● Email security and DMARC for small business: out of spam, nobody sending as you, no wire fraud

Make sure your email arrives, and that nobody else can send as you

Mail landing in spam, a copier that stopped emailing scans, and an invoice paid into a criminal's account (wire fraud) are one problem seen from three sides: nobody has written down which systems are allowed to send email as your company, and proved it to the rest of the internet. The four fixed-price jobs below do that, with every variation priced, plus a written plan for the first hour after a suspected break-in.

22Prices published on this page
86%Of email payment fraud losses moved by wire or bank transfer (FBI)
EN + ESStaff training in both
5.0Clutch rating, software clients
One list, three problems

Every system that sends email as your company has to be on the list, including your website's contact form

The sentence we hear most is some version of: our email goes to spam even though we set up SPF and DKIM. Those are two of the three records, published in your domain's settings, that tell other mail servers which systems are allowed to send as you and let them check the signature on each message (the third, DMARC, tells them what to do when a message fails). They were set up for the mailboxes. But your company also sends email from the website's contact form, the booking page, the invoicing tool, the marketing module, the helpdesk and the copier in the hallway, each set up by a different vendor at a different time. Any sender missing from those records fails the checks, and since Google, Yahoo and Microsoft tightened their rules in 2024 and 2025, failing the checks means the junk folder or an outright rejection. As of February 2026 only 12.8 percent of domains have the full protection switched on; the rest are both easier to impersonate and more likely to land in spam.

Getting your email out of spam, $295 per domain, is the inventory nobody did: every sender found, the three records rewritten so every sender passes, reports flowing back from the receiving servers, and a written list of senders you keep. Full protection, $695, is the next two months: reading those reports, tightening in stages, and switching on full blocking only when no legitimate sender has failed for fourteen days. After that, a message claiming to be from your company that did not come from your list is thrown away by the receiving server before anyone sees it. Nothing else you can do is as effective against someone pretending to be your accounts department.

The scanner is the same work on one device. Copiers send scans with a simple password sign-in that Microsoft is switching off by default at the end of 2026. Administrators can turn it back on, and the final removal date is to be announced in the second half of 2027, so this is not a cliff and anyone who sells it as one is selling urgency. It is, though, work that has to be done once, properly: a sending route the device can use, your sender record updated so the scans pass, a test scan to an address inside and one outside your company, and the setup written down. $175 for the first device, $75 for each one after it in the same office.

Then there is the reason all of this matters more than a junk folder. The FBI puts losses from email payment fraud (it calls it business email compromise) at 2.77 billion dollars in 2024 and 3.05 billion in 2025, with 86 percent of the money moved by wire or bank transfer, and real estate alone lost 275 million in 2025. The attack is not clever: someone reads a mailbox for a few weeks, waits for an invoice or a closing, and sends a change of bank details from an address that looks right. The Payment Fraud Shield is the set of controls that stops each step: a second sign-in step on every mailbox so a stolen password is not enough, full protection so the lookalike cannot send as you, alerts on the forwarding rules attackers create to watch a mailbox, a written call-back rule for any change of bank details that your staff have practised, a watch on web addresses registered to look like yours, and a playbook for the first hour, because the first hour is when a wire can still be recalled.

A domain with full protection switched on cannot be used to send as you. Nothing else on this page is as effective, and it costs less than one wrong wire.

The jobs

Four fixed-price jobs, one list of senders

Each job has a published scope, written assumptions and priced variations. Sending services and certificates are billed at cost and are never inside a price.

Email out of spam, $295 per domain

Every system that sends as your company found and listed, the three sender records (SPF, DKIM, DMARC) rewritten so each one passes, reports flowing back, and a written list of senders. Two to three hours of work that ends the spam folder for a domain with up to six sending systems.

Full protection, $695 per domain

The spam fix, then four to eight weeks of reading the reports, tightening in stages, and switching on full blocking only after no legitimate sender has failed for fourteen days. 3 months of monitoring included, then $35 a month.

Scanner email fix, from $175

For the Microsoft change: a sending route chosen for the device, your sender record updated, the device configured, a test scan to an address inside and one outside your company, the setup documented. $75 for each extra device in the same office. Fixed once, properly.

Payment Fraud Shield, from $1,295

A second sign-in step everywhere, full protection, alerts on forwarding rules and odd sign-ins, a practised call-back rule for bank changes, a watch on lookalike web addresses, and the first-hour playbook, for up to ten users. $29 per user after that and $19 per user a month to keep watching.

