LFW

Blog · Email

Email Deliverability

Password resets, spam folders, domain trust, and why important website emails should never look suspicious to inbox providers.

A missing password reset is a trust problem

When password reset emails never arrive, users do not diagnose DNS records. They decide the site is broken. If the message lands in spam, the result is not much better.

Treat transactional emails like password resets, receipts, and notifications as infrastructure. They need a reliable sender, correct authentication, and monitoring so you know when something changes.

Do not teach inboxes to distrust you

Your site can make legitimate mail look suspicious by sending from the wrong domain, skipping authentication, mixing marketing and transactional mail, or sending vague messages.

Marking everything as safe and hoping doesn't work. Send mail in a way that actually earns trust.

The fix is usually operational

SPF, DKIM, and DMARC matter, but deliverability is also about process: who owns the sending domain, which service sends each type of email, and how you find out when something fails.

Know the path each kind of email takes from your site: contact forms, password resets, receipts, and internal notifications.

Check your own domain, right now

You can check your own domain right here. This is the same check we run at the start of every audit: type your organization's domain and it runs live on this page.

Live demo

Can a stranger send email in your organization's name?

A "please renew your membership" note to your members. A payment request to your finance team, signed with your director's name. If your domain isn't locked down, a stranger can send both. And to the person receiving them, they look completely real. See where yours stands. Free, about three seconds, nothing stored.

How this is built: the check runs on our own server. It makes a few DNS lookups against your domain's published records and grades them the way inbox providers read them. Nothing is stored, and no third-party service is involved. This page is also a product demo: we build tools like this into our clients' sites too.

Keep reading

September 20, 2026 4 minutes

What a Stranger Learns About Your Site in One Minute

Everything in this article is public. It is what a curious visitor, a vendor sizing you up, a journalist, or a scanner run by someone less friendly can read about your website in about a minute. The free audit runs those same checks for you, and you can try it at the end of this article. Here is what it looks at, in the order a stranger would.

September 20, 2026 3 minutes

Login Names Are Half a Login

By default, a WordPress site will list its users for anyone who asks. You get every author's login name, in a machine-readable list, at a fixed address. Attackers don't have to guess who the accounts are. They only have to guess the passwords. This post covers where the list comes from, how the free audit reports it, and four changes that close it without locking anyone out.

All articles

    Powered by LFW Search
    Prefer to write?

    Tell us what needs to work better.

    Slow, fragile, hard to edit, missing a workflow. Say it plainly, and you'll get a straight answer, not a ticket number.