Email security

Stop criminals sending email as your business.

A fake invoice that reads exactly like yours can cost a customer and a reputation in one morning. Three records on your domain make that much harder, and most small business domains are missing at least one.

Why this happens

Email was designed without any built-in check that a sender is who they claim to be. At a technical level, anyone can put your address in the from line, the same way anyone can write your name on the back of an envelope.

Nothing has to be hacked

The criminal does not need access to your website, your inbox or your systems. They copy your sign-off, attach an invoice with their own bank details, and press send. By the time the real invoice is chased, the money has gone.

It is the most common attack there is

The government's Cyber Security Breaches Survey for 2025/2026 found phishing to be far and away the most prevalent form of attack, reported by 38% of businesses. Impersonation is not an exotic threat. It is the ordinary one.

The fix is public, and permanent

These records live in your domain's DNS, where every receiving inbox in the world can read them. Set up once and maintained, they keep working without anybody thinking about them again.

The three records

They are separate because they fail separately. Having one or two is common, and more misleading than having none, because it looks handled.

  1. SPF

    The guest list

    A public record naming the servers allowed to send email for your domain. When a message claiming to be from you arrives, the receiving inbox checks whether it came from one of them. No list, or a sloppy one, and a forgery walks straight through.

  2. DKIM

    The tamper seal

    Your genuine email is signed with a cryptographic stamp on the way out, and the receiving inbox uses your public record to confirm the stamp is real and the message was not altered in transit. A forger cannot produce it, because they do not hold your key.

  3. DMARC

    The standing instruction

    Tells every inbox what to do with mail that fails those checks: deliver it anyway, put it in junk, or refuse it. It also reports who is sending as your domain, which is how you find out about a problem before your customers do.

What I do

Available on its own, whether or not I built your website, and included as standard on every site I do build.

Get a quote
  • A read of what your domain publishes today, and what it means in plain English
  • SPF, DKIM and DMARC configured for your real senders, including any newsletter or booking tools
  • DMARC started in monitoring mode, then tightened once the reports show nothing genuine is being caught
  • The reports translated into a short note in English, rather than left as raw XML nobody opens
  • A written record of what changed, so a future provider is not guessing

Common questions

Will this stop all spam and phishing reaching my inbox?
No, and anyone promising that is overselling. This protects your domain from being used to fool other people, which is the harm that costs a small business a customer or an invoice. Filtering what arrives in your own inbox is a separate job your email provider already does.
I use Microsoft 365 or Google Workspace. Is it not handled already?
Partly. Both make DKIM straightforward and both publish guidance, but neither sets up DMARC for you, and a domain sitting on the default policy is being monitored rather than protected. The gaps usually appear when a second system sends on your behalf, like a booking tool or a mailing list.
Could this stop my genuine email getting through?
It can if it is rushed, which is exactly why the policy starts in monitoring mode. Nothing is blocked while the reports show which systems genuinely send as you. Only once that list is complete and correct does the policy tighten.
How long does it take?
The records themselves are an afternoon. The honest answer is that the safe rollout takes a few weeks, because it is worth watching a couple of reporting cycles before enforcing anything. You are protected progressively rather than all at once.

Find out where your domain stands

The free check reads your domain's public records and grades them in plain English. It is passive, so nothing touches your website or your inbox, and there is no sign-up.

Want the background first? Read why criminals can send email as your business or the plain-English DMARC guide.