Skip to main content
Email impersonation & invoice fraud

Right now, anyone can send email that looks like it's from your company.

Criminals forge your domain to invoice your clients and phish your staff — and most firms never find out until it costs someone money. Check yours in 60 seconds, plain English. No IT team needed.

  • 60-second check
  • No IT team needed
  • Fixed price to fix
Your client's inbox
AccountsNot sent by you

accounts@your-company.com

Updated bank details for invoice #4021

Hi — quick note, our account has changed. Please send today's payment to the new details attached. Thanks!

new-remittance.pdf
Your domain didn't send this. Your client can't tell.
Security & compliance
  • SOC 2 Type II
  • ISO 27001
  • GDPR Compliant
  • CCPA Compliant

01 — The scan

See what an attacker sees

Enter your domain. We check the DNS records that decide whether someone can impersonate your firm by email — and whether your own mail reaches the inbox.

  • SPF — which servers are allowed to send as you
  • DKIM — whether your mail is cryptographically signed
  • DMARC — what receivers do with mail that fails those checks
  • MX — where your mail is routed

Instant DNS Security Scan

Free — results in seconds

02 — The fix

A staged rollout that won't break your real email

The part firms get wrong on their own is flipping enforcement on too soon. We do it in three steps over 30 days — tap through to see each.

Watch first — block nothing

p=none

We switch on reporting only. Not a single message is blocked yet. From the reports your domain starts collecting, we map every legitimate service that sends mail as you — your mailbox provider, invoicing tool, marketing platform, everything.

Zero risk to your real mail.

03 — The offer

DMARC Enforcement Sprint

Thirty days to an enforced policy that blocks impersonation without blocking your real mail. Every legitimate sender is verified before anything is turned on — which is the part most firms get wrong when they try this themselves.

From $2,50030 days, fixed scope

What you get

  • Full SPF / DKIM / DMARC audit across all in-scope domains
  • Complete sender inventory built from your live DMARC reports
  • SPF / DKIM alignment fixed for every legitimate sender
  • Staged rollout — p=none → quarantine → reject, monitored at each step
  • Completion report + evidence pack for insurers and auditors
  • 90-day handoff plan so enforcement doesn't drift

Not included

  • Mailbox migrations or mail-platform changes
  • Full security programme or compliance certification
  • Ongoing monitoring (available separately as Managed DMARC)

04 — After the fix

Then it becomes a retainer

A sprint fixes what's broken today. Most firms don't have anyone to keep it fixed — so the drift starts the week after. That ongoing ownership is what a retainer buys.

The systems we hardened during the sprint stay owned, monitored, and patched
New tools, senders, and infrastructure get reviewed before they go live
A named senior engineer who already knows your environment
Monthly reporting your insurer, auditor, or board can read

Essential

$3,500 – $7,500/mo

For growing teams ready to level up their security posture

Professional

$8,000 – $15,000/mo

For businesses requiring broader coverage and active compliance

Enterprise

Custom

For mission-critical infrastructure requiring dedicated teams and custom SLAs

Questions owners actually ask

No jargon. If it's not here, ask on the call.

It's when someone sends email that looks like it came from your company's address, even though they don't have access to your accounts. They can't do this because they hacked you — they do it because your domain isn't set up to stop them. The fix is a setting on your domain, not a change to your mailboxes.

No. That's the point of this page. The free check runs on its own, the results are written in plain language, and if you want it fixed we do the technical work for you — you don't need anyone in-house.

It won't, because we don't flip a switch. We first map every legitimate service that sends email as you — your mailbox provider, your invoicing tool, your marketing platform — and make sure each one still gets through before we start blocking the fakes. That staged rollout is the part firms get wrong when they try it themselves.

Insurers and client security questionnaires increasingly ask whether you enforce email authentication (DMARC). A "no" can raise your premium or, on a client questionnaire, cost you the deal. The sprint ends with an evidence pack you can hand straight to them.

The check is instant and free. The fix is a fixed-scope 30-day sprint starting at $2,500 for a single domain. Multi-domain or high-volume senders are scoped on a short call — no open-ended hourly billing.

Yes. Enter your domain and you'll see how your email is configured right away. If you want the step-by-step fixes, we ask for a work email so we can send them — that's the only thing we collect, and there's no obligation.

Find out where you stand — before someone else does.

The check takes a minute and it's free. If it turns up a gap, we'll tell you exactly what it means — and fix it for a fixed price.

Free check · no login · plain-English results