Email protection
and website review

A Nezaam service for UK firms, delivered remotely

Can someone send email as your business?

Check your domain here in five seconds, free. If the answer is yes, we close the gap for £195, fixed, and you pay once the fixes are live.

Founding price £195 for the first 10 firms this October. £395 after that.

One paid review delivered, July 2026. Client and findings not published.

Can someone send email as you?

nezaam.co.uk29 Sep 2026

Mostly no. Fakes are sent to spam.

Reads your public DNS records through public DNS services (Cloudflare, with Google as a backup). Nothing is sent to us, and nothing touches your mail server.

The fix

One fixed price. Nothing upfront.

We find everything that sends email as you, fix each one, then switch on blocking in stages so none of your real email goes missing. It's done remotely, anywhere in the UK.

Email Protection Package

£195fixed, per firm

Founding price for the first 10 firms this October. £395 after.

Nothing upfront. You pay once the fixes are live, usually in the first week. Monitoring through to full blocking is included.

  • Every system that sends email as you, found and listed
  • SPF corrected and DKIM switched on for each sender
  • DMARC reports read for you, so nothing real gets blocked
  • Blocking switched on in stages: spam folder first, then refused
  • A one-page record of every change, for your insurer, auditor or clients
  • If a change of ours ever stops real email, we fix it the same day, free

Extra domains £45 each. After full blocking, optional monitoring at £15 a month per domain, cancel any time.

  1. Day 1

    A 15 minute callWe list everything that sends email as you: your email, practice or case software, e-signing, newsletters, website forms.

  2. Days 1 to 3

    Records go liveYour IT person or web host adds them in about 10 minutes, or gives us access. We never ask for your email password.

  3. Days 4 to 14

    We read the reportsAnything real that fails gets fixed before a single email is blocked.

  4. Around day 14

    Fakes go to spamThe policy moves to quarantine.

  5. Around days 28 to 42

    Fakes are refusedThe policy moves to reject once the reports are clean, and you get the one-page record.

The steps follow the National Cyber Security Centre's plan for moving to reject. It notes many organisations take about three months; a firm with a handful of sending systems is usually quicker, and we only move when the reports are clean.

Why now

Until it's fixed, anyone can email your clients as you.

44 of the 62 UK firms we checked in September 2026 had no working block on fake emails from their domain: 18 of 20 dental practices, 16 of 17 accountancy firms and 10 of 25 law firms.

  • Law firms

    When the SRA visited law firms, email modification was the most common cyberattack it found, and most cases ended with clients sending money to a fraudster. Its guidance points firms to DMARC.

    Source: SRA cybersecurity advice

  • Accountancy firms

    £41.3 million was lost to invoice and mandate fraud in 2025: the fake "please pay our new account" email. 68% of it came from business accounts.

    Source: UK Finance Annual Fraud Report 2026

  • Every business

    The UK's National Cyber Security Centre tells organisations to publish DMARC and move it to reject, so fakes of their domain are refused.

    Source: NCSC email security and anti-spoofing

The full review

Want the whole picture?

The package covers email. The full review looks at everything a stranger sees when they look up your business, and you get it in writing, in plain English. We quote it after a 15 minute call.

  1. 01

    Whether someone can send email in your name £195 package

    Every domain can publish a short record telling other mail servers what to do with a message that claims to be from you but is not. Without it, a fake invoice from your address gets delivered like a real one.

  2. 02

    What Google shows before anyone clicks

    Your opening hours, phone number, reviews and the words under your name in the results, checked against what is true today.

  3. 03

    What a chatbot says when asked for a business like yours

    People now ask ChatGPT and others who to call. You can try this one yourself, below.

  4. 04

    How the site behaves on a phone

    How long it takes to open, whether the contact details can be tapped, and whether the enquiry form can be found.

  5. 05

    Deeper checks, only with written permission

    For a business running its own software, such as whether somebody can reach a paid feature without paying. These start only with a signed scope that says what we may look at.

How we check. Public records and one visit to your homepage, the same as anyone can do. No scanning, no logging in, and nothing sent to your mail server. Our own domain had the first of these gaps until September 2026.

Ask it before you ask us.

Put in what you do and where you are, and this writes the sentence a customer types into a chatbot. Then go and ask it yourself. Nobody can tell you in advance what it will answer: it changes with the model, the wording and the person asking, which is why it is worth looking.

I need a dentist in Oldham. Who would you recommend?

Nothing is sent anywhere. This page never learns what you typed.

The limits, written down.

  • Nothing private without your written permission

    Beyond what is public, we agree in writing what we may look at, and the list of what we may not is the longer one.

  • Nothing that belongs to someone else

    Your host, your card processor and whoever sends your email are outside it. They were never ours to look at.

  • No further than the question

    We confirm the thing and stop. Nobody needs to prove how much further they could have gone.

  • Your name stays private

    What we find is written for you. It does not appear on this website and it is not a name we drop in a meeting.

  • Never your email password

    Records go in through your web host or your IT person, or through access you can take back at any time.

  • Every change agreed first

    You get the exact record and the day it goes live before we touch anything, and a note of it afterwards.

Questions

Before you say yes.

Will this stop our real emails arriving?

Not if it's done in order, which is the whole job. We read two weeks of reports before anything is blocked. If a change of ours ever stops real email, we fix it the same day at no cost.

What do you need from us?

A 15 minute call, a list of the software you use, and 10 minutes of whoever manages your domain. Or access to your DNS that you can take back at any time. Never your email password.

We already have an IT provider. Is this still for us?

If the check above says yes, the gap is still open. We send your IT provider the exact records and do the report reading most of them don't have time for.

Why is it only £195?

Software does the heavy lifting: our own checker for the records, and AI to read the reports. So it takes hours of our time, not days. £195 is the founding price for the first 10 firms this October. It's £395 after that.

When do we pay?

Once the fixes are live and the reports are coming in, usually in the first week. Nothing upfront. Monitoring through to full blocking is included in the £195.

What happens after full blocking?

You're done. If you want, we keep reading the reports for £15 a month and tell you if anything new starts sending as you. Cancel any time.

Who are you?

Nezaam Ltd, a Manchester software studio. Company 17453602, Unit C, Blackett Street, Manchester M12 6AE. Our own domain sends fakes to spam: you can check it above.

Start with your domain.

Put in your web address. It opens the contact page with the Email Protection Package and your address filled in, and nothing is sent until you press send there.

Founding price for the first 10 firms this October. Nothing to pay until the fixes are live.

Or just tell us what worries you about your website.

We will tell you whether it is worth looking at, and what we would look at first.

We reply within one working day.