Find the weak points.
Then fix them properly.
Security checks and fixes for small businesses. Start with a free review of your public DNS and website, then get a clear plan for what to fix first.
- Security auditFind and close the gaps
- AutomationDelete the manual steps
- AI agents and skillsBuilt around your work
Domain Lockdown
Three records stand between your invoices and a convincing fake
Fixing this is not a big project. It is a handful of DNS records, done in the right order, verified rather than assumed. Most businesses never do it because nobody told them it was missing.
We check what is public
Your SPF, DKIM, and DMARC records live in public DNS. Reading them usually takes a few seconds and touches nothing you own. You see the same result we do.
We publish the records
Working in your DNS host and your mail provider, we add SPF, turn on DKIM signing, and set DMARC to monitor. Then we watch the reports and tighten to quarantine once your legitimate mail passes cleanly.
You get proof it worked
A before-and-after report showing authentication results from controlled test messages, plus a plain-English summary you can forward to your bookkeeper, your bank, or your insurer.
Three ways a problem gets fixed
The free site audit is where most people start, with public observations and clear limits. The audit goes further, and the fix can be a security change, an automated workflow, or an AI agent. Below is the sort of thing we actually find, written the way you would notice it rather than the way a consultant would name it.
Security audit and hardening
Find what is exposed, then close the gap that lets someone take money or trust from you.
A client says they paid an invoice you never sent
Publish SPF, DKIM, and DMARC to help receivers identify unauthorized use of your domain
Anyone with your password can get into your site or email
Two-factor on the site host and the mail account, and a review of who still has access
Your contact form gets junk, or accepts any file anyone uploads
Restrict what the form accepts and add bot protection that does not annoy real customers
Automation and workflows
Delete the manual step you have been doing by hand for years.
A lead comes in and nobody answers until the next morning
Instant text and email reply, with the lead pushed into wherever you track jobs
You retype the same estimate numbers into three different places
One entry point that fills the quote, the invoice, and the calendar together
You keep meaning to ask happy customers for a review
A request that sends itself a few days after the job closes
AI agents, skills and tools
Hand off the work that eats your evenings, without changing how you work.
You answer the same twenty questions on the phone every week
An agent on your site that answers them in your words, and hands over the real ones
Site-visit notes and photos sit for days before becoming an estimate
A skill your team runs on demand: notes in, draft estimate out, for you to check and send
Nobody on the team knows how to actually use the AI you pay for
Packaged skills and short workflows built for your jobs, not generic prompt advice
Most jobs are one of these, not all three. We tell you which one is worth doing first, and we say so when the honest answer is that nothing here is worth your money right now.
What we keep finding
A sample of recent reviews of local trades and service businesses, anonymised. The pattern is consistent: the website is fine, and the identity around it is wide open.
See an example reportThe review did not discover SPF, DKIM, or DMARC records in its checked scope. The owner used the domain for bids and deposits, making email authentication a priority for verification.
SPF and DKIM in place, but DMARC left at monitor-only. The published policy did not request DMARC enforcement.
Review presence and lead capture were the bigger exposure than the server. The site was quietly losing calls it had already paid to earn.
Details are generalised and clients are not named. Your results are yours; we do not publish them.
What it costs
Flat prices, published. We explain the scope before work starts and tell you when a paid service is unnecessary.
Free site audit
Review public email authentication and website signals. No account, no email, no call.
- SPF, DKIM, and DMARC status
- Mail provider detected
- Plain-English risk summary
Domain Lockdown
The most common finding, fixed. We publish the records, verify them, and hand you proof.
- SPF published and validated
- DKIM signing enabled on your mail provider
- DMARC to monitor, then tightened to quarantine
- Before-and-after authentication report
- 30 days of monitoring included
Full security audit
The whole picture, not just email. Everything reachable from outside your business, ranked by what it would actually cost you.
- Email authentication, DNS, and certificate health
- Security headers, cookies, and third-party scripts running on your pages
- Forms, uploads, and exposed files
- Account and access review across your site host and mail
- Findings ranked high to low, each with a fix and an effort estimate
- Assessment and written report; remediation scope agreed separately
Prefer to do it yourself? The step-by-step guide for your exact DNS and mail host is $149. Ongoing monitoring, which re-checks your records monthly and flags drift, is $99 a month after the first 30 days. Changes between monthly checks may not be detected; remediation is scoped separately. The free saved-history tool runs only when you request a scan. Automation and AI work is quoted from what the audit finds, because pricing it before we have looked would be a guess.