DNS & Email Security
Multi-domain audit, SPF, DKIM, DMARC and CAA remediation, Cloudflare configuration, DNSSEC, web firewall controls, staged enforcement, report and re-test.
We price every engagement as a scoped job, never by the hour. Charging by the hour rewards the slowest supplier and turns specialist judgement into a commodity. We scope the work, quote a fixed fee, and carry the risk if it takes longer than we expected.
The one fixed number on this site. Sold at the published list price, with no markup.
heylogin Enterprise licences are billed annually at the published list price with no WPfoss markup. Deployment, credential migration, password rotation, staff training and optional ongoing management are separate fixed-fee services quoted after a security review. See how the heylogin rollout works.
Each is scoped on a call, then quoted as a fixed fee. That is a deliberate position: the work has genuinely variable effort, so a quote is honest rather than evasive.
Multi-domain audit, SPF, DKIM, DMARC and CAA remediation, Cloudflare configuration, DNSSEC, web firewall controls, staged enforcement, report and re-test.
heylogin licences, team-wide rollout, credential migration and rotation, access structure, staff training, joiner and leaver controls, and optional ongoing management.
Because the work has genuinely variable effort. A single-domain business with one mail provider is not the same job as a group with eleven domains and four senders nobody remembered. Quoting per engagement is honest rather than evasive, and it means you are not anchored to a floor price that would not apply to you.
No. We scope the work, quote a fixed fee, and carry the risk if it runs long. Hourly billing rewards the slowest supplier and turns specialist judgement into a commodity.
USD 79 per user per year, billed annually. Add a seat when someone joins and it is prorated for the rest of the year. Our own deployment work is quoted separately as a fixed fee.
No. They are sold at the published list price of USD 79 per user per year. We make our money on the deployment work, not on your licence bill.
We tell you so, and we do not invent work. Not inventing work is a promise on every engagement, whether or not a free check is involved.
No. Every change is staged. DMARC moves through reporting mode before enforcement, DNSSEC is enabled registry-side first, and firewall rules run in log-only mode before they are enforced. The order is the part you are paying for.
The check tells you what is actually wrong, which means the security review is about your real situation rather than a generic proposal.