You've seen the finding. Here's the fix.

A fixed-price email authentication cleanup for nonprofits. SPF, DKIM, and DMARC configured correctly and staged safely to enforcement, without turning it into a big IT project.

$1,500 fixed. No retainer. No surprise scope.

Legitimate email keeps getting through. Forged email using your domain gets rejected.

Reply "send report" to the email I sent, or book 30 minutes.

Book 30 minutes

What this fixes

The issue I flagged in your domain records is part of a common pattern:

These problems are common. They are also fixable.

What you get

Built for nonprofits

This is narrow by design. Not managed IT. Not endpoint security. Not a retainer. Not a broad assessment that turns into a sales funnel.

It fixes one important control, documents it clearly, and leaves. When it's done, you own the configuration and I'm out of your way.

Straightforward, but not a five-minute job

On paper it's a few DNS records. In practice it usually means moving you to a DNS host that handles this cleanly, tracking down forgotten records left behind by tools you signed up for years ago, and clearing out the cruft before staging enforcement so nothing breaks.

Simple if you've done it a hundred times. Your part stays small. Mine doesn't.

Price and timing

$1,500 fixed. No retainer, no surprise scope, no open-ended meter. Below most nonprofits' capitalization threshold, so it's CFO-discretionary, no board vote.

The work is usually staged over three to five weeks so DMARC can move gradually to enforcement, confirming legitimate senders before the strict setting turns on.

Your part is small:

Book 30 minutes

Why it matters now

A few things have converged. SAS 145 has auditors looking harder at IT-related risks and controls. The updated Uniform Guidance now expects federal grantees to take reasonable cybersecurity measures. Cyber-insurers increasingly ask whether SPF, DKIM, and DMARC are in place. And AI has made forged email cheaper to send and harder to spot.

Email authentication is not a cure-all. It does not stop every scam, and it does not satisfy a grant requirement by itself. It closes one basic door, cleanly, and gives you the paperwork to show it's closed.

Why this usually goes unfixed

This work falls between chairs. It touches DNS, email, security, audit, and your fundraising and finance tools, and no single provider owns the whole picture, so records drift, SPF chains break, and DMARC sits on "monitor only" for years.

Your auditor may flag the issue but, under independence rules, may not be able to implement the control for you. That's the gap I fill.

Background

I'm David Koosis, a senior technology consultant (fractional CTO) for mission-driven organizations. Across twenty-plus years, I've built systems for organizations ranging from a startup to investment banks to government agencies to 988, the nation's suicide hotline.

More on what else I do at uprizr.com.

Next step

You have the finding and my address. The simplest next step is to reply to my email with:

"Send report."

I'll send the fuller findings for your domain, no charge.

Or book 30 minutes below. No slide deck, no hard sell. The call is just to confirm whether this fixed-scope engagement fits your domain, your timeline, and your team.

Book 30 minutes

Common questions

How did you find this? Were you scanning my systems?

No. SPF, DKIM, and DMARC records are public. They live in your public DNS, where every receiving mail server reads them to decide what to do with a message. I read them the same way a receiving server does. Nothing private, nothing touched.

Whether the fix breaks legitimate email, timing, coverage, and scope are all answered on the questions page.

Read common questions

Book 30 minutes

Pick a time that works. No slide deck. The call is just to confirm whether this fixed-scope engagement fits your domain, your timeline, and your team.

If you landed here some other way

Enter your domain and I'll send you a plain-English report on your current email authentication posture within 24 hours. One-time, no list, no drip.

No drip sequence. No sales automation. No list. If this isn't the right time or the right fit, I'd rather know than not.