Access We Control,
Email You Can Trust
Two background jobs: controlling who can reach sensitive church information, and proving that email using the Preston Trail name is really ours.
Who can reach our information.
Four tools, one goal: the right people see only what their role needs — and lose access when they should.
One secure staff login
Microsoft Entra · SSOStaff sign in once and reach every connected app — no separate password per tool.
Fewer passwords, fewer ways in. Lock one account, and every app behind it is protected.
Access that starts and ends on time
SCIM · Auto account setupWhen someone is hired, changes roles, or leaves, access updates everywhere automatically.
Nothing stays on after someone leaves. Access appears on day one, gone on the last.
Only what your role needs
RBAC · Role-based accessAccess follows your role — Kids Check-In, Finance, Pastoral Care — not one person at a time.
A check-in volunteer never sees giving records; finance never sees counseling notes.
A locked vault for every other key
Keeper · Password managerFor tools outside the Microsoft login, Keeper is an encrypted vault — and lets staff share passwords safely. No sticky notes, no texting them around.
Every account gets a strong, unique password, and shared logins can be shut off in seconds. It covers the doors the main login can't.
How we secure our email — and share it with vendors.
Impersonating a church is a common scam — fake giving receipts, fake "urgent" notes from a pastor. These four settings in DNS (the public directory for our domain) prove which mail is really ours, block the fakes, and let us safely authorize the outside vendors that email on our behalf.
Proof the domain is ours
Verified domainBefore any provider will send email as prestontrail.org, we prove we own the domain. That proof is the foundation the rest is built on.
Only Preston Trail can act as prestontrail.org — shutting impersonators out at the source.
The list of who can send as us
SPF · Approved sendersA public list of every service allowed to send email as prestontrail.org. When we bring on a vendor — a giving platform, a bulk-email tool — they go on this list.
It's how we let a trusted vendor send in our name without ever handing over an account. Anyone not on the list can't pass as us.
A tamper-proof seal on every message
DKIM · SignatureEvery genuine message — ours or an authorized vendor's — carries an invisible signature proving it came from us and wasn't changed in transit.
We can give a vendor their own signing key, so their mail proves out as ours — while forged or altered email gets flagged or rejected.
The rule that rejects the fakes
DMARC · EnforcementTells every inbox what to do with mail that fails the checks above: bin it. It also reports back who's trying to send as us.
It turns SPF and DKIM from suggestions into enforcement — the backstop that makes impersonation actually bounce.
How it all fits together.
None of this shows on a Sunday morning — that's the point. Two jobs, running quietly in the background.
Information stays with the right people, only as long as their role needs it.
Email in our name — ours or an approved vendor's — can be proven genuine, and fakes get turned away.