Anti-phishing

Email authenticity

Encryption protects what is stored. It does not stop someone from writing you an email that looks like it came from us. This page tells you exactly how to tell a real DRIVUNO message from a forgery — and shows the live state of our sender-authentication records so you can check our side too.

Live sender-authentication check

Checking DNS…
Resolving over DNS-over-HTTPS…

You can reproduce this yourself, from your own machine, with dig TXT drivuno.com and dig TXT _dmarc.drivuno.com. We report what DNS says, not what we would like it to say.

The only addresses we send from

Every genuine DRIVUNO email comes from the drivuno.com domain, and passes DKIM. If the visible address is right but the message fails authentication, your mail client will usually say so — look for “unauthenticated”, a question-mark avatar in Gmail, or the raw Authentication-Results header.

noreply@drivuno.com
security@drivuno.com
hello@drivuno.com
support@drivuno.com

What DRIVUNO will never do

Ask for your master password, recovery phrase, PIN, or 2FA code — by email, chat, or phone.

Ask you to “re-verify” your vault by entering your password on a page we linked to.

Send you an attachment you must open to keep your account.

Contact you from a look-alike domain such as drivuno-support.com, drivuno.net, or drivunо.com (Cyrillic “о”).

Why this matters more here than elsewhere

DRIVUNO is zero-knowledge: we cannot reset your master password or read your vault, and neither can an attacker who breaks into our servers. That makes you the target. Phishing is the realistic path to a DRIVUNO account, which is why passkeys, step-up MFA, and this page exist.

How to verify a suspicious message in 30 seconds

  1. Do not click anything in the email. Open drivuno.com by typing it, and check your in-app notifications.
  2. Open the message headers and look for dkim=pass header.d=drivuno.com and spf=pass. A forgery almost never has both.
  3. Check the sender against the list above, character by character — look-alike domains are the norm.
  4. Forward anything suspicious to security@drivuno.com as an attachment (that preserves the headers), then delete it.

Related: Vulnerability disclosure · Code integrity · security.txt

Encrypted on your device · upload in 1 click
Upload