1. Official DAXP Automation channels

All legitimate communications from DAXP come exclusively from these channels. If you receive something from a different channel, assume it's fraudulent until verified.

Official web domain

daxpautomation.com

The only active domain. Any variant (daxp-automation, daxpautomation.es, daxp.es, etc.) is NOT us.

Corporate email

info@daxpautomation.com

security@daxpautomation.com — for security reports

Any email ending in a variant (gmail, hotmail, daxp-automation.com, etc.) is NOT DAXP.

Founder's phone and WhatsApp

+34 698 15 48 03 — Arturo Comesaña

The only number from which we will contact you. Nobody from DAXP will ever ask for passwords, verification codes or bank details through this channel.

Official LinkedIn

linkedin.com/company/daxpautomation

Founder's personal profile: linkedin.com/in/arturocomesana

Any profile saying "DAXP" that doesn't link to these is not official.

2. How to verify an email claiming to be from DAXP

  1. Look at the sender's domain, not the display name. An attacker can set "DAXP Automation" as name, but the domain (what comes after the @) gives it away. Only legitimate if the domain is @daxpautomation.com.
  2. Hover over each link before clicking. You'll see the real URL below. If the link promises to take you to daxpautomation.com but the real destination is somewhere else, it's phishing.
  3. Verify the SPF/DKIM/DMARC signature. In Gmail you can "show original" and check that SPF, DKIM and DMARC say "PASS". In Outlook, "view message properties". Any "FAIL" is a red flag.
  4. If it has urgency or pressure, be suspicious. "Urgent bank account change", "pending invoices", "I need plant access today"... are classic fraud patterns. Call us at the official number before acting.

3. What DAXP will NEVER ask you for

  • Passwords or 2FA codes for your systems
  • Remote access without scheduling by phone in advance
  • Payments to bank accounts different from those on the signed proposal (any "account change" is notified only by verified phone call)
  • Upfront payments without a signed contract
  • Personal data via WhatsApp or non-secure channels
  • Installation of software outside what was agreed

4. Bank account policy

To avoid "intercepted invoice" fraud, DAXP applies this policy:

  • The bank account is communicated only once in the signed contract
  • Any account change requires double verification: signed email + call to the registered phone
  • We never change bank accounts by email alone
  • If you receive an email saying "we've changed our account", call us before paying

5. Security technologies implemented on this site

For your protection when browsing and sending us information:

  • HTTPS enforced with HSTS preload
  • TLS 1.3 on all connections
  • Strict Content Security Policy blocking script injection and XSS
  • SPF, DKIM and DMARC with p=reject policy on the email domain
  • DNSSEC signed on DNS to prevent cache poisoning
  • CAA records limiting which certificate authorities can issue certificates for us
  • Strictly necessary cookies: no third-party tracking, optional anonymous analytics
  • GDPR/LOPDGDD compliance auditable

6. Report a fraud attempt or vulnerability

If you have received a suspicious communication claiming to be from DAXP, or you have detected a vulnerability in our systems:

We guarantee response in under 72 business hours. If you report a vulnerability in good faith and following the policy, we don't take legal action and we publicly acknowledge the researcher if they wish.

Page updated: 2026. Security is a continuous practice — this policy is reviewed every 6 months.