Common questions

About the fixed-fee email authentication cleanup. If yours isn't here, reply "send report" to my email or book 30 minutes.

How did you find this? Were you scanning my systems?

No. SPF, DKIM, and DMARC records are public. They live in your public DNS, where every receiving mail server reads them to decide what to do with a message. I read them the same way a receiving server does. Nothing private, nothing touched.

Will this break legitimate email?

That is exactly what the staged rollout is designed to avoid. DMARC moves gradually to enforcement, with reports reviewed along the way.

Why does this take three to five weeks?

Because we ratchet up enforcement in stages, monitoring which systems legitimately send email for your domain.

What systems does this cover?

Common senders include Google Workspace, Microsoft 365, Mailchimp, CRMs, donor platforms, payroll systems, and finance tools.

Is this a full cybersecurity assessment?

No. This is narrower and more practical: email authentication cleanup, documentation, and a 30-day follow-up report.

What if this is not a fit?

No problem. Reply "not a fit" and I'll stop.

See the fix

The full scope, price, and timing for the email authentication cleanup are on the service page.

Email authentication cleanup