Cyber insurance: does your email side hold up?

Cyber-insurance questionnaires ask pointed questions about your email. Enter your domain: we check what your underwriter can check on their own, and you leave with a dated report.

Free, no signup. Result in 15 seconds, with the full report (SPF, DKIM, DMARC, website).

What underwriters ask for in 2026

Underwriting questionnaires have grown longer and renewal increasingly feels like an audit. On the email and digital-identity side, cyber insurers generally expect:

Why email weighs so much in the file

Because that is where the money leaves. Business email compromise (BEC) — a fake email from the boss or a supplier asking to change a bank account number — is one of the leading small-business claim causes. A domain without DMARC in blocking mode makes that fraud trivial: anyone can write to your bookkeeper in your name. To an underwriter that is a risk measurable in 30 seconds, from the outside, without your permission. You may as well know what they see.

What this test checks — and what it does not

Our free report covers what is publicly verifiable: SPF, DKIM, DMARC and its mode, HTTPS, the SSL certificate and its expiry, security headers, sending blocklists, domain age and protection. That is exactly the angle an insurer or a business customer takes when assessing you from outside.

What we cannot see are your internal controls: whether MFA is truly enforced for everyone, whether your backups are tested, what runs on your workstations. Those answers stay yours — be wary of any tool claiming to “certify” your insurability from an external scan.

How to prove your controls without losing a week

Three levels, all usable the day someone asks for evidence:

  1. The dated report (free) — the check downloads as a PDF with the date: a snapshot of your posture at a precise moment.
  2. Continuous monitoring (free for one domain) — daily checks, history, and an alert if something degrades. That is what turns “it was fine in January” into “it is fine continuously”.
  3. The compliance dossier (Pro) — a dated document gathering your checks, your monitoring history and your incidents, ready to attach to an insurance or vendor questionnaire. See pricing.

Worth knowing: we are neither a broker nor an insurer, and every carrier has its own criteria — this is not insurance advice. The goal is simple: that you can answer the questionnaire's technical questions with evidence in hand.

Frequently asked questions

Can an underwriter really check my email on their own?

Yes, and without asking your permission: SPF, DKIM, DMARC, your certificate and your security headers are public information. That is also why several insurers and brokers run an external check before pricing a risk.

Which DMARC policy do insurers expect?

Generally at least quarantine, and increasingly reject. DMARC at p=none ticks the “we have a record” box but blocks nothing — the kind of nuance that gets noticed when a questionnaire is read closely.

Does Cyberbilan guarantee I will be insured or paid out?

No, and nobody can. We check and document the publicly verifiable technical side of your email and web security. Underwriting and claims decisions belong to your insurer.

I already have a policy. Is this still useful?

Often more than before you bought it: renewal is when the questions get harder, and a silent degradation (DMARC dropped during a provider change, an expired certificate) is exactly what continuous monitoring catches.

Is the test free?

Yes, no signup and no card. We only read public information (DNS, site headers). The dated report downloads as a PDF.

Helpful guides