Website security, DNS, email routing, domain configuration and access management, reviewed rather than assumed.

What you get

Website security, DNS, email routing and domain management: the configuration that keeps your site reachable, trusted, and out of other people's hands.

Most of this is invisible when it is right and extremely visible when it is wrong. A lapsed certificate turns your site into a browser warning. A misconfigured mail record sends your invoices to spam. An expired domain takes everything down at once, and getting it back is neither quick nor guaranteed.

Who this is for

  • Organisations who do not know who controls their domain
  • Anyone whose email lands in customers' spam folders
  • Businesses with a browser security warning on their site
  • Companies where one former employee's personal account still owns everything
  • Anyone who has been told they were hacked and does not know what to do next

What is included

  • Domain registration and renewal in your name, with expiry that cannot pass unnoticed
  • DNS configured correctly and documented so it can be understood later
  • SSL certificates installed and renewing automatically
  • Email authentication records set up properly, so your mail is trusted
  • Access reviewed, so people have what they need and nothing more
  • Administrator accounts moved onto addresses the organisation controls

The two failures that cause the most damage

Nobody owns the domain. It is registered to a developer's personal account, or to a staff member who left, or to an email address that no longer exists. Everything works until renewal, and then it does not, and the person who can fix it is unreachable. We move ownership to accounts your organisation actually controls, which is dull and occasionally saves a business.

Email is not authenticated. Without the right DNS records, receiving mail servers cannot tell your invoice from someone impersonating you, so they treat it with suspicion. Setting these up properly is a small piece of configuration that decides whether your mail arrives.

Access, and who has it

Security failures are far more often about permissions than about attackers. The former bookkeeper who still has a login. The shared password everyone knows. The one account with full control that four people use, so no action can be traced to a person.

We work through who has access to what, remove what is no longer needed, and separate accounts so actions are attributable. It is not complicated work and it closes the doors most commonly walked through.

How we work

We look at what is actually configured rather than what is assumed, because these differ often. Then you get a plain-language account of what we found, including the parts that are fine.

We fix what is urgent first, and we tell you honestly which risks are real for an organisation your size and which are theoretical. Being frightened into buying protection you do not need is its own kind of harm.

Questions we are often asked

How do I find out who owns our domain? We can usually establish it from public registration and DNS records, then help you recover control if it sits with the wrong person.

Why does our email go to spam? Most often because the authentication records are missing or wrong. It is a configuration problem with a configuration fix.

Is our site secure? We can check the things that are checkable: certificates, access, exposed administration, out-of-date components. We will tell you what we find rather than reassure you.

We think we have been hacked. Can you help? Yes. The first steps are containing it, restoring from a clean backup, and closing the way in so it does not simply happen again.

Who holds the passwords afterwards? You do. Every account is in your organisation's name, with access to us only where you want it.

Want to talk about this?

Tell us what you need and we will come back with an honest answer on scope and cost.

Get in touch