1. Official DAXP Automation channels
All legitimate communications from DAXP come exclusively from these channels. If you receive something from a different channel, assume it's fraudulent until verified.
daxpautomation.com
The only active domain. Any variant (daxp-automation, daxpautomation.es, daxp.es, etc.) is NOT us.
info@daxpautomation.com
security@daxpautomation.com — for security reports
Any email ending in a variant (gmail, hotmail, daxp-automation.com, etc.) is NOT DAXP.
+34 698 15 48 03 — Arturo Comesaña
The only number from which we will contact you. Nobody from DAXP will ever ask for passwords, verification codes or bank details through this channel.
linkedin.com/company/daxpautomation
Founder's personal profile: linkedin.com/in/arturocomesana
Any profile saying "DAXP" that doesn't link to these is not official.
2. How to verify an email claiming to be from DAXP
- Look at the sender's domain, not the display name. An attacker can set "DAXP Automation" as name, but the domain (what comes after the @) gives it away. Only legitimate if the domain is
@daxpautomation.com. - Hover over each link before clicking. You'll see the real URL below. If the link promises to take you to daxpautomation.com but the real destination is somewhere else, it's phishing.
- Verify the SPF/DKIM/DMARC signature. In Gmail you can "show original" and check that SPF, DKIM and DMARC say "PASS". In Outlook, "view message properties". Any "FAIL" is a red flag.
- If it has urgency or pressure, be suspicious. "Urgent bank account change", "pending invoices", "I need plant access today"... are classic fraud patterns. Call us at the official number before acting.
3. What DAXP will NEVER ask you for
- Passwords or 2FA codes for your systems
- Remote access without scheduling by phone in advance
- Payments to bank accounts different from those on the signed proposal (any "account change" is notified only by verified phone call)
- Upfront payments without a signed contract
- Personal data via WhatsApp or non-secure channels
- Installation of software outside what was agreed
4. Bank account policy
To avoid "intercepted invoice" fraud, DAXP applies this policy:
- The bank account is communicated only once in the signed contract
- Any account change requires double verification: signed email + call to the registered phone
- We never change bank accounts by email alone
- If you receive an email saying "we've changed our account", call us before paying
5. Security technologies implemented on this site
For your protection when browsing and sending us information:
- HTTPS enforced with HSTS preload
- TLS 1.3 on all connections
- Strict Content Security Policy blocking script injection and XSS
- SPF, DKIM and DMARC with
p=rejectpolicy on the email domain - DNSSEC signed on DNS to prevent cache poisoning
- CAA records limiting which certificate authorities can issue certificates for us
- Strictly necessary cookies: no third-party tracking, optional anonymous analytics
- GDPR/LOPDGDD compliance auditable
6. Report a fraud attempt or vulnerability
If you have received a suspicious communication claiming to be from DAXP, or you have detected a vulnerability in our systems:
- Email: security@daxpautomation.com (preferred) or info@daxpautomation.com
- Phone: +34 698 15 48 03
- Responsible disclosure policy: /.well-known/security.txt
We guarantee response in under 72 business hours. If you report a vulnerability in good faith and following the policy, we don't take legal action and we publicly acknowledge the researcher if they wish.
Page updated: 2026. Security is a continuous practice — this policy is reviewed every 6 months.