Methodology
Transparent method, start to finish
We don't have a wall of testimonials yet — we're early. What we have instead is a method you can inspect and results you can reproduce.
1 · The free scan
You give us a domain. We query its public DNS records: SPF, DKIM (common selectors), DMARC, MX, MTA-STS, TLS-RPT, and BIMI. This is the same data any mail server — and any attacker — can already see. We never connect to your mailboxes, servers, or any private system. There is nothing to install and nothing to authorize.
The result is a 0–100 score computed by deterministic, published rules: the same domain state always produces the same score, and every point is traceable to a finding shown on screen. Bands: CRITICAL AT RISK PROTECTED HARDENED
2 · The $249 audit
The audit converts findings into the fix: for every issue the scan identifies, you receive the exact DNS record to publish — copy-paste ready — plus the order to publish them in, so legitimate mail keeps flowing throughout. Delivered immediately as a PDF to your email. Your IT person or vendor can implement it directly; no further purchase required.
3 · You publish the records
You (or your IT person) paste each record into your domain registrar, in the order the audit specifies. That order matters: legitimate senders get authorized first, so mail keeps flowing while you tighten the policy. Nothing to install, no access to grant us — the records are yours and they live in your DNS.
4 · Re-scan free to confirm
Once the records propagate, run the free scan again. Public DNS is the proof: the same deterministic rules that produced your first score now read the corrected state, and you see exactly what moved. Re-scan as often as you like — it is always free.
What we will never claim
DMARC at enforcement stops spoofing of your exact domain. It does not stop look-alike domains, compromised mailboxes, or every form of fraud — and we make no legal or regulatory compliance determination of any kind. If a vendor promises "100% protection," ask them to show you which DNS record delivers it. Ours are all verifiable in public DNS.