hello@wpfoss.com

The acronyms, explained in plain English.

You should not need a DNS degree to protect your own name. These are the controls that stop impersonation, what each one actually does, and the order to set them in.

Or skip the reading and check your domain, it takes about twenty seconds.

Email securityDMARCSPF

How to stop email spoofing: the complete sequence

The full path from an unprotected domain to one nobody can forge: inventory your senders, then SPF, DKIM, DMARC at none, the reports, quarantine, reject. In the order that does not take your own email down.

Read the article →
Password managementheylogin

heylogin vs 1Password vs Bitwarden: choosing a team password manager

A straight comparison of what the three cost, how each one signs you in, and which team each actually suits. Written by a heylogin partner, with that stated up front.

Read →
CloudflareDNSSEC

Cloudflare WAF, DNSSEC and CAA: what to switch on

Most domains sit on Cloudflare half configured. What the WAF is really for, and the settings worth turning on before you pay for a plan.

Read →
CAADNS

The CAA record explained: who can issue your certs

Without a CAA record, any certificate authority on earth can issue an HTTPS certificate for your domain. It is free, takes minutes, and almost nobody has one.

Read →
DMARCEmail security

DMARC policy: none, quarantine or reject

What p=none, p=quarantine and p=reject actually do, why most domains are stuck at none, and the staged path to enforcement that does not take your own email down.

Read →
Email securityDMARC

What building a domain checker taught us

We built a tool to grade any domain on DMARC, SPF, DNSSEC and CAA. The first thing it caught was a fault in our own scoring.

Read →
Email securityDMARC

SPF, DKIM and DMARC explained, without the acronyms

The three records that stop anyone sending email as your business, what each one does, and why two of them are not enough on their own.

Read →
DNSSECDNS

What is DNSSEC, and why the order matters

DNSSEC signs your DNS answers so they cannot be forged in transit. What it protects against, and why enabling it in the wrong order takes a domain offline.

Read →

Stop impersonation. Control access. Protect your business.

Choose the service you need, or book a security review and we will help you identify the correct starting point.