Domain & Email Security
SPF, DKIM and DMARC set so receivers refuse mail that only pretends to be you.
How this worksRuns in your browser against public DNS. No signup, no email address needed.
We lock down your domain, email, DNS and cloud so criminals cannot forge your invoices, redirect your traffic, or walk in through an old password. See exactly where you stand in about twenty seconds.
Most owners find out their domain was wide open the day a customer pays an invoice they never sent. Without the right records in place, impersonating your business costs a criminal nothing and takes no hacking at all. Every month it stays unlocked is another month someone can send email as you, and you would never know.
A supplier pays a forged invoice that came from your exact domain.
Your quotes quietly stop arriving, because your own mail is treated as spam.
Someone points your domain elsewhere and your customers follow, with no warning.
The person who left in March still reads your Drive.
You find out the day it costs you money and standing.
We are a specialist practice, not a general agency adding security on the side. These three are the whole list.
SPF, DKIM and DMARC set so receivers refuse mail that only pretends to be you.
How this worksCloudflare and DNSSEC, so your traffic and mail cannot be quietly redirected.
How this worksheylogin rolled out and actually adopted, so credentials leave WhatsApp for good.
How this worksWe know it is unsettling to suspect you are exposed and not be able to see where. You have a business to run, not a stack of acronyms to master. That is the job we take off your desk.
No open-ended retainer, no discovery phase that never ends. A clear path from where you are to a report you can hand to a board.
Run the free check, or book a scan, and get a plain-English grade in about twenty seconds.
Staged changes, so your site and email never go dark. The order matters more than the speed.
A before-and-after report you can hand to a board or client, and a checker you can re-run any time.
Grade any domain on DMARC, SPF, DKIM, DNSSEC, CAA and more in about twenty seconds. Plain English, no signup, no email. If it comes back clean, we will tell you so.
Runs in your browser against public DNS. No signup, no email address needed.
WPfoss is a specialist security practice. We do three things: domain and email security (SPF, DKIM, DMARC, CAA), Cloudflare with DNSSEC and firewall configuration, and heylogin team password management. We do not do anything else.
A free tool that grades any domain on DMARC, SPF, DNSSEC, CAA and more in about twenty seconds, in plain English. It runs in your browser against public DNS. There is no signup, no email required, and nothing is stored. If your domain comes back clean, we tell you so.
If your domain has no DMARC record, or DMARC is set to p=none, then yes. It requires no hacking and no password. The attacker simply sends mail with your domain in the From address, and receiving servers have been given no instruction to refuse it.
Fixed scope, fixed fee, agreed before we start. We never bill by the hour, because hourly billing rewards the slowest supplier. heylogin licences are sold at the published list price of USD 79 per user per year with no markup.
WPfoss (WP FOSS LLC) is registered in Delaware, USA, and works with clients internationally.
Run the free check against your own domain, or one whose answer you already know. Then, if you want it fixed properly, book a call and we will scope it at a fixed fee.