hello@wpfoss.com
DNS, email & password security

Protect your business identity and the accounts behind it.

WPfoss stops criminals impersonating your company and helps your team replace shared passwords in chat with controlled, auditable access. Two specialist services, fixed scope, fully documented.

Fixed scope and feeStaged changesFull documentationNo lock-in

Businesses lose control in two places.

Criminals can impersonate your domain from the outside. Former staff and uncontrolled shared passwords can expose your accounts from the inside. Either problem can cost money, interrupt operations and damage customer trust.

Your business identity can be impersonated.

Weak DNS and email controls allow criminals to forge your invoices, redirect traffic or make legitimate email look suspicious.

The wrong people can retain access.

Passwords stored in chat, spreadsheets and personal browsers make it difficult to know who can still access critical systems.

Two security problems, handled properly.

WPfoss is a specialist security practice. We protect the identity your customers trust and control the access your employees hold.

DNS & Email Security

We secure SPF, DKIM, DMARC, CAA, Cloudflare, DNSSEC and your web firewall so criminals cannot impersonate your business or redirect your customers.

See DNS & Email Security

heylogin Password Management

We deploy heylogin across your team, move credentials out of chat and spreadsheets, rotate exposed passwords, train staff and establish reliable joiner and leaver controls.

See heylogin Password Management

You should not need to become a security expert to know your business is protected.

You have a business to run, not a stack of DNS records and access lists to master. WPfoss identifies the exposure, fixes each control in the correct order and gives you plain-language proof of what changed.

  • A free public-domain checker you can run before and after the work
  • Fixed scope and fixed fee agreed before work starts
  • Every technical change staged to protect uptime
  • Complete handover documentation with no lock-in
  • Honest recommendations when no work is required
How we work
Our promise to you
01 Fixed scope, fixed fee. Never by the hour.
02 Every change staged, so nothing goes offline.
03 Full documentation handed over. No lock-in.
04 If your check comes back clean, we tell you so.
05 We never publish proof we cannot evidence.

Take control in three steps.

No open-ended retainer, no discovery phase that never ends. A clear path from where you are to a report you can hand to a board.

1

See the exposure

Check your domain free or book a review of your team's password and access practices.

2

Secure the right things in order

We agree a fixed scope, then stage the work so email, websites and employee access keep working.

3

Keep control and proof

You receive documentation, before-and-after evidence and a repeatable process for reviewing access.

Check your public DNS and email security free.

Grade any domain on DMARC, SPF, DKIM, DNSSEC, CAA and related public controls in about twenty seconds. No signup and no email address required.

Runs in your browser against public DNS. No signup, no email address needed.

Know who can represent your business and who can access it.

  • Forged email claiming to be your business is refused.
  • Legitimate email is correctly authenticated.
  • DNS changes and certificate issuance are controlled.
  • Shared passwords are removed from chat and spreadsheets.
  • Staff access is granted and removed through a documented process.
  • Management can prove what is protected and who controls it.

Common questions

What does WPfoss do?

WPfoss is a specialist security practice. We do two things: DNS and email security (SPF, DKIM, DMARC, CAA, Cloudflare and DNSSEC), and heylogin team password management. We do not do anything else.

What is the free domain security checker?

A free tool that grades any domain in about twenty seconds. It runs in your browser against public DNS. No signup, no email. We keep a log of the domain and its grade. If your domain comes back clean, we tell you so.

Can someone really send email as my business?

If your domain has no DMARC record, or DMARC is set to p=none, then yes. It requires no hacking and no password. The attacker simply sends mail with your domain in the From address, and receiving servers have been given no instruction to refuse it.

How do you charge?

Fixed scope, fixed fee, agreed before we start. We never bill by the hour, because hourly billing rewards the slowest supplier. heylogin licences are sold at the published list price of USD 79 per user per year with no markup.

Where is WPfoss based?

WPfoss (WP FOSS LLC) is registered in Delaware, USA, and works with clients internationally.

Stop impersonation. Control access. Protect your business.

Choose the service you need, or book a security review and we will help you identify the correct starting point.