hello@wpfoss.com
Domain, email and cloud security

Make your business
impossible to impersonate.

Runs in your browser against public DNS. No signup, no email address needed.

We lock down your domain, email, DNS and cloud so criminals cannot forge your invoices, redirect your traffic, or walk in through an old password. See exactly where you stand in about twenty seconds.

πŸ‡ΊπŸ‡Έ WP FOSS LLC, DelawareπŸ”’ Security only, nothing elseπŸ“„ Fixed fee, never by the hour

The attack does not need your password.

Most owners find out their domain was wide open the day a customer pays an invoice they never sent. Without the right records in place, impersonating your business costs a criminal nothing and takes no hacking at all. Every month it stays unlocked is another month someone can send email as you, and you would never know.

A supplier pays a forged invoice that came from your exact domain.

Your quotes quietly stop arriving, because your own mail is treated as spam.

Someone points your domain elsewhere and your customers follow, with no warning.

The person who left in March still reads your Drive.

You find out the day it costs you money and standing.

Three things, done properly. Nothing you do not need.

We are a specialist practice, not a general agency adding security on the side. These three are the whole list.

Domain & Email Security

SPF, DKIM and DMARC set so receivers refuse mail that only pretends to be you.

How this works

Cloudflare, DNSSEC & WAF

Cloudflare and DNSSEC, so your traffic and mail cannot be quietly redirected.

How this works

heylogin Password Management

heylogin rolled out and actually adopted, so credentials leave WhatsApp for good.

How this works

Keeping your domain safe shouldn't require a degree in DNS

We know it is unsettling to suspect you are exposed and not be able to see where. You have a business to run, not a stack of acronyms to master. That is the job we take off your desk.

  • A free checker you can run against any domain, including one whose answer you already know, so you see we are right before you pay us anything.
  • ISACA-certified consultants, CISA and CISM. Two seats are reserved and shown honestly as vacant while we appoint them.
  • Before-and-after records on every engagement, verifiable by you with the same public tool.
  • WP FOSS LLC, Delaware. A practice that does security and nothing else.
How we work
Our promise to you
01 Fixed scope, fixed fee. Never by the hour.
02 Every change staged, so nothing goes offline.
03 Full documentation handed over. No lock-in.
04 If your check comes back clean, we tell you so.
05 We never publish proof we cannot evidence.

Three steps, and you are done worrying about it.

No open-ended retainer, no discovery phase that never ends. A clear path from where you are to a report you can hand to a board.

1

See where you stand

Run the free check, or book a scan, and get a plain-English grade in about twenty seconds.

2

We fix it in the right order

Staged changes, so your site and email never go dark. The order matters more than the speed.

3

Keep the proof

A before-and-after report you can hand to a board or client, and a checker you can re-run any time.

Not ready to talk? Check your domain first.

Grade any domain on DMARC, SPF, DKIM, DNSSEC, CAA and more in about twenty seconds. Plain English, no signup, no email. If it comes back clean, we will tell you so.

Runs in your browser against public DNS. No signup, no email address needed.

What "handled" looks like.

  • Forged email in your name is refused before it reaches anyone.
  • Your real email stops landing in spam.
  • Your DNS answers are signed and cannot be redirected.
  • The person who left in March no longer has a way in.
  • Your passwords are out of the group chat.
  • And when a client or auditor asks how you handle security, you send them a report instead of a shrug.

Common questions

What does WPfoss do?

WPfoss is a specialist security practice. We do three things: domain and email security (SPF, DKIM, DMARC, CAA), Cloudflare with DNSSEC and firewall configuration, and heylogin team password management. We do not do anything else.

What is the free domain security checker?

A free tool that grades any domain on DMARC, SPF, DNSSEC, CAA and more in about twenty seconds, in plain English. It runs in your browser against public DNS. There is no signup, no email required, and nothing is stored. If your domain comes back clean, we tell you so.

Can someone really send email as my business?

If your domain has no DMARC record, or DMARC is set to p=none, then yes. It requires no hacking and no password. The attacker simply sends mail with your domain in the From address, and receiving servers have been given no instruction to refuse it.

How do you charge?

Fixed scope, fixed fee, agreed before we start. We never bill by the hour, because hourly billing rewards the slowest supplier. heylogin licences are sold at the published list price of USD 79 per user per year with no markup.

Where is WPfoss based?

WPfoss (WP FOSS LLC) is registered in Delaware, USA, and works with clients internationally.

Find out where you stand. It takes about twenty seconds.

Run the free check against your own domain, or one whose answer you already know. Then, if you want it fixed properly, book a call and we will scope it at a fixed fee.