What it looks at
The same assessment we run before we ever write to anyone, on the same engine. It is not a score out of ten and there is no grade, because a letter starts an argument about the letter instead of a conversation about the finding.
Your email
- Whether mail can reach you at all
- SPF, and whether it stays inside the ten lookup limit
- DKIM on the selectors the major platforms use
- DMARC, and whether the policy is actually enforcing
- Whether anyone is reading the reports it produces
- Domains registered to look like yours
Your website
- Links in your own navigation that go nowhere
- Page titles and descriptions, which is what a search result shows
- Whether a privacy policy exists where the site says it does
- Terms that name another company or another state
- Whether it renders on a phone
- The contact address you publish
How it works, and what it cannot tell you
- Everything comes from public records: DNS, the domain registry, and the pages your own site links to. Nothing logs in, submits a form, or looks for a vulnerability.
- A record is only called missing when at least three independent resolvers agree. A lookup that fails is recorded as inconclusive and left out rather than counted against you.
- DKIM is checked against the selectors the major mail platforms use. A firm on a non-standard selector may have DKIM we cannot see, and the report says so.
- The website review follows the links your navigation offers. It does not guess at pages you have not linked to.
Would rather we just looked at it?
We are in East Windsor and we do this for firms around Mercer and Middlesex. The assessment is free, there is no obligation attached to it, and if the answer is that everything is fine we will tell you that.