Multi-Provider Enterprise Authentication Assessment
Executive Summary
Meridian Fintech Group ("Meridian") engaged Vaixus Technologies to assess its email authentication posture following three acquisitions completed over the past four years, each of which introduced its own email infrastructure, DNS conventions, and sending platform into the Meridian environment without a unifying integration standard. Meridian's IT leadership sought an independent inventory of its combined DNS and authentication footprint following an internal audit finding that no single team could produce a complete list of authorized senders for the root domain.
The assessment covered Meridian's root domain (Microsoft 365), the Google Workspace tenant retained from the LedgerPay acquisition, Amazon SES and SendGrid transactional streams, a legacy Mailgun integration inherited from the QuickTerm Lending acquisition, a developer-platform integration on Resend, and HubSpot marketing—seven distinct sending identities sharing a single root DNS zone.
Vaixus identified thirteen findings. Two are rated Critical: the root domain's SPF record has accumulated includes from every vendor onboarded since Meridian's first acquisition and now exceeds the RFC 7208 ten-lookup limit, and a Mailgun-authenticated sending stream inherited from the decommissioned QuickTerm Lending platform continues to deliver monthly account statements to a small population of legacy customers with no assigned internal owner.
This assessment finds no evidence of active compromise or unauthorized access. Every finding traces to the absence of a unifying sender-governance model across four merged organizations. Vaixus recommends establishing a centralized authorized-sender inventory as the foundational remediation step.
Environment Overview
Meridian's current footprint is the product of three acquisitions. Corporate correspondence for the parent organization is served by Microsoft 365 on the root domain. Each acquired or newly built business unit layered its own sending platform on top of this shared root DNS zone, resulting in seven identities sharing Route 53 as the authoritative DNS provider.
| Domain | Platform | Function |
|---|---|---|
| meridianfg.com | Microsoft 365 | Corporate mail, root DNS zone |
| ledgerpay.meridianfg.com | Google Workspace | Subsidiary correspondence |
| app.meridianfg.com | Amazon SES | Product notifications |
| billing.meridianfg.com | SendGrid | Invoices and receipts |
| legacy.meridianfg.com | Mailgun | Acquired platform mail |
| developers.meridianfg.com | Resend | Developer platform alerts |
| marketing.meridianfg.com | HubSpot | Lifecycle marketing |
Assessment Scope
- Root domain and subdomain DNS records across Route 53 and GoDaddy
- SPF, DKIM, and DMARC configuration across all 7 sending identities
- Post-acquisition integration state of LedgerPay Google Workspace
- Ownership of the legacy Mailgun sending stream
- DKIM key age, rotation cadence, and DMARC subdomain policy
- Application security of Meridian's payments platforms
- PCI-DSS or regulatory compliance certification
- Internal network security and corporate firewall configuration
- Endpoint security of employee workstations
- Mail content, data residency, or cross-border transfer analysis
Assessment Methodology
This assessment follows the Vaixus Email Infrastructure Assessment Methodology, adapted for a multi-entity, post-acquisition environment.
Structured interviews across IT, Engineering, Finance, and Marketing to reconstruct an as-built sender inventory.
Authoritative-record enumeration across the Route 53 zone and residual legacy zones to establish the configuration.
Controlled test messages sent through each of the seven sending identities with full header capture and alignment analysis.
Direct review of administrative consoles cross-referenced against internal ownership records (or their absence).
Consolidation of findings into severity-rated, business-impact-aligned recommendations.
Executive Findings Summary
Vaixus identified thirteen total findings across DNS configuration, vendor governance, and authentication posture. The highest severity findings requiring executive attention are summarized below.
Business Impact Analysis
The least security-conscious onboarding decision (an un-isolated SPF include) threatens the deliverability of the most business-critical mail stream (Microsoft 365) because all sending identities share one root DNS zone.
A real communication obligation persists on unmonitored infrastructure with no assigned owner, creating a risk that customer statements could silently fail if the legacy domain breaks.
A Meridian-branded subsidiary domain remains fully unenforced, increasing brand and phishing-impersonation exposure beyond what Meridian's IT leadership currently believes their DMARC investment provides.
Without a centralized sender inventory and onboarding checkpoint, each future acquisition or vendor relationship will likely reproduce the exact same categories of findings.
Remediation Strategy
Complete Route 53 migration for remaining legacy subdomains to unify DNS management. Assign named ownership and monitoring to the legacy Mailgun stream.
Isolate all vendor sending onto dedicated subdomains and correct root SPF record. Configure custom MAIL FROM for SES and complete SendGrid Return-Path. Add explicit subdomain DMARC policies.
Align LedgerPay DMARC policy with parent organization. Adopt a 12-month enterprise DKIM rotation cadence. Publish and enforce a centralized authorized-sender inventory.
Verification Strategy
The following methods are utilized to confirm successful remediation and closure of identified vulnerabilities across the enterprise infrastructure.
| DNS & SPF Resolution | SPF lint validation on root and all subdomains confirming $\le10$ lookups. |
| DMARC Enforcement | DMARC record and DKIM key inspection confirming subsidiary policy alignment. |
| Authentication Paths | Trace test with full alignment analysis ensuring both SPF and DKIM pass correctly. |
| Vendor Governance | Inventory accessible, owned, and referenced in onboarding checklists with documented rotation schedules. |

Download the Complete Case Study
This webpage summarizes the investigation logic. The complete 28-page PDF report contains full DNS trace evidence, detailed technical findings, risk prioritization tables, and structured remediation guidelines.
Download Representative Report (PDF)Related Deliverables
Ready to begin an assessment?
Submit a request and we will review your domain, scope the engagement, and respond within one business day.
Request Assessment