Learn·No jargon. No pitch.

Understand the check,
then ship the fix.

Short, honest explainers for every check in a cqwerty report. Read the guide, run the matching tool, and move on. No filler, no upsell.

Start here

Four checks, one chain of trust.

SPF, DKIM and DMARC decide whether mail claiming to be you is trusted. TLS decides whether the connection to your site can be. Read them in order and the report stops looking like alphabet soup.

SPF
01
Who is allowed to send as you?

A DNS record that lists the mail servers permitted to send from your domain. Senders outside the list get flagged or rejected by the receiver.

DKIM
02
Was the message changed in transit?

A cryptographic signature on each message. The receiver verifies it against a public key in your DNS, proving the mail came from you and was not altered.

DMARC
03
What happens when a check fails?

The policy that ties SPF and DKIM together and tells receivers what to do with mail that fails: none, quarantine, or reject. p=none is monitoring, not protection.

TLS
04
Is the connection actually private?

The certificate and protocol that encrypt traffic to your site. A weak grade, an expiring cert, or a broken chain quietly breaks trust for every visitor.

The library

Every guide, grouped by what it protects.

Each explainer pairs with a free tool, so you can read the why and then test your own domain on the same surface.

Read it, then prove it on your domain.

Every guide above maps to a check we run. Scan your domain and see which ones pass before you finish reading.

No credit card Results in 90 seconds Read only