problem that sank S/MIME and PGP — DMCN was designed around it.
No. Mail is encrypted on your devices, our servers hold no key material — not even encrypted copies — and there is nothing on our side to read, leak or hand over. On a managed domain your own administrator can recover accounts; we never can. The two-sided guarantee: the provider can never read the mail, your organization's administrator can.
No, and we won't pretend otherwise. Mail crossing the bridge to legacy email is protected in transit (TLS), like all email today — that's the floor, never the ceiling. Mail between DMCN inboxes never touches the bridge and is always end-to-end encrypted. If you want us out of the trust path entirely, you can run your own bridge.
Every message is signed at composition — tamper-evident and non-repudiable, which is stronger evidence than ordinary email. Admin key custody answers recovery; for retention, encrypted archive-on-send to an organization archive key is designed and on the roadmap, and design partners shape it. We'll be straight with you about what's built versus planned.
The protocol is open and identity records are self-certifying: your keys, your domain and your mail remain yours and remain verifiable without us. No incumbent provider can make that claim. You can also export everything at any time.
One email starts the conversation. Thirty days proves it on your own domain.
Book a design-partner pilot