hello@wpfoss.com

Stop anyone from sending email as your business.

We audit and fix SPF, DKIM, DMARC and CAA across every domain you own, then take you all the way to enforcement without losing a single real invoice. You end up with email criminals cannot forge and a report you can hand to a client.

What is almost certainly wrong right now

Most domains fail on at least two of these. Not through carelessness, but because email records are set once during a migration, nobody owns them afterwards, and every new tool that sends mail on your behalf quietly makes them worse.

  • DMARC is missing, or stuck at p=none, which watches impersonation happen and does nothing about it.
  • SPF exceeds the ten-lookup limit, which silently invalidates the whole record. Nothing warns you.
  • SPF ends in ~all instead of -all, telling receivers to accept forged mail but flag it. Most deliver it anyway.
  • Two SPF records exist because two providers were set up months apart. The standard allows one, so both are ignored.
  • No CAA record, so any certificate authority on earth can issue an HTTPS certificate for your domain.
  • Nobody reads the DMARC reports, so you have no idea who is currently sending mail as you.

What you get

  • A full audit of every domain and subdomain you own, not just the one you remembered to mention.
  • SPF rewritten to stay under the ten-lookup limit, with every legitimate sender accounted for.
  • DKIM signing verified or set up across every service that sends on your behalf.
  • DMARC moved through none, then quarantine, then reject in controlled stages, with reporting at every step.
  • CAA records published so only your chosen authorities can issue certificates for you.
  • A written before-and-after report in language you can forward to a board, plus a re-test you can run yourself.

How the engagement runs

  1. 1

    Audit and inventory

    We find every domain you own and every service sending mail as you. This routinely surfaces senders nobody remembered.

  2. 2

    Fix the foundations

    SPF and DKIM first, because DMARC cannot enforce anything until your real mail has something valid to pass against.

  3. 3

    Monitor at p=none

    We publish DMARC in reporting mode and watch for two to four weeks until every legitimate stream authenticates cleanly.

  4. 4

    Tighten to reject

    Once the reports are clean we move to quarantine, then reject. This is the step most providers never take.

  5. 5

    Hand over and verify

    You get the report, the records and a way to check the result yourself, any time.

What changes afterwards

Forged email claiming to be your business is refused by receiving servers rather than delivered. Your legitimate email stops being treated as suspicious, which usually improves deliverability. You can answer a client security questionnaire about email authentication truthfully and in writing. And someone is finally reading the reports, so you know who sends mail as your domain.

Start with the free domain security checker. It grades your domain on DMARC, SPF, DNSSEC and CAA in about twenty seconds, and it is the same tool you can use afterwards to verify our work. If it comes back clean, we will tell you so.

If you want the background before you talk to anyone, SPF, DKIM and DMARC explained covers how the three fit together, and DMARC policy: none, quarantine or reject covers the step most providers never take.

Frequently asked questions

Will this break our existing email?

That is the risk we are paid to manage, and exactly why we do not jump to enforcement. We fix authentication first, monitor until every real sender passes, then tighten.

We already have SPF. Is that not enough?

No. SPF alone does not survive forwarding, does not cover the From address people actually read, and tells receivers nothing about what to do when it fails. DMARC is what makes it count.

Do you charge by the hour?

No. We scope the work, quote a fixed fee, and carry the risk if it runs long. Hourly billing rewards the slowest supplier.

Our promise, on every engagement

  • Fixed scope, fixed fee, agreed before we start.
  • Every change staged, so your site and email never go offline.
  • Full documentation handed over. No lock-in, ever.
  • If your free check comes back clean, we will tell you, and we will not invent work.

Find out where you stand first.

Run the free check against your own domain, or one whose answer you already know. Then, if you want it fixed properly, we scope the work and quote a fixed fee.