Your business identity can be impersonated.
Weak DNS and email controls allow criminals to forge your invoices, redirect traffic or make legitimate email look suspicious.
WPfoss stops criminals impersonating your company and helps your team replace shared passwords in chat with controlled, auditable access. Two specialist services, fixed scope, fully documented.
Criminals can impersonate your domain from the outside. Former staff and uncontrolled shared passwords can expose your accounts from the inside. Either problem can cost money, interrupt operations and damage customer trust.
Weak DNS and email controls allow criminals to forge your invoices, redirect traffic or make legitimate email look suspicious.
Passwords stored in chat, spreadsheets and personal browsers make it difficult to know who can still access critical systems.
WPfoss is a specialist security practice. We protect the identity your customers trust and control the access your employees hold.
We secure SPF, DKIM, DMARC, CAA, Cloudflare, DNSSEC and your web firewall so criminals cannot impersonate your business or redirect your customers.
See DNS & Email SecurityWe deploy heylogin across your team, move credentials out of chat and spreadsheets, rotate exposed passwords, train staff and establish reliable joiner and leaver controls.
See heylogin Password ManagementYou have a business to run, not a stack of DNS records and access lists to master. WPfoss identifies the exposure, fixes each control in the correct order and gives you plain-language proof of what changed.
No open-ended retainer, no discovery phase that never ends. A clear path from where you are to a report you can hand to a board.
Check your domain free or book a review of your team's password and access practices.
We agree a fixed scope, then stage the work so email, websites and employee access keep working.
You receive documentation, before-and-after evidence and a repeatable process for reviewing access.
Grade any domain on DMARC, SPF, DKIM, DNSSEC, CAA and related public controls in about twenty seconds. No signup and no email address required.
Runs in your browser against public DNS. No signup, no email address needed.
WPfoss is a specialist security practice. We do two things: DNS and email security (SPF, DKIM, DMARC, CAA, Cloudflare and DNSSEC), and heylogin team password management. We do not do anything else.
A free tool that grades any domain in about twenty seconds. It runs in your browser against public DNS. No signup, no email. We keep a log of the domain and its grade. If your domain comes back clean, we tell you so.
If your domain has no DMARC record, or DMARC is set to p=none, then yes. It requires no hacking and no password. The attacker simply sends mail with your domain in the From address, and receiving servers have been given no instruction to refuse it.
Fixed scope, fixed fee, agreed before we start. We never bill by the hour, because hourly billing rewards the slowest supplier. heylogin licences are sold at the published list price of USD 79 per user per year with no markup.
WPfoss (WP FOSS LLC) is registered in Delaware, USA, and works with clients internationally.
Choose the service you need, or book a security review and we will help you identify the correct starting point.