Every price and every variation

The rate card, including what turns up after the job starts

A quote names its assumptions and the row below that applies if one proves false. Nothing extra is done without your written yes.

Getting your email out of spam
Email out of spam, per domainOne domain (the part after the @ in your addresses), up to 6 systems that send mail as it, and someone who can change the domain's settings within one business day. We list every system that sends as you (website forms, CRM, invoicing, marketing, helpdesk, scanners), publish the three records that tell other mail servers who may send as you (SPF, DKIM and DMARC), and hand you the written list of senders.$295
Each sending system beyond 6$45
Extra domain on the same Microsoft 365 or Google account$195
A domain you own but do not send from, locked so nobody can send as itEach. A domain that sends nothing should say so, or it can be used to impersonate you.$35
An old system that cannot sign its own mail (old CRM, old web form)Its mail is routed through a sending service (a relay) that signs for it; the relay's own fee is at cost.$95
A shared mailbox whose messages fail the checksIts sending permission is changed so the messages pass.Included
Your sender record has grown past its technical limitA common reason mail fails even when every sender is listed.Included
Nobody has the login for the domain's settingsPer domain registrar; recovering the login comes first.$195
Blocking anyone else from sending as you
Full protection (DMARC enforcement), per domainThe spam fix above, then 4 to 8 weeks of reading the reports other mail servers send back, tightening in stages, and switching on full blocking only after no legitimate sender has failed for 14 days. 3 months of monitoring included.$695
Monitoring after the included monthsReports read, new senders flagged, impersonation attempts counted. Included in Managed Office through the add-on list.$35 per domain a month
Extra domain on the same account, to full protection$395
Forcing encryption on mail sent to you (MTA-STS)Per domain.$145
Your logo shown beside your emails in the inbox (BIMI)Needs full protection first and a paid certificate, at cost.$195
Scanner and copier email fix
First deviceThe device supports modern encryption, we can reach its settings page remotely or through a person on site, and you are on Microsoft 365 or Google Workspace. We choose and set up the sending route, update your sender record, configure the device, send a test scan to an address inside and one outside your company, and write the setup down.$175
Each extra device in the same office$75
Device has no modern sign-in and needs a sending service (relay)That is the usual fix.Included
Device software (firmware) needs updating firstPer device, or the copier dealer's visit at your cost.$75
Scan to a shared folder (SharePoint or OneDrive) instead of emailPer device.$95
Other systems found using the same old sign-in (business software, alarms, website forms)Each. They show up in the sign-in logs.$75
Device too old to send securely at allA written recommendation to replace it instead.No fix sold
The device cannot be reached remotely1-hour minimum for a visit. Visits in Cape Coral, Fort Myers, Estero, Bonita Springs and Naples, no travel charge; everywhere else the fix is remote.$150 an hour
Leased copier locked by the dealer's admin passwordYou get the password from the dealer.No charge while waiting
Payment Fraud Shield
Setup, up to 10 usersA second sign-in step on every mailbox and admin account (multi-factor authentication, MFA, usually a code on a phone) with old password-only sign-in switched off; full protection against anyone sending as you; alerts when a forwarding rule or a suspicious sign-in appears; a written call-back rule for any change of bank details, with staff training and a test; a watch on web addresses registered to look like yours; and the first-hour playbook.$1,295
Each user beyond 10$29
MonitoringMinimum $95 a month. Available as an add-on to any plan.$19 per user a month
A live break-in found during setupThe work switches to incident response at the hourly rate with a written cap.We stop and tell you
When it has already happened
Incident response, no retainer2-hour minimum. Work whose size cannot be known in advance is hourly with a written cap you approve first.$295 an hour
Incident retainer (prepaid, with a one-hour response at any hour)Up to 25 users, 6 prepaid hours, 1-hour response around the clock; then $165 in business hours and $195 after hours.$2,400 a year

Microsoft's scanner change: password sign-in for device email is off by default on existing accounts at the end of December 2026, administrators can turn it back on, and the final removal date is to be announced in the second half of 2027 (Microsoft Message Center MC786329). Nothing here is sold against a date.

The first hour

What to do in the first hour if you think a mailbox has been broken into

This is the playbook the Payment Fraud Shield leaves with you. It is in this order because a wire can sometimes be recalled in the first hours and almost never after a day.

