£49 one-off. No website needed.
Stop criminals sending email as your business.
A fake invoice that reads exactly like yours can cost a customer and a reputation in one morning. I will set up the three records that stop it, on your domain, within 48 hours. You do not need a website from me, or a conversation about one.
- Cost
- £49 one-off, including VAT
- Records live
- 48 hours
- Your effort
- One login
Not sure you need it? Check your domain free and see what it publishes today. Takes seconds, no email address needed.
Why this happens
Email was designed without any built-in check that a sender is who they claim to be. At a technical level, anyone can put your address in the from line, the same way anyone can write your name on the back of an envelope.
Nothing has to be hacked
The criminal does not need access to your website, your inbox or your systems. They copy your sign-off, attach an invoice with their own bank details, and press send. By the time the real invoice is chased, the money has gone.
It is the most common attack there is
The government's Cyber Security Breaches Survey for 2025/2026 found phishing to be far and away the most prevalent form of attack, reported by 38% of businesses. Impersonation is not an exotic threat. It is the ordinary one.
The fix is public, and permanent
These records live in your domain's DNS, where every receiving inbox in the world can read them. Set up once and maintained, they keep working without anybody thinking about them again.
What your customer actually sees
This is the whole problem in one picture. Nothing here is broken, misspelled or suspicious. It is your name, your address and your sign-off, because at a technical level anyone is allowed to type them.
Invoice 1043: please note our new bank details
to me
Hi Sarah,
Thanks for the go-ahead. Invoice for the work is attached as agreed.
One thing to flag: we have changed banks this month, so please use the details on the new invoice rather than the ones you have on file. Sorry for the faff.
Any problems, give me a ring.
Cheers,
Dave
There is nothing to spot
The address is not a lookalike domain with a swapped letter. It is genuinely yours. Advice about checking the sender carefully does not help here, because the sender checks out.
Your customer pays it
Then the real invoice gets chased weeks later, and both of you find out at once. They are out the money, and they remember your business as the one that cost them it.
The records answer for you
With SPF, DKIM and DMARC published, the receiving inbox has a way to ask whether that message really came from you, and something to do about it when the answer is no.
The three records
They are separate because they fail separately. Having one or two is common, and more misleading than having none, because it looks handled.
SPF
The guest listA public record naming the servers allowed to send email for your domain. When a message claiming to be from you arrives, the receiving inbox checks whether it came from one of them. No list, or a sloppy one, and a forgery walks straight through.
DKIM
The tamper sealYour genuine email is signed with a cryptographic stamp on the way out, and the receiving inbox uses your public record to confirm the stamp is real and the message was not altered in transit. A forger cannot produce it, because they do not hold your key.
DMARC
The standing instructionTells every inbox what to do with mail that fails those checks: deliver it anyway, put it in junk, or refuse it. It also reports who is sending as your domain, which is how you find out about a problem before your customers do.
What I do
Available on its own, whether or not I built your website, and included as standard on every site I do build.
Check your domain free- A read of what your domain publishes today, and what it means in plain English
- SPF, DKIM and DMARC configured for your real senders, including any newsletter or booking tools
- DMARC started in monitoring mode, then tightened once the reports show nothing genuine is being caught
- The reports translated into a short note in English, rather than left as raw XML nobody opens
- A written record of what changed, so a future provider is not guessing
How it works
Five steps, one of which is yours. You will know what changed and why, and you will have it in writing at the end.
You give me access to your DNS
Your domain provider's login, or add me as a user on the account, whichever you prefer. That is the only thing this asks of you. If you do not know who your provider is, send me the domain and I will tell you.
I record what you publish today
A full read of your current SPF, DKIM and DMARC records before I touch anything. This is the 'before' half of your report, and it is what proves the job was worth doing.
I set the records properly
SPF and DKIM configured for every system that genuinely sends as you, including any newsletter, invoicing or booking tool. DMARC published alongside them with reporting switched on.
You get the before and after report
A branded PDF showing what your domain published before, what it publishes now, and what each record does in plain English. Yours to keep, and to hand to whoever asks.
I come back and tighten it
Once the reports show nothing genuine is being caught, I move DMARC from monitoring to enforcement, which is the point where forged email actually stops. Included in the same one-off price, no second invoice.
The whole offer
SPF, DKIM and DMARC set up on your domain so nobody can send email pretending to be you. Records live within 48 hours, a before and after report at the end, and the follow-up that tightens DMARC to full enforcement included.
No subscription, nothing to cancel, and no website required.
Tell me your domain and I will confirm what needs doing before you pay anything. If your records are already correct, I will say so and there is nothing to buy.
Common questions
- Will this stop all spam and phishing reaching my inbox?
- No, and anyone promising that is overselling. This protects your domain from being used to fool other people, which is the harm that costs a small business a customer or an invoice. Filtering what arrives in your own inbox is a separate job your email provider already does.
- I use Microsoft 365 or Google Workspace. Is it not handled already?
- Partly. Both make DKIM straightforward and both publish guidance, but neither sets up DMARC for you, and a domain sitting on the default policy is being monitored rather than protected. The gaps usually appear when a second system sends on your behalf, like a booking tool or a mailing list.
- Could this stop my genuine email getting through?
- It can if it is rushed, which is exactly why the policy starts in monitoring mode. Nothing is blocked while the reports show which systems genuinely send as you. Only once that list is complete and correct does the policy tighten.
- How long does it take?
- Your records are published and live within 48 hours of me getting access, and reporting starts immediately. Full enforcement, the setting that actually turns forged email away, comes a few weeks later once the reports have proved nothing genuine is being caught. That second visit is included. Anyone offering you enforcement inside 48 hours is either guessing at your senders or willing to lose your real email, and both go wrong the same way.
- What does the £49 cover?
- All of it: the read of what you publish today, SPF, DKIM and DMARC configured for your real senders, the before and after report, and the follow-up visit that tightens DMARC to enforcement. One payment including VAT, no subscription, and nothing to cancel. If a genuine sender turns up later and needs authorising, tell me and I will sort it.
- Do I need a website from you?
- No. This is a standalone job on your domain and it works whoever built your site, whoever hosts it, and even if you have no website at all. Plenty of businesses run on a domain, an email address and a Facebook page, and this protects that domain just the same.
- What if my domain is already set up correctly?
- Then you should not pay me anything, and I will tell you so. Run the free check first: if SPF, DKIM and DMARC all come back green, the job is already done and there is nothing here worth buying. It reads your public records in seconds and asks for nothing but the domain name.
Find out where your domain stands
The free check reads your domain's public records and grades them in plain English. It is passive, so nothing touches your website or your inbox, and there is no sign-up.
Want the background first? Read why criminals can send email as your business or the plain-English DMARC guide.
