How easy would it be to get into your company through email or a staff account?
We check your company email, staff sign-ins, admin accounts and laptops. That includes whether someone could pose as you by email.
Request a scoping callFree 30-minute scoping call.
An invoice email that looks like it came from you
A fictional example of what can go wrong here.
Someone sends email as you
Your domain doesn’t tell mail servers to reject fakes, so the email can get through.
It reaches your customer
It looks like a real invoice from your finance team, with new bank details.
The customer pays
The money goes to the attacker, and your name is on the email.
You hear about it last
Nobody reads the email reports that would have shown it, so your customer tells you.
So we ask: Can someone outside your company send email that passes as yours?
For your engineer
DNS records for example.com
example.com. TXT "v=spf1 include:_spf.google.com ~all"
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:it@example.com"
What we check
The questions we start from. We agree the final list with you on the scoping call.
- Can someone send email that looks like it came from your domain?
- Who has to use MFA, and which sign-in rules apply?
- Who has admin rights, and what happens to them when someone leaves?
- Are laptops managed and protected, and does anyone look at the alerts?
Best done after a spoofing or phishing scare, or during a Microsoft 365 or Google Workspace rollout.
What you get, and what it costs
Fixed fee for the agreed scope, quoted before work starts.
We quote it after the scoping call, once we know what’s in. If the scope grows later, we price the extra before we start it.
Included
- The assessment of the systems we agree
- A findings report with the evidence for each issue
- What to fix first, and how to check each fix
- A walkthrough call with your engineers
- One round of retesting after your fixes
- A staged plan for email authentication (DMARC), where it applies
Not included: Making the fixes (your engineers do that), a compliance certificate and anything outside the agreed scope. Quoted separately: Further retests after the first and extra scope added once work has started.
Before you enquire
What people ask us most. Wondering whether a pentest would do? Is a VAPT enough?
What do you need from us?
Your domains’ DNS records, read-only access to or exports from Microsoft 365 or Google Workspace, and whatever manages your laptops.
Where do you stop?
We review your settings and hand over the changes. We don’t monitor your systems or run phishing tests.
Is this a penetration test?
No. We review email, sign-in and device settings. Phishing tests and penetration testing aren’t included.
Will turning on DMARC block our own email?
It can if you switch it on too early. First we use your DMARC reports to list every service that sends email for you. Then we agree a period of monitoring before we recommend switching it on fully.
How do you handle confidential material?
Send an outline first and leave out passwords and customer data. We only ask for anything sensitive once we’ve agreed the scope and a safe way to share it.
Start with the domain your invoices come from
Microsoft 365 or Google Workspace, and what made you ask?
What happens next
Sending an enquiry doesn’t commit you to anything. About the team