Call the bank before anyone else

If money has moved, your bank's fraud line first and the receiving bank second, with the wire reference, the amount and the time. A recall request has the best chance while the funds are still in transit. Everything else on this list waits until that call has been made.

Minutes 0 to 10

Lock the mailbox, keep the evidence

Change the affected account's password, sign it out everywhere, remove any forwarding or inbox rule that was not yours, and set up the second sign-in step again. Do not delete the messages: they, the rules and the sign-in history are what the bank, the insurer and the FBI will ask for.

Minutes 10 to 25

Find out who else

The sign-in history shows where the attacker came from and which other accounts were reached from the same place. Anyone who received the fraudulent message, or whose mailbox shows the same pattern, gets the same treatment before the hour is up.

Minutes 25 to 45

Tell the people who are about to pay

A short message to every client, vendor and counterparty with a payment in flight: our bank details have not changed, confirm by phone before paying anything. Sent from a mailbox you have just secured, not the one that was read.

Minutes 45 to 60

Report, then fix the cause

File a report with the FBI's Internet Crime Complaint Center (ic3.gov) and notify your cyber insurer within their window. Then the controls that would have stopped it go in: the second sign-in step everywhere, full protection, alerts, the call-back rule, in that order. Incident work beyond the playbook is hourly with a written cap you approve first.

The same day
Why Appluex

Why Appluex for email security

We built half your senders

The contact form, the booking page, the portal that emails your clients: those are software, and a software company reads their settings instead of guessing. That is why every sender ends up on the list, which is the whole job.

We sell the fix, not a countdown

The Microsoft scanner change is off by default at the end of 2026, reversible by an administrator, with the final date still to be announced. We say so plainly and sell the scanner fix as work done once, not as a deadline.

The playbook is yours before anything happens

The first-hour sequence, the call-back rule and the staff training are delivered and practised during setup. When it happens, nobody is reading instructions for the first time, and a wire can still be recalled.

What you receive

Documents you can hand to an insurer, a bank or an auditor

Each job ends with written evidence, not a verbal all-clear.

Spam fix and full protection

  • Written list of senders: every system that sends as your company, who owns it, how it is signed
  • The three sender records as published
  • Protection report: what the reports showed and when blocking was switched on
  • Monthly monitoring summary: new senders, impersonation attempts, pass rate

Scanner email

  • Per-device setup sheet: sending route, address, settings
  • Test record: scans delivered inside and outside the company
  • List of other systems found using the old sign-in, and what was done
  • Replacement recommendation for any device too old to send securely

Payment Fraud Shield

  • The call-back rule, signed by the people who pay invoices
  • Training record and the result of the test
  • Alert settings: forwarding rules, risky sign-ins, who receives them
  • Lookalike web address watch list
  • The first-hour playbook, printed, with the bank's fraud line on it
FAQ

Email security. Questions owners ask

We already have SPF and DKIM and still land in spam. Why?

Because those records only help a sender that is actually listed in them, and your mailboxes are rarely the only sender. SPF and DKIM are two records in your domain's settings that tell other mail servers which systems may send as you and let them check each message's signature. Your website's contact form, booking page, invoicing tool, CRM, helpdesk and copier all send as your company too, and each one missing from the records goes to junk or is rejected. A second common cause is a sender record that has grown past its technical limit, which makes the whole record invalid even when every sender is in it. The fix starts with an inventory of every sender for exactly this reason.

What does the $295 spam fix include and assume?

It covers one domain with up to six sending systems, assuming you or we can change the domain's settings within a business day. We list every sender, rewrite the records so each one passes, switch on the reports that receiving servers send back, and hand you a written list of senders. Each sender beyond six, an extra domain, an unused domain to lock, and an old system that cannot sign its own mail and needs a sending service are the priced variations above; a shared mailbox that fails the checks and an oversized sender record are included.

What is full protection (DMARC enforcement), and why does it take two months?

It is the point where receiving servers are told to throw away any message claiming to be from your company that fails the checks, which is what stops someone sending as you. It takes four to eight weeks because the reports have to be read first: they reveal the senders nobody remembered, and switching on blocking before those are fixed would block your own mail. We tighten in stages and switch on full blocking only after no legitimate sender has failed for fourteen days. The job is $695 per domain with 3 months of monitoring included, then $35 a month, because new senders keep appearing and someone has to notice.

Will our scanner stop emailing at the end of 2026?

Not on a date, and anyone who tells you otherwise is selling urgency. Microsoft's change switches off password-only sign-in for device email by default on existing accounts at the end of December 2026, an administrator can turn it back on, and the final removal date is to be announced in the second half of 2027. New Microsoft 365 accounts created after the change get modern sign-in only. What it does mean is that the copier's current setup is on borrowed time, and the right response is to fix it once, properly: a sending route the device can use, your sender record updated so the scans pass, and the setup written down.

What does the scanner fix cost for an office with three copiers?

$175 for the first device and $75 for each extra one in the same office, so three devices is the first price plus two extras. The first device carries the one-time work: choosing and setting up the sending route and updating your sender record. Each extra device is then about half an hour of configuration and a test. It assumes the device supports modern encryption, that we can reach its settings page remotely or through someone on site, and that you are on Microsoft 365 or Google Workspace. A device software update, scanning to a shared folder instead, and other systems found using the same old sign-in each have a published price; a device too old to send securely gets a written recommendation to replace it, not a fix we cannot stand behind.

What is business email compromise, in plain terms?

It is payment fraud done through email. Someone gets into a mailbox, usually with a stolen password and no second sign-in step, and reads quietly for weeks. They learn who pays whom, when, and how the emails are worded. Then, just before a real payment, they send a change of bank details, either from the mailbox they broke into or from a web address that looks like yours or your vendor's. The money is wired to the new account and is gone within hours. FBI figures put the losses at 2.77 billion dollars in 2024 and 3.05 billion in 2025, with 86 percent of it moved by wire or bank transfer. It is the most expensive crime against small businesses and it needs no technical skill.

What is in the Payment Fraud Shield, and who is it for?

It is for any business that moves money on instructions received by email: title and real estate, law firms, accountants, property managers, lenders, yacht brokers, importers, agencies of every kind. For $1,295 up to ten users and $29 per user after that, we put a second sign-in step on every mailbox and admin account with old password-only sign-in switched off, take your domain to full protection, set alerts on new forwarding rules and suspicious sign-ins, write a call-back rule for any change of bank details and train and test your staff on it, start watching for lookalike web addresses, and leave you the first-hour playbook. Monitoring continues at $19 per user a month with a $95 minimum, and it is available as an add-on to any plan.

What is a call-back rule, and does it really work?

Yes, it works, and it is one sentence your staff follow without exception: any change to a vendor's or client's bank details is confirmed by phone, to a number you already had on file, before any payment is sent. Not the number in the email asking for the change. It works because the attacker controls the mailbox but not the telephone, and because it is a rule rather than a judgment call, so a convincing email does not get an exception. We write it with you, your staff practise it with a test, and the signed copy is one of the documents you receive.

We think a mailbox has been broken into right now. What do we do?

If money has moved, call your bank's fraud line and then the receiving bank before anything else, with the wire reference and the time; a recall has a chance in the first hours and almost none after a day. Then change the account's password, sign it out everywhere, remove any forwarding or inbox rule you did not create, set up the second sign-in step again, and do not delete anything. Call us: incident response without a retainer is $295 an hour with a 2-hour minimum and a written cap you approve first, and the first-hour sequence on this page is what we run. Clients with the incident retainer get a one-hour response at any hour.

Does full protection break our marketing emails or our CRM?

Not if they are on the list, and finding them is what the two months of monitoring are for. Marketing platforms and CRMs can almost always be set up to sign mail as your company once a few records are published; a few old tools cannot, and those are routed through a sending service for a published price rather than left to fail. We switch on full blocking only when no legitimate sender has failed for fourteen days, so a sender that is still unlisted at that point is one nobody at your company recognises, which is itself worth knowing.

Can you lock down domains we own but do not use?

Yes, and you should. A domain that sends no mail can still be used to send mail as you unless its settings say it never sends. Each unused domain gets records that say so, plus full blocking, for a published per-domain price, so an old brand name or a misspelling you bought defensively cannot be turned into a phishing sender. Lookalike web addresses you do not own are a different problem, and that is what the watch in the Payment Fraud Shield is for.

Do you do the staff training in Spanish?

Yes. The call-back rule, the training session and the test are run in English or Spanish, or both for a mixed office. The printed playbook and the signed rule are written in the language your accounts staff actually work in, because a rule nobody can read quickly under pressure is not a control.

Available · typically replies within 24hGet in touch

Let's build something worth shipping

Tell us about your idea. With a track record of success and a commitment to client satisfaction, we'll help bring your product to life.

WhatsApp