Email protection
and website review
A Nezaam service for UK firms, delivered remotely
Can someone send email as your business?
Check your domain here in five seconds, free. If the answer is yes, we close the gap for £195, fixed, and you pay once the fixes are live.
Founding price £195 for the first 10 firms this October. £395 after that.
One paid review delivered, July 2026. Client and findings not published.
Reads your public DNS records through public DNS services (Cloudflare, with Google as a backup). Nothing is sent to us, and nothing touches your mail server.
The fix
One fixed price. Nothing upfront.
We find everything that sends email as you, fix each one, then switch on blocking in stages so none of your real email goes missing. It's done remotely, anywhere in the UK.
Email Protection Package
£195fixed, per firm
Founding price for the first 10 firms this October. £395 after.
Nothing upfront. You pay once the fixes are live, usually in the first week. Monitoring through to full blocking is included.
- Every system that sends email as you, found and listed
- SPF corrected and DKIM switched on for each sender
- DMARC reports read for you, so nothing real gets blocked
- Blocking switched on in stages: spam folder first, then refused
- A one-page record of every change, for your insurer, auditor or clients
- If a change of ours ever stops real email, we fix it the same day, free
Extra domains £45 each. After full blocking, optional monitoring at £15 a month per domain, cancel any time.
- Day 1
A 15 minute callWe list everything that sends email as you: your email, practice or case software, e-signing, newsletters, website forms.
- Days 1 to 3
Records go liveYour IT person or web host adds them in about 10 minutes, or gives us access. We never ask for your email password.
- Days 4 to 14
We read the reportsAnything real that fails gets fixed before a single email is blocked.
- Around day 14
Fakes go to spamThe policy moves to quarantine.
- Around days 28 to 42
Fakes are refusedThe policy moves to reject once the reports are clean, and you get the one-page record.
The steps follow the National Cyber Security Centre's plan for moving to reject. It notes many organisations take about three months; a firm with a handful of sending systems is usually quicker, and we only move when the reports are clean.
Why now
Until it's fixed, anyone can email your clients as you.
44 of the 62 UK firms we checked in September 2026 had no working block on fake emails from their domain: 18 of 20 dental practices, 16 of 17 accountancy firms and 10 of 25 law firms.
-
Law firms
When the SRA visited law firms, email modification was the most common cyberattack it found, and most cases ended with clients sending money to a fraudster. Its guidance points firms to DMARC.
Source: SRA cybersecurity advice
-
Accountancy firms
£41.3 million was lost to invoice and mandate fraud in 2025: the fake "please pay our new account" email. 68% of it came from business accounts.
-
Every business
The UK's National Cyber Security Centre tells organisations to publish DMARC and move it to reject, so fakes of their domain are refused.
The full review
Want the whole picture?
The package covers email. The full review looks at everything a stranger sees when they look up your business, and you get it in writing, in plain English. We quote it after a 15 minute call.
-
01
Whether someone can send email in your name £195 package
Every domain can publish a short record telling other mail servers what to do with a message that claims to be from you but is not. Without it, a fake invoice from your address gets delivered like a real one.
-
02
What Google shows before anyone clicks
Your opening hours, phone number, reviews and the words under your name in the results, checked against what is true today.
-
03
What a chatbot says when asked for a business like yours
People now ask ChatGPT and others who to call. You can try this one yourself, below.
-
04
How the site behaves on a phone
How long it takes to open, whether the contact details can be tapped, and whether the enquiry form can be found.
-
05
Deeper checks, only with written permission
For a business running its own software, such as whether somebody can reach a paid feature without paying. These start only with a signed scope that says what we may look at.
How we check. Public records and one visit to your homepage, the same as anyone can do. No scanning, no logging in, and nothing sent to your mail server. Our own domain had the first of these gaps until September 2026.
Ask it before you ask us.
Put in what you do and where you are, and this writes the sentence a customer types into a chatbot. Then go and ask it yourself. Nobody can tell you in advance what it will answer: it changes with the model, the wording and the person asking, which is why it is worth looking.
The limits, written down.
- Nothing private without your written permission
Beyond what is public, we agree in writing what we may look at, and the list of what we may not is the longer one.
- Nothing that belongs to someone else
Your host, your card processor and whoever sends your email are outside it. They were never ours to look at.
- No further than the question
We confirm the thing and stop. Nobody needs to prove how much further they could have gone.
- Your name stays private
What we find is written for you. It does not appear on this website and it is not a name we drop in a meeting.
- Never your email password
Records go in through your web host or your IT person, or through access you can take back at any time.
- Every change agreed first
You get the exact record and the day it goes live before we touch anything, and a note of it afterwards.
Questions
Before you say yes.
Will this stop our real emails arriving?
Not if it's done in order, which is the whole job. We read two weeks of reports before anything is blocked. If a change of ours ever stops real email, we fix it the same day at no cost.
What do you need from us?
A 15 minute call, a list of the software you use, and 10 minutes of whoever manages your domain. Or access to your DNS that you can take back at any time. Never your email password.
We already have an IT provider. Is this still for us?
If the check above says yes, the gap is still open. We send your IT provider the exact records and do the report reading most of them don't have time for.
Why is it only £195?
Software does the heavy lifting: our own checker for the records, and AI to read the reports. So it takes hours of our time, not days. £195 is the founding price for the first 10 firms this October. It's £395 after that.
When do we pay?
Once the fixes are live and the reports are coming in, usually in the first week. Nothing upfront. Monitoring through to full blocking is included in the £195.
What happens after full blocking?
You're done. If you want, we keep reading the reports for £15 a month and tell you if anything new starts sending as you. Cancel any time.
Who are you?
Nezaam Ltd, a Manchester software studio. Company 17453602, Unit C, Blackett Street, Manchester M12 6AE. Our own domain sends fakes to spam: you can check it above.
Start with your domain.
Put in your web address. It opens the contact page with the Email Protection Package and your address filled in, and nothing is sent until you press send there.
Or just tell us what worries you about your website.
We will tell you whether it is worth looking at, and what we would look at first.
We reply within one working day.