Get a Quote
Email Security Shield · £15/month

Stop attackers spoofing your domain. £15 a month.

Our engineers configure SPF, DKIM and DMARC on your domain and monitor the daily reports — the same setup big-brand legal and finance teams pay thousands for. Flat fee, no setup charge.

£300 typical setup £15/month
✓ No setup fee
Not sure if your domain even has a problem? Run a free 30-second scan first →

Lock my domain — £15/month

Tell us where to reach you. We’ll confirm by phone within one working day and configure DNS for you.

By submitting you agree to be contacted by Orbis Cloud about this service. No card needed.

Three records. One job. Done properly.

Every email server on the internet checks these three DNS records before deciding whether to trust mail claiming to come from your domain. We set up all three correctly and watch them every day.

SPF

Sender Policy Framework

We publish the exact list of servers allowed to send as your domain — so spoofers using your name get rejected before they hit an inbox.

DKIM

DomainKeys Identified Mail

We generate and rotate cryptographic keys that sign every outgoing email, proving to receiving servers it really came from you and wasn’t altered.

DMARC

Domain-based Reporting

We set policy to reject impersonators, monitor the daily reports from Google, Microsoft and Yahoo, and alert you the moment something looks off.

What’s included for £15/month

  • Initial SPF record published & tuned
  • DKIM keys generated, published, rotated
  • DMARC record set to reject (after monitoring window)
  • Daily aggregate report ingestion
  • Monthly summary delivered to your inbox
  • Alerts when a new sender fails authentication
  • Help when you add new email tools (Mailchimp, HubSpot, etc.)
  • Direct line to a UK engineer when something looks off
Real costs of getting this wrong

What happens when these aren’t set up.

A missing DMARC reject policy or a stale SPF record isn’t a paperwork problem. It’s the open door attackers walk through. Three patterns we see in UK businesses every month, plus one public incident on the record.

£85,000 wired

30-person London accounting firm

An attacker spoofed the managing partner’s address and emailed the finance lead asking to redirect a client’s settlement. Without a DMARC reject policy, the spoofed mail landed straight in the inbox with no warning. The transfer cleared before anyone noticed.

What would have stopped it: DMARC p=reject — included in our £15/mo service.
3 weeks of lost mail

UK e-commerce brand, ~50 staff

They added a new email tool but never updated SPF. Half their order confirmations and password resets started landing in spam or bouncing. Customers churned, support tickets piled up, and the cause wasn’t found for nearly a month.

What would have stopped it: active SPF maintenance + DMARC reporting — we’d see the bounce in day-one reports.
£12k extortion paid

Manchester logistics SME

Phishers cloned the CEO’s domain because there was no DKIM signature to verify against. Staff received a series of urgent “invoice attached” emails leading to credential theft, then ransomware on a shared drive. The recovery cost dwarfed the ransom.

What would have stopped it: DKIM signing + DMARC p=reject — both covered.
€42 million

FACC AG — public incident, 2016

An aerospace supplier to Airbus and Boeing lost roughly €42 million to a CEO-impersonation email. The attacker used a domain spoof that proper DMARC enforcement would have caught at the receiving server. The CEO and CFO were dismissed in the aftermath.

Source: FACC AG ad-hoc disclosure, January 2016. The same attack pattern targets UK SMEs every week.
Want to see your domain’s actual risk level before signing up? Run our free domain scan →

Common questions.

If something here doesn’t answer your question, call us on +44 203 355 2711.

Will this break my existing email?

No. We start in monitoring mode (DMARC p=none) so we can see every system sending mail as you — Microsoft 365, Mailchimp, your CRM, your accountant’s tool — before we tighten the policy. Only when reports are clean do we move to reject. Zero risk to legitimate mail.

What if I add a new email tool later?

Email or call us. We update SPF and add the new sender’s DKIM key. Included in the monthly fee — no extra charge for "we just signed up to HubSpot."

Why £15 when other providers charge hundreds?

We don’t bill per-domain or per-mailbox. One flat monthly fee per domain. Most enterprise tools (Valimail, Dmarcian, Red Sift) start at £100+/mo because they bundle dashboards you don’t need. We do the work, you get the protection.

Do I need to grant you access to my email server?

No. We only touch DNS records — the public records that say "this is who’s allowed to send as me." Your mail server, mailboxes and contents stay completely private to you.

Can I cancel?

Yes, anytime. Email or call. We hand you back the records (you keep DKIM keys), no clawback, no exit fee.

How long does setup take?

Once we have DNS access (or you publish records we send), live monitoring follows shortly after. The full DMARC reject policy follows after a 1–2 week observation window so we don’t accidentally block your own systems.

Don’t be the next case study.

Lock your domain for less than the price of one team coffee round.

Start protecting my domain — £15/month → Or run a free 30-second domain scan first →
+971 50 296 0345 +44 203 355 2711
Whatsapp