Understand the check,
then ship the fix.
Short, honest explainers for every check in a cqwerty report. Read the guide, run the matching tool, and move on. No filler, no upsell.
Four checks, one chain of trust.
SPF, DKIM and DMARC decide whether mail claiming to be you is trusted. TLS decides whether the connection to your site can be. Read them in order and the report stops looking like alphabet soup.
A DNS record that lists the mail servers permitted to send from your domain. Senders outside the list get flagged or rejected by the receiver.
A cryptographic signature on each message. The receiver verifies it against a public key in your DNS, proving the mail came from you and was not altered.
The policy that ties SPF and DKIM together and tells receivers what to do with mail that fails: none, quarantine, or reject. p=none is monitoring, not protection.
The certificate and protocol that encrypt traffic to your site. A weak grade, an expiring cert, or a broken chain quietly breaks trust for every visitor.
Every guide, grouped by what it protects.
Each explainer pairs with a free tool, so you can read the why and then test your own domain on the same surface.
Email authentication
Stop attackers from sending mail that looks like it came from your domain.
Web and transport
The headers and certificates that protect every page load.
DNS and domain hygiene
The records and registrar state that hold your whole posture together.
Reference
A working checklist you can run through before you ship.
Read it, then prove it on your domain.
Every guide above maps to a check we run. Scan your domain and see which ones pass before you finish reading.