kaimoku

Kuju Email · reference

Email security glossary.

Plain definitions for the security terms we use across Kuju Email. We'd rather teach you the words than hide them.

← Back to Kuju Email

DKIM— DomainKeys Identified Mail

A cryptographic signature attached to each outgoing message, verified by the recipient's mail server against a public key in your DNS.

In your message headers:

Authentication-Results: mx.kuju.email;
  dkim=pass header.d=example.com header.s=mail

DNS record (for domain admins):

mail._domainkey.example.com.  IN TXT  "v=DKIM1; k=rsa; p=MIGfMA0G..."

Why it matters: It proves the message wasn't altered between the sender and you.

DMARC— Domain-based Message Authentication, Reporting, and Conformance

A DNS policy telling receiving servers what to do when a message claiming to be from your domain fails SPF or DKIM checks — reject it, quarantine it, or just report it.

In your message headers:

Authentication-Results: mx.kuju.email;
  dmarc=pass action=none header.from=example.com

DNS record (for domain admins):

_dmarc.example.com.  IN TXT
  "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com"

Why it matters: SPF and DKIM detect impersonation; DMARC decides what to do about it.

Encrypted at rest

Data written to disk is encrypted, so a lost or discarded disk can't be read without the key. Kuju's stored mail and its servers' boot disks use our hosting provider's volume encryption, with keys managed by the provider rather than by Kaimoku — it protects against a lost disk, not against someone with access to the running system.

Why it matters: A server's physical security alone isn't enough — at-rest encryption is the second line of defense for stored mail.

End-to-end encryption

A class of encryption in which only the sender and recipient hold the keys — no server in between (not even your mail provider) can read the message. Kuju Email does not implement end-to-end encryption today; we use TLS in transit and at-rest encryption instead.

Why it matters: End-to-end encryption is a stronger guarantee for specific use cases, but it breaks server-side spam filtering, search, and shared-mailbox workflows. We've prioritized strong transport and storage encryption with full feature support.

Link-safety check

When you ask, the links in a message are checked against Google's continuously-updated lists of known phishing, malware, and unwanted-software sites. The check is optional and runs only on request.

Why it matters: Even a message that passes every other check can carry a link to a malicious site. This is the last check before you click.

MX records— Mail Exchange records

DNS entries that tell sending mail servers which servers handle incoming mail for your domain. When you point MX records at Kuju, mail addressed to your domain comes to us.

DNS record (for domain admins):

kuju.email.  IN MX 10  mx1.kuju.email.
kuju.email.  IN MX 20  mx2.kuju.email.

Why it matters: This is the switch that moves your email to Kuju. Until your MX records change, your mail still flows to your old provider.

Passkeys— WebAuthn

A cryptographic key pair stored on your device (or in a password manager) that replaces the password entirely. Signing in is a tap of your fingerprint or a face unlock.

Why it matters: There is no shared secret to steal in a phishing attack. Passkeys cannot be intercepted, replayed, or guessed.

Relay-hop trace

Mail messages pass through a chain of servers ("hops") on the way to you, and each hop adds a Received header. Inspecting the chain reveals where a message really came from.

In your message headers (read bottom-up):

Received: from mx-out.example.com (198.51.100.42)
  by mx.kuju.email; Mon, 12 May 2026 09:14:22 +0000
Received: from internal.example.com by mx-out.example.com;
  Mon, 12 May 2026 09:14:20 +0000

Why it matters: Some phishing attempts forge the visible "From" address but can't hide their true path. Tracing the hops surfaces those fakes.

Reputation checks

External services maintain lists scoring the trustworthiness of sending mail servers, IP addresses, and domains based on historical behavior. Incoming mail is scored against those lists.

Why it matters: Known spammers and compromised servers get caught even when their individual messages look innocuous.

Spam & phishing patterns

A library of structural signals — suspicious links, unusual formatting, common scam phrasing — that mail filters use to classify messages alongside the reputation score.

Why it matters: New scams get caught quickly when they reuse patterns from older scams, even when they come from new addresses.

SPF— Sender Policy Framework

A DNS record listing which mail servers are allowed to send mail for your domain. Receivers check this list when a message arrives.

In your message headers:

Authentication-Results: mx.kuju.email;
  spf=pass smtp.mailfrom=sender@example.com

DNS record (for domain admins):

example.com.  IN TXT  "v=spf1 include:_spf.kuju.email ~all"

Why it matters: Without SPF, anyone can claim to send mail from your address. With it, fakes get caught at the door.

TLS in flight

Encryption applied to the connection between mail servers and between your mail client and the server, so messages can't be read mid-transit.

Why it matters: No one on the network in between can read what's passing through, even when the message contents aren't end-to-end encrypted.

TOTP— Time-based One-Time Password

A six-digit code that changes every 30 seconds, generated by an authenticator app on your phone, entered alongside your password when signing in.

In your authenticator app:

123 456    (expires in 22 seconds)

Why it matters: A stolen password alone isn't enough to sign in as you. The attacker would also need physical access to your phone.

Virus stripping

Attachments are scanned with anti-virus engines before the message is delivered. Confirmed malicious files are removed automatically; the message body still arrives so you don't miss what was sent.

Why it matters: Most malicious attachments arrive as ordinary-looking documents. Stripping them keeps the message useful without putting your machine at risk.