We store the records you use to create the Custom Sender Address in the same manner as the rest of your data - in a Microsoft Azure Database with significant access restrictions.
We do need to add these records to outgoing emails for the verification to work properly.
As a result, if a recipient's inbox is compromised, the email records may also be.
If you believe that your email records may have been used fraudulently, please follow the below instructions:
- Alert us at support@plus.live with a screenshot of the Custom Sender Address table - we can ensure that the records have been removed from systems we have access to
- Delete the records from Forecast (Admin Menu -> Setup -> Custom Sender Address -> Delete Domain)
- Delete the records from your Domain provider's toolkit.
- You can go through the setup again to create new keys and re-secure your email address.
We would recommend waiting from the all-clear from the compromised party before doing this.
Need any more information?