Project host-bring-domain-site-and-email-to-safe-baseline · revised 11 October 2026
Project
Bring your domain, WordPress site and email up to a safe, tested baseline
We review your domain, WordPress site and business email against a written checklist, fix the gaps, and hand back a tested baseline you can show an insurer or client.
This asks for a proposal by email. Nothing is charged, and nothing starts, until you have agreed the scope, the price and the terms in writing.
The result you are buying
The basics of a small business's web presence are scattered across a registrar, a host, a mail provider and a plugin or two. Backups that were never restored, administrator users nobody remembers, mail that fails authentication and a site nobody watches rarely cause trouble until the day they all do. Buying each fix separately means nobody owns the overall picture.
Who it’s for: Owner of a small business whose site and email have grown over years with nobody checking the basics.
Usually starts when: An insurer, client or tender asked how backups, security and email protection are handled, or a scare made you realise nobody has looked.
The result: You buy the finished baseline, not the separate jobs. Backups are tested by a real restore, the WordPress site is hardened, mail authentication is in place, uptime alerts are proved, and you hold a written record of what was found, fixed and left open.
How the work fits together
The project is complete when the four baseline jobs have each been accepted by you against their own checks, every further fix agreed after the review has been accepted or removed in writing, and you have read the review report.
Set up off-site backups for a website and prove a restore works Job Included
Back up one site and its database to a storage account you own, then restore a copy on staging and test pages and a record before signing off.
One WordPress site
Apply an agreed security hardening checklist to one WordPress site Job Included
Work through a written ten-item checklist on one WordPress site (backup check, eight hardening changes, risks report), test nothing broke, and hand over the evidence. Risk is reduced, not removed.
One site, after the backup is proved
After: Off-site backup and restore test
Set up SPF, DKIM and DMARC for business mail going to spam Job Included
Authenticate mail from your domain across your mailboxes and up to three other sending tools. Check headers and DMARC reports; inbox placement cannot be guaranteed.
One domain and up to three other sending tools
Set up outside uptime, certificate and domain-expiry alerts and test them Job Included
Configure up to five outside checks for one site with alerts to two named people, then trigger a deliberate test failure to prove the alert arrives. No on-call cover is included.
One website, up to five checks
Make your bare domain and www address both open the same website Job Each time it fires
Repair the DNS records and arrange one redirect so the bare domain and the www address both reach your website, with mail records left exactly as they are.
If the review finds the names do not both work
Find and fix why mail sent to your domain does not arrive Job Each time it fires
Correct the MX records and, where your host has one, the mail routing setting, so test messages from outside and from your own website reach the right mailboxes.
If the review finds mail routed wrongly
Stop forwarded business mail being rejected, junked or dropped Job Each time it fires
Check up to five forwarding rules, fix your side or swap the forward for an alias or shared mailbox, and show the result with test messages; a strict-policy sender's result is recorded, not promised.
If the review finds forwarding rules that fail
Clear the “Not secure” warning after your site's certificate expired Job Each time it fires
Find why your site’s HTTPS certificate expired, replace it through your host, check the renewal path where the host exposes it, and set an independent expiry warning.
If the review finds an expired or mismatched certificate
Fix "too many redirects" on a site behind Cloudflare Job Each time it fires
For a site behind Cloudflare, trace the redirect chain, find the two settings that disagree and fix them so each http and https address reaches your site within two redirects, tested with a log-in.
If the review finds a redirect loop on a site behind Cloudflare
Fix Cloudflare caching that shows visitors old, wrong or private pages Job Each time it fires
Find which cache rule or response header makes pages stale or shared between visitors, fix it for up to five page types, and prove it with headers and two test sessions.
If the review finds wrong caching on a site behind Cloudflare
Restore a hacked WordPress site from a clean backup and verify it Job Optional
Rebuild one compromised WordPress site from fresh core files and a backup dated before the earliest evidence we find, check it against official checksums, and give you a credential reset list.
Added in writing only if the review finds a compromise; the baseline waits until it is done.
How an engagement works
The price covers the agreed jobs only. A further fix found later, or a shop or custom application, is quoted separately.
How it starts
You tell us about the domain, the site, the email and why you want a baseline, by email.
We do a read-only review from public records and what you send, and propose the four baseline jobs and up to three further fixes, with a fixed price.
You agree the scope, price and terms in writing. Nothing starts before then.
We carry out each job to its own acceptance checks, with your approval before any live change.
We send the review report, the evidence packs and the one-page summary.
Who decides what
You approve every change and accept each job. We are accountable for delivering and verifying the agreed work.
Handover
Each job ends with its evidence pack. The final report lists findings fixed, declined and left open, and what you should look at again and when.
Sharing your product safely. Send the domain, the host and the email provider in words. Do not send passwords, mailbox contents or customer data. After you agree the project we arrange scoped, revocable access through a company-controlled secure handoff.
