Skip to content

How easy would it be to get into your company through email or a staff account?

We check your company email, staff sign-ins, admin accounts and laptops. That includes whether someone could pose as you by email.

Request a scoping call

Free 30-minute scoping call.

A typical SaaS product. Your team signs in to everything, from email to the pipeline.

An invoice email that looks like it came from you

A fictional example of what can go wrong here.

  1. Someone sends email as you

    Your domain doesn’t tell mail servers to reject fakes, so the email can get through.

  2. It reaches your customer

    It looks like a real invoice from your finance team, with new bank details.

  3. The customer pays

    The money goes to the attacker, and your name is on the email.

  4. You hear about it last

    Nobody reads the email reports that would have shown it, so your customer tells you.

So we ask: Can someone outside your company send email that passes as yours?

For your engineer

DNS records for example.com

example.com.        TXT  "v=spf1 include:_spf.google.com ~all"
_dmarc.example.com. TXT  "v=DMARC1; p=none; rua=mailto:it@example.com"

What we check

The questions we start from. We agree the final list with you on the scoping call.

  • Can someone send email that looks like it came from your domain?
  • Who has to use MFA, and which sign-in rules apply?
  • Who has admin rights, and what happens to them when someone leaves?
  • Are laptops managed and protected, and does anyone look at the alerts?

Best done after a spoofing or phishing scare, or during a Microsoft 365 or Google Workspace rollout.

What you get, and what it costs

Fixed fee for the agreed scope, quoted before work starts.

We quote it after the scoping call, once we know what’s in. If the scope grows later, we price the extra before we start it.

Included

  • The assessment of the systems we agree
  • A findings report with the evidence for each issue
  • What to fix first, and how to check each fix
  • A walkthrough call with your engineers
  • One round of retesting after your fixes
  • A staged plan for email authentication (DMARC), where it applies

Not included: Making the fixes (your engineers do that), a compliance certificate and anything outside the agreed scope. Quoted separately: Further retests after the first and extra scope added once work has started.

See what a report looks like

Before you enquire

What people ask us most. Wondering whether a pentest would do? Is a VAPT enough?

What do you need from us?

Your domains’ DNS records, read-only access to or exports from Microsoft 365 or Google Workspace, and whatever manages your laptops.

Where do you stop?

We review your settings and hand over the changes. We don’t monitor your systems or run phishing tests.

Is this a penetration test?

No. We review email, sign-in and device settings. Phishing tests and penetration testing aren’t included.

Will turning on DMARC block our own email?

It can if you switch it on too early. First we use your DMARC reports to list every service that sends email for you. Then we agree a period of monitoring before we recommend switching it on fully.

How do you handle confidential material?

Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.

Start with the domain your invoices come from

Microsoft 365 or Google Workspace, and what made you ask?

Request a scoping call

Include your country code. We only use it to follow up on your enquiry.

Please leave out passwords and customer data.

We only use your details to reply to your enquiry. How we handle enquiry information.

Or email contact@unmesha.io directly.

What happens next

  1. We reply within one working day. We set up the call, and you meet the people who’d do the work.
  2. We send a proposal with the scope, the timing and a fixed fee.
  3. Work starts when you say go.

Sending an enquiry doesn’t commit you to anything. About the team