SPF-Report.com
United States · spf-report.com · 1 vendor
InterNexum GmbH is a German company that provides an all-in-one domain risk monitoring platform. Their services include DMARC, SPF, DKIM, DNS-SEC, TLS, and domain monitoring to secure domain and email security, reduce cyber attacks, and increase email delivery rates.
Resilience scores
- Digital Sovereignty: 100
- Digital Resilience: 6
Technology vendors
- Amazon Web Services (aws) — Technology — United States
Services catalogue
2 services in catalogue across 2 categories; runs on 1 sub-vendor.
- SPF Management / Email Security
- SPF-Report.com
Insights
Last updated 2026-07-30 · revision 6
1 direct vendor, 57 subvendors
Direct vendors by controlling owner country (sample)
- United States: 1
Subvendors by controlling owner country (sample)
- Japan: 1
- Australia: 1
- Sweden: 1
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
SPF-Report.com exhibits medium migration readiness, leaning towards high, primarily due to its highly modern and cloud-native internal tech stack. The use of Docker and Kubernetes ensures that applications are containerized and largely portable, facilitating migration or refactoring efforts within a cloud environment. The adoption of Python, Node.js, React, and Terraform further supports agile development and infrastructure as code, which are key enablers for efficient migrations. However, significant challenges exist. There is a high degree of vendor lock-in to Amazon Web Services (AWS) for the core infrastructure. While applications are portable, migrating the entire infrastructure and associated services away from AWS to a different cloud provider would be a substantial and complex undertaking. Additionally, unaddressed regulatory compliance requirements (GDPR, SOC2, ISO 27001) and data residency considerations introduce significant planning overhead and potential blockers for any major migration, especially those involving cross-border data transfers or new environments requiring specific certifications. The financial capacity to fund a large-scale migration is also unknown.
Compliance
4 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
Email security services typically process personal data including email addresses, sender information, and potentially message metadata. If SPF-Report.com processes any personal data of EU/EEA residents (which is highly likely for an email security service), GDPR applies regardless of US headquarters. Non-compliance carries severe penalties up to 4% of annual turnover or €20M. Risk is high due to the global nature of email services and likelihood of processing EU personal data.
ISO 27001 (source) — Assessment Required
ISO 27001 is relevant for information security management in email security services. While not legally mandated, it's often required by enterprise customers and demonstrates systematic approach to information security. Risk is medium as lack of certification could impact competitive position and customer trust but doesn't carry legal penalties.
CAN-SPAM Act — Assessment Required
As a US-based email-related service, CAN-SPAM Act compliance is relevant if the company sends commercial emails. Violations can result in penalties up to $43,792 per email. Risk is medium as email security companies typically send service-related communications that may include promotional content.
Financials
Three-year financials
- null:
- null:
- null:
Financial Resilience Score: null/10
No financial report content was successfully retrieved or parsed from SPF-Report.com. The research process described in the prompt consisted solely of attempted web fetches and search retries that did not return any substantive financial data, disclosures, or company metrics. As a result, no meaningful resilience assessment can be constructed from the available information. A score and qualitative reasoning would require at minimum revenue figures, profitability data, balance sheet items, or operational disclosures from the subject company.
Risk factors: No financial data was retrievable from the source report, Unable to verify company identity, size, or sector, Absence of disclosed financials prevents any creditworthiness or resilience evaluation
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.