Email Authentication Hardening

Without SPF, DKIM and DMARC, anyone can send email that appears to come from your domain. That's how most invoice-redirection and impersonation scams start, and major inbox providers increasingly filter or reject mail from domains that don't authenticate.

Price
$150–300 CAD
Turnaround
Same day to 48 hours

What's included

Stops people from sending email that looks like it came from you. Most businesses have never set this up, and it's usually the fastest visible win.

  • Audit of your current SPF, DKIM and DMARC setup, or confirmation that none exists
  • Every legitimate sender mapped: your mail provider, invoicing, newsletters, booking tools
  • SPF record drafted to cover them all without breaking the 10-lookup limit
  • DKIM enabled through your email provider
  • DMARC set up in monitor-only mode (p=none) with a defined path to enforcement
  • Delivery test confirming your domain passes authentication
  • Plain-language report: what was wrong, what it exposed you to, what was fixed

Price depends on how many sending services need mapping. Included free on every Full Audit or Bundle.

How it runs

  1. Start with what's public

    A free finding or a Security Snapshot. It only looks at what anyone on the internet can already see, so no access or passwords are needed.

  2. Talk it through

    A short call in plain English: what each finding means for your business, and which ones actually matter this month.

  3. Get the fix, not just the finding

    Deeper testing only happens under a written scope agreement. Fixes arrive as pull requests your developer can review, DNS records ready to paste, or takedown reports already filed.

  4. Keep watching

    Look-alike sites come back under new domains and new email senders appear. A retainer keeps someone watching after the report is done.

Often requested by

  • Law and accounting firms

    Wire-fraud and impersonation usually start in the inbox. If your domain has no email authentication, anyone can send a convincing "change of payment details" email as you.

  • Dental, physio and med-spa clinics

    Under PHIPA you're accountable for patient information. Online booking tools, forgotten staging logins and outdated plugins are where it leaks.

  • Property management and real estate

    Tenant records, deposit payments and look-alike domains make you a target for payment redirection scams aimed at your clients.

Other services

Ask about Email Authentication Hardening

Say what you run and when you need it. You'll get a fixed quote within the published range before any work starts.

Connect on LinkedInSee the code on GitHub

Opens your email app with this filled in.