hello@wpfoss.com

Stop criminals impersonating your business or redirecting your customers.

We secure the systems that establish your identity online: email authentication, DNS, certificate controls and web traffic protection. Every change is staged to protect uptime and documented for handover.

The risks we find

Most domains fail on at least two of these. Not through carelessness, but because email records are set once during a migration, nobody owns them afterwards, and every new tool that sends mail on your behalf quietly makes them worse.

  • DMARC is missing, or stuck at p=none, which watches impersonation happen and does nothing about it.
  • SPF exceeds the ten-lookup limit, which silently invalidates the whole record. Nothing warns you.
  • SPF ends in ~all with no enforcing DMARC behind it, so nothing actually refuses forged mail. With DMARC at reject the soft fail is fine; without it, it is not.
  • Two SPF records exist because two providers were set up months apart. The standard allows one, so both are ignored.
  • No CAA record, so any certificate authority on earth can issue an HTTPS certificate for your domain.
  • Nobody reads the DMARC reports, so you have no idea who is currently sending mail as you.
  • DNSSEC is switched off, so your DNS answers are unsigned and can be forged in transit.
  • Domains are scattered across several registrars and DNS accounts, so nobody can say what is configured where, or who controls each one.

Start with the free domain security checker. It grades your domain on DMARC, SPF, DNSSEC and CAA in about twenty seconds, and it is the same tool you can use afterwards to verify our work. If it comes back clean, we will tell you so.

Email authentication: SPF, DKIM and DMARC

Together, these records decide whether a receiving server accepts mail that claims to come from you. SPF lists the servers allowed to send on your behalf, DKIM signs each message so it cannot be altered in transit, and DMARC ties both to the From address a person actually reads and tells receivers what to do when the check fails.

We rewrite SPF to stay under the ten-lookup limit that silently invalidates an over-long record, verify or set up DKIM signing on every service that sends as you, then publish DMARC in reporting mode. Only once every legitimate stream authenticates cleanly do we move the policy to quarantine and then to reject. Enforcement without that monitoring period is how providers lose real invoices, which is why we do not skip it.

SPF, DKIM and DMARC explained covers how the three fit together, and DMARC policy: none, quarantine or reject covers the step most providers never take.

DNS and certificate protection: DNSSEC and CAA

Email authentication is only as trustworthy as the DNS that publishes it. DNSSEC signs your DNS answers so they cannot be forged in transit, and a CAA record names the certificate authorities allowed to issue an HTTPS certificate for your domain. Without CAA, any authority on earth can issue one.

The order matters more than the speed. The registry DS record must be published and confirmed before the DNS side is switched on; get that sequence wrong and the whole domain goes dark, website and email together, with no obvious cause. That sequencing is most of what you are paying for. See what DNSSEC is and the CAA record explained.

Cloudflare migration and configuration

Where it helps, we move DNS onto Cloudflare with no downtime and no lost records. Every existing record is inventoried and replayed before nameservers change, so mail routing, verification records and subdomains survive the move intact.

Cloudflare is tooling we use to deliver DNS and email security, not a product we resell. We earn nothing from your Cloudflare bill, and where the free tier is enough we say so.

Web firewall, rate limiting and bot controls

The same DNS work puts your web traffic behind a firewall worth configuring. We tune WAF rules, rate limits and bot controls to your real traffic rather than a default template, and run every rule in log-only mode first so legitimate customers are never the ones blocked.

The Cloudflare WAF and DNSSEC setup guide walks through the configuration if you would rather do it yourself.

What you receive

  • A full audit of every domain and subdomain you own, not just the one you remembered to mention.
  • SPF rewritten to stay under the ten-lookup limit, with every legitimate sender accounted for.
  • DKIM signing verified or set up across every service that sends on your behalf.
  • DMARC moved through none, then quarantine, then reject in controlled stages, with reporting at every step.
  • CAA records published so only your chosen authorities can issue certificates for you.
  • DNSSEC enabled in the correct sequence, registry side confirmed before the DNS side is switched on, so the domain never goes dark.
  • Where you want it, migration onto Cloudflare with no downtime and no lost records, plus firewall and rate-limit rules tuned to your real traffic rather than a default template.
  • A written before-and-after report in language you can forward to a board, plus a re-test you can run yourself.

How the engagement runs

  1. 1

    Audit domains, senders, registrars, DNS zones and Cloudflare accounts

    We find every domain you own, every service sending mail as you, and who controls each registrar and DNS account. This routinely surfaces senders and domains nobody remembered.

  2. 2

    Correct SPF, DKIM and the underlying DNS records

    SPF and DKIM first, because DMARC cannot enforce anything until your real mail has something valid to pass against.

  3. 3

    Stage DMARC from monitoring to enforcement

    We publish DMARC in reporting mode and watch for two to four weeks until every legitimate stream authenticates cleanly, then move to quarantine, then reject. This is the step most providers never take.

  4. 4

    Enable DNSSEC, CAA and web protection in the correct order

    The registry DS record is published and confirmed before the DNS side is switched on, so the domain never goes dark. Firewall and rate-limit rules run in log-only mode before they are enforced.

  5. 5

    Re-test, document and hand over

    You get the report, the records and a way to check the result yourself, any time.

What changes afterwards

Forged email claiming to be your business is refused by receiving servers rather than delivered. Your legitimate email stops being treated as suspicious, which usually improves deliverability. You can answer a client security questionnaire about email authentication truthfully and in writing. And someone is finally reading the reports, so you know who sends mail as your domain.

Frequently asked questions

Will this break our existing email?

That is the risk we are paid to manage, and exactly why we do not jump to enforcement. We fix authentication first, monitor until every real sender passes, then tighten.

We already have SPF. Is that not enough?

No. SPF alone does not survive forwarding, does not cover the From address people actually read, and tells receivers nothing about what to do when it fails. DMARC is what makes it count.

Do you do the Cloudflare and DNSSEC side too?

Yes, as part of this engagement. Cloudflare is tooling we use to deliver DNS and email security, not a separate product we sell. DNSSEC and CAA sit in the same DNS you are already fixing, so doing them together is cheaper than doing them twice. Where the free Cloudflare tier is enough, we say so; we earn nothing from your Cloudflare bill.

Why is the DNSSEC order such a big deal?

Because getting it wrong takes your whole domain offline, website and email, and the failure is not obvious. The registry DS record must be published and confirmed first, then the DNS side. That sequencing is most of what you are paying for.

Do you charge by the hour?

No. We scope the work, quote a fixed fee, and carry the risk if it runs long. Hourly billing rewards the slowest supplier.

Our promise, on every engagement

  • Fixed scope, fixed fee, agreed before we start.
  • Every change staged, so your site and email never go offline.
  • Full documentation handed over. No lock-in, ever.
  • If your free check comes back clean, we will tell you, and we will not invent work.

Stop impersonation before it reaches your customers.

Book a security review and we will walk through what your domain check found, what it allows someone to do today, and what fixing it involves at a fixed fee.