SPF, DKIM and DMARC prove a message left the right server. None of them prove a human being is who they say they are. The badge answers the question your recipient is actually asking.
Email authentication solved a machine problem. SPF says which servers may send for a domain, DKIM signs the message, DMARC tells receivers what to do when those checks fail. All three are necessary, all three are about infrastructure, and a determined impersonator simply registers a lookalike domain and configures them correctly on it.
The result is a message that passes every technical check and is still a fraud. The advice given to recipients — read the address carefully — does not survive contact with a domain that differs by one character, viewed on a phone, in a hurry.
That a named individual passed a credential review against a public register and controls this mailbox. It is a claim about a person, checked by a person, and published at a URL the recipient can open independently rather than a graphic pasted into a signature that anyone could copy.
For the professions where impersonation is most costly — clinicians discussing care, attorneys confirming wire instructions — that is the difference between asking someone to trust an address and giving them something they can check.
Your professional licence or registration number, plus a government ID to tie it to you rather than to whoever typed it in.
Clinicians are matched against the NPI registry; other professions against the relevant public licensing body.
Someone on our team confirms the match before the badge issues. Automated-only checks are trivially gamed.
A public verification page anyone can open — no account needed — to confirm the address belongs to you.
Clinicians whose patients receive results, scheduling and billing by email, and who are among the most impersonated senders in phishing. Attorneys in conveyancing, settlement and any matter where payment instructions travel by email — the single highest-value target for business email compromise. Consultants and accountants whose first contact with a client is a cold message that has to survive a credibility check.
A badge is an identity signal, not a security control. It does not encrypt anything and it does not stop a message being spoofed — it gives the recipient a way to check the sender that a spoofed message cannot reproduce.
That a named human passed our credential review and controls this mailbox. It is an identity check on the person, not a spam score on the message. SPF, DKIM and DMARC prove a message left the right server; they say nothing about who the sender is. The badge covers the gap between those two questions.
You submit your professional credential and a government ID. For clinicians we check the credential against the public NPI registry; for other professions we check the relevant public licensing register. A person on our team reviews the match before the badge is issued.
On your public verification page, which lives at a permanent link you can put in a signature, a profile or a directory listing. Recipients can open it without an account to confirm the address belongs to the person named on it.
Badges are available on Professional and Enterprise workspaces. Each professional activates their own badge for $0.99 a month, billed to them personally rather than to the organisation, so it stays with the individual if they move.
Badges are available on Professional and Enterprise, activated per person for $0.99 a month.
Create your free accountNo credit card. No trial clock.