What is included, and what is not
- The review report, with each finding marked fixed, declined or left open and why
- The evidence pack of each job carried out
- A one-page summary you can show an insurer or client, which makes no claim of certification
Included
- A read-only review of one domain, one single-site WordPress installation and one email domain against a written checklist
- The four baseline jobs: off-site backups with a restore test, a hardening checklist, mail authentication and tested uptime alerts
- Up to three further fixes from the listed jobs where the review finds the fault, agreed with you before work starts
- A written record of findings, fixes and anything left open, in plain English for an insurer or client
Not included
- A security audit or penetration test, or advice for any certification or compliance scheme
- Shops, membership sites, Multisite networks and more than one site or domain
- Moving hosting, DNS or mailboxes: see the move project
- Fixing a hacked site, unless the restore job is added in writing
- Ongoing monthly care, which is a separate standing service
How we know it’s done
Agreed with you before work starts. Each check produces evidence you keep.
The four baseline jobs and every further fix agreed after the review have each been accepted by you against their own acceptance checks, or removed from the list in writing.
Evidence: Each job's evidence pack and your acceptance or removal record
The review report lists every finding as fixed, declined or left open with a reason, and a restore of the latest backup onto a non-public copy loaded the agreed pages and a database record.
Evidence: The review report and the restore test record
The one-page summary states what was done, what remains open and that it is not an audit or certification, and every statement in it matches a job's evidence pack.
Evidence: The summary, which you can compare with the packs
Sign-off. You accept each job as it finishes, then the finished baseline after you have read the review report.
If it fails. A job we cannot complete is named with the reason and what it would take, and the price is adjusted to match. Nothing is billed as delivered that you have not accepted.
When it fits, and when we stop
It fits when
- You can create a named administrator account for this project, protected by two-step sign-in and removed at sign-off, and give scoped access to the host and DNS. The account has the full administrator role, because updates, removals and the editor setting need it
- A named person can approve each change and sign off each job
- The site works normally today and shows no sign of compromise
We stop and tell you if
- The review shows the site is already compromised, so the restore job comes first
- Backups cannot be kept off the host and you do not want to pay for storage that can
- The findings are mostly about a shop or a custom application, which need a different scope
What could go wrong
Each job keeps its own way back, and the proved backup protects the site while the other jobs run. If the project stops, finished jobs stay accepted and the rest is handed back with notes.
Scroll the table sideways to read it all.
| Risk | How we handle it |
|---|---|
| The review finds more than the agreed fixes cover. | Extra findings are listed, priced separately and never absorbed silently, and you choose which to buy. |
| The summary is read as a certificate of security. | The one-page summary says in terms that it is a record of work done, not an audit or certification. |
| A hardening change breaks the site. | The backup is proved by a real restore first, and the hardening job tests the site after each risky change. |
Each change or report is checked by a reviewer separate from the work that produced it before it reaches you. No human supervisor is included unless your agreement names one. At launch the work is largely automated, and we say so.
Stays with a person
- You approve every live change and accept each job
- Your domain holder makes every DNS change
Access we would need
- A named administrator account for this project with two-step sign-in, a DNS export and scoped host access
- An off-site storage account held by you
Questions
Is this a security audit?
No. It is a review against a written checklist and a set of fixes, with a record of what was done. It is not penetration testing, and the summary makes no claim of certification.
Why these four jobs?
Backups that restore, a hardened site, authenticated mail and working alerts are the basics that an insurer or client most often asks about. Further fixes depend on what the review finds.
Why does this cost more than buying the jobs separately?
At their listed test prices the four baseline jobs come to £780, and each further fix is listed at between £125 and £195, so the four jobs plus three further fixes come to between £1,155 and £1,365. The project price also pays for the read-only review against the checklist, the review report, putting the work in a safe order, the independent check of all the evidence packs together and the one-page summary. All of these prices are untested.
Will an insurer or client accept the summary?
We cannot promise that. The summary records what was done and what remains open; whether it satisfies a particular insurer or client is for them to decide, so ask what they need before you buy.
Can you keep it up afterwards?
Yes, through the standing services for the domain and for the WordPress site, which are separate.
Send an enquiry
Send us
- The domain, the host and the email provider
- Why you want the baseline: an insurer, a client or a scare
- Anything you already know is wrong, and who approves changes
Later, once you agree
- A named administrator account for this project with two-step sign-in, a DNS export and scoped host access
- An account at a storage provider for off-site backups, in your name
- A list of the tools that send email as your domain
- No live passwords or customer records by ordinary email
Every account stays in your name. We use only the access you grant, record every change, and you can remove the access when the project is signed off.
Email fallback: open your mail app
If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “host-bring-domain-site-and-email-to-safe-baseline” as the subject.