Skip to main content
Email impersonation & invoice fraud

Right now, anyone can send email that looks like it's from your company.

Criminals forge your domain to send fake invoices to your clients and phishing to your staff. Most small firms are wide open to it — and never find out until it costs someone money. Check yours in 60 seconds, in plain English. You don't need an IT team.

60-second check

Free, no login

No IT team needed

We do the fixing

Fixed price to fix

From $2,500

Free check · no login · plain-English results

See what an attacker sees

Enter your domain. We check the DNS records that decide whether someone can impersonate your firm by email — and whether your own mail reaches the inbox.

  • SPF — which servers are allowed to send as you
  • DKIM — whether your mail is cryptographically signed
  • DMARC — what receivers do with mail that fails those checks
  • MX — where your mail is routed

Instant DNS Security Scan

Free — results in seconds

What those results actually mean

Three findings, three business consequences. None of them require you to have an IT team to understand — or to fix.

DMARC policy

Invoice fraud in your name

Without an enforced DMARC policy, anyone can send mail that appears to come from your domain. The common version: a client receives payment instructions that look like they came from your firm, and wires the money.

SPF / DKIM alignment

Your real mail lands in spam

Google, Yahoo, and Microsoft now require authenticated mail from bulk senders. Domains with broken SPF or DKIM get filtered — so client updates, invoices, and intake forms quietly stop arriving.

Enforcement evidence

A gap you have to disclose

Cyber-insurance renewals and client security questionnaires increasingly ask whether you enforce email authentication. "No" affects your premium, and sometimes the answer decides the deal.

Where most clients start

DMARC Enforcement Sprint

Thirty days to an enforced policy that blocks impersonation without blocking your real mail. Every legitimate sender is verified before anything is turned on — which is the part most firms get wrong when they try this themselves.

From $2,50030 days, fixed scope

What you get

  • Full SPF / DKIM / DMARC audit across all in-scope domains
  • Complete sender inventory built from your live DMARC reports
  • SPF / DKIM alignment fixed for every legitimate sender
  • Staged rollout — p=none → quarantine → reject, monitored at each step
  • Completion report + evidence pack for insurers and auditors
  • 90-day handoff plan so enforcement doesn't drift

Not included

  • Mailbox migrations or mail-platform changes
  • Full security programme or compliance certification
  • Ongoing monitoring (available separately as Managed DMARC)

After the sprint

Then it becomes a retainer

A sprint fixes what's broken today. Most firms don't have anyone to keep it fixed — so the drift starts the week after. That ongoing ownership is what a retainer buys.

The systems we hardened during the sprint stay owned, monitored, and patched
New tools, senders, and infrastructure get reviewed before they go live
A named senior engineer who already knows your environment
Monthly reporting your insurer, auditor, or board can read

Essential

$3,500 – $7,500/mo

For growing teams ready to level up their security posture

Professional

$8,000 – $15,000/mo

For businesses requiring broader coverage and active compliance

Enterprise

Custom

For mission-critical infrastructure requiring dedicated teams and custom SLAs

Questions owners actually ask

No jargon. If it's not here, ask on the call.

What is email spoofing, in plain terms?

It's when someone sends email that looks like it came from your company's address, even though they don't have access to your accounts. They can't do this because they hacked you — they do it because your domain isn't set up to stop them. The fix is a setting on your domain, not a change to your mailboxes.

Do I need an IT team to deal with this?

No. That's the point of this page. The free check runs on its own, the results are written in plain language, and if you want it fixed we do the technical work for you — you don't need anyone in-house.

Will fixing this break our real email?

It won't, because we don't flip a switch. We first map every legitimate service that sends email as you — your mailbox provider, your invoicing tool, your marketing platform — and make sure each one still gets through before we start blocking the fakes. That staged rollout is the part firms get wrong when they try it themselves.

Why is my cyber-insurance renewal asking about this?

Insurers and client security questionnaires increasingly ask whether you enforce email authentication (DMARC). A "no" can raise your premium or, on a client questionnaire, cost you the deal. The sprint ends with an evidence pack you can hand straight to them.

How long does it take and what does it cost?

The check is instant and free. The fix is a fixed-scope 30-day sprint starting at $2,500 for a single domain. Multi-domain or high-volume senders are scoped on a short call — no open-ended hourly billing.

Is the free check really free?

Yes. Enter your domain and you'll see how your email is configured right away. If you want the step-by-step fixes, we ask for a work email so we can send them — that's the only thing we collect, and there's no obligation.

Find out where you stand — before someone else does.

The check is free and takes a minute. If it turns up a gap, we'll tell you exactly what it means and what fixing it costs.