QuillHatch pricing

A clearer view of what your domain is exposing.

Start with a focused free check. Choose a one-time report for a practical action plan, or keep a monthly watch on the changes that matter.

Start free
No passwords. No installs.

The free check is a useful first signal

It reads public records, checks HTTPS and certificate health, and fingerprints visible WordPress signals. It does not pretend to be a complete security audit.

Run the free check

Paid options

The reports use the same six public signals at different depths: the $49 limited/basic report is concise, while the $79 standard full report adds expanded context and a prioritized remediation plan. Monitoring adds monthly rechecks and email alerts.

Limited/basic security report
A focused one-time read of six public signals, useful when you need an affordable first answer.
$49one-time
  • Six public checks across email, HTTPS, SSL, and WordPress exposure
  • Concise plain-English findings with the first priority called out
  • Useful for deciding what deserves attention next

One-time purchase. Limited scope, no recurring charge.

Standard full security report
Best value
A broader one-time report that turns the same six signals into a complete, prioritized action plan.
$79one-time
  • Everything in the limited/basic report
  • Expanded context for each finding and why it matters
  • Prioritized remediation plan with provider-specific next steps

One-time purchase. Expanded interpretation and remediation guidance.

Monthly monitoring
A recurring watch for teams that want to catch meaningful domain and email-protection changes early.
$39/month
  • Monthly rechecks across all six public coverage areas
  • Email alerts when a monitored signal changes
  • A standard full report baseline to make changes easier to understand
  • Future phishing campaigns remain separate and are not bundled

Billed monthly. Cancel future months through the hosted billing process.

The six-check boundary

Focused evidence, not a mystery score.

QuillHatch checks the public-facing signals most relevant to email impersonation and common small-business web exposure.

01SPF
02DKIM
03DMARC
04HTTPS reachability
05SSL certificate health
06WordPress exposure

What you get

Readable guidance, then a way to stay oriented.

Report depth
  • A plain-English explanation of what we found
  • A clear distinction between urgent gaps and lower-risk signals
  • Practical next steps without a technical report dump
Monthly monitoring
  • A standard full report to establish your baseline
  • Monthly rechecks of SPF, DKIM, DMARC, HTTPS, SSL, and WordPress exposure
  • Email alerts when a monitored signal changes
  • Future phishing campaigns are not included and will be priced separately

Choose the depth and continuity you need

All paid options stay within the same six public checks. The $49 report is intentionally concise; the $79 report adds depth; monitoring keeps the baseline current.

FeaturesLimited/basic security reportStandard full security reportMonthly monitoring
Included
Six public checks: SPF, DKIM, DMARC, HTTPS, SSL, WordPressIncludedIncludedIncluded
Concise findings and first priorityIncludