Services & Pricing
From Free Audit to Documented, Defensible Compliance
Your free scan shows where you stand. These packages fix what it finds, watch for lookalike domains, and keep you in Safe Harbor year-round. Pricing is a starting point — every engagement is scoped to your domain and headcount.
The Compliance Ladder
Each step builds on the last. Most clients start with the free audit, unlock the Full Audit Report when they need evidence, fix gaps with a Remediation Sprint, add Cybersquat Monitoring for brand impersonation, then move to a Managed Compliance retainer.
Free Domain Audit
See your email and web security score in seconds.
- SPF, DKIM & DMARC spoofing check
- TLS / transport security review
- Website security-header scan
- Zero-knowledge — we don't store your results
Full Audit Report
Unlock the complete technical report from your free scan.
- Executive summary & prioritized remediation plan
- Granular DNS, DMARC, SPF, DKIM & MTA-STS evidence
- Credential breach checklist: HIBP check, MFA, Proton Pass¹, M365/Google guidance
- SB 2610 / industry compliance relevance map
- Three PDF guides + 90-day favicon suite access
Remediation Sprint
We fix everything the audit flagged, then re-scan to prove it.
- SPF / DKIM / DMARC configured to enforcement
- MTA-STS & transport hardening
- Microsoft 365 / Google Workspace / Proton anti-phishing setup
- Before-and-after audit score report
Compliance Package
The documented program regulators and your insurer ask for.
- Written Information Security Program (WISP)
- Mapped to SB 2610, FTC Safeguards, HIPAA or IRS Pub 4557
- Risk assessment & policy templates
- Dated compliance attestation you can hand to auditors
Managed Compliance
Stay in Safe Harbor without thinking about it.
- DMARC-as-a-Service monitoring & reports
- Quarterly re-audits + annual program review
- Security-awareness training & phishing tests
- vCISO guidance and incident-response readiness
Cybersquat Monitoring
Catch lookalike and typosquat domains targeting your brand — including Surfside-style BEC staging.
- Daily BEC/ACH-depth lookalike scan (plural inserts, i/l swaps)
- Same-day alert when a new threatening lookalike appears
- Monthly digest + MX-only BEC staging flags
- One brand domain · Stripe checkout & customer portal
¹ We may earn a commission if you sign up for Proton Pass through links in the full audit report.
À la carte services
Email Authentication (SPF/DKIM/DMARC)
Stop attackers spoofing your domain. We configure and validate full email authentication and move you to a reject policy safely.
DMARC-as-a-Service
Ongoing monitoring of who is sending as your domain, with monthly reports and progressive enforcement — the recurring backbone of email security.
Microsoft 365 / Google Workspace / Proton Hardening
MFA, conditional access, anti-phishing and safe-links policies, and audit logging turned on and tuned for small teams — on Microsoft 365, Google Workspace, or Proton Mail.
WISP & Policy Documentation
Productized written security policies mapped to the framework your industry is regulated under, so 'document everything' becomes a deliverable.
Security-Awareness Training
Recurring phishing simulations and short training for your staff — the control most compliance frameworks explicitly require.
BEC & Wire-Fraud Protection
Layered controls for firms that move client money — title, real estate and finance — where a single spoofed email is a six-figure loss.
Not sure where you stand?
Start with the free audit at audit.emailmenow.com. Unlock the Full Audit Report ($99) when you need remediation steps, raw DNS evidence, and compliance documentation — or add Cybersquat Monitoring ($49/mo) to watch for lookalike domains.
Run a Free Audit