Turn on MFA
Use multi-factor authentication on email, finance, admin, and remote-access accounts.
QuillHatch is the plain-English health check for agents and small brokerages without a dedicated IT team. Find the gaps behind your domain, then get a calm, prioritized plan to close them.
No passwords. No scare tactics. Just the next right step.
Domain review
Email protection
DMARC policy needs attention
Certificate
Valid · 74 days remaining
Next best step
Publish a stricter DMARC policy
Live email protection check
The useful version of secure
You do not need another dashboard full of red warnings. You need to know what a scammer could use, what deserves attention first, and what can wait.
Start with the live domain check below. We read SPF, DKIM, and DMARC — the public guardrails that help stop impostors from borrowing your address.
SSL health, certificate timing, and WordPress software that can quietly become an entry point.
A careful look at breach data connected to your domain, with practical next steps if something surfaces.
You do not need to become a security specialist to make your business harder to disrupt. Start by understanding why small companies get swept into broad attacks, then take a few practical steps that improve your resilience.
01 / The pattern
Small businesses are not targeted because they are unimportant. They are often included in broad, automated searches. Automated scanning and AI-assisted impersonation or phishing make it cheap for threat actors to look for many companies at once.
Limited IT capacity and exposed email or website weaknesses can create openings. A smaller team may also have less time to spot unusual requests, rotate access, or recover from a disruption.
02 / The disruption
Ransomware is a type of criminal disruption that can lock access to systems or data and pair that disruption with an extortion demand. Common entry points include phishing, stolen credentials, exposed services, or unpatched software.
The impact is disruption and extortion as well as financial pressure: missed work, unavailable files, pressure on staff, and difficult decisions during an already stressful event. Preparation does not make a business invulnerable, but it can improve resilience and make the next safe decision clearer.
Practical fixes
Start with the accounts and systems your team relies on every day. The best plan is the one people can follow when work is busy.
Use multi-factor authentication on email, finance, admin, and remote-access accounts.
Keep tested backups of important data in a separate place, and practice restoring a few files before you need them.
Keep operating systems, browsers, websites, plugins, and security tools current.
Give each person only the access they need, and remove access when roles change.
Tell staff how to report a suspicious message or mistake quickly, without blame.
Set up SPF, DKIM, and DMARC so recipients can better distinguish your mail from impostors.
Renew certificates on time and fix website warnings before visitors are trained to ignore them.
Keep a short list of who to call, what to isolate, how to communicate, and where recovery steps live.
What QuillHatch does today
QuillHatch checks public email and domain protections, public-facing site signals, and leaked-credential exposure connected to a domain. The paid report and monitoring path turn those signals into prioritized, plain-English next steps.
That is different from general preparedness: QuillHatch does not prevent ransomware, replace incident response, or claim to be a complete security audit. Phishing simulations are not available today; they remain separate roadmap work.
Keep learning
These external guides add context to the checklist. They are general preparedness resources, not QuillHatch scan results.
How QuillHatch works
Built for the moment between “I should probably check that” and calling an expensive consultant.
Enter your business domain and email provider. No passwords, installs, or technical setup.
Receive a prioritized review in plain English: what matters, why it matters, and the safest fix.
Monthly rechecks watch for new exposure, altered email protection, and certificates nearing expiration.
A small line item for a big peace of mind
$29–39 / month
A prioritized first report, monthly rechecks, and an alert when the risk picture changes.
Prefer a one-off look? Reports are $49–99.
Run the checkStart with the question
Give QuillHatch your domain. We will show you what is exposed, what to fix first, and what to keep watching.
Check your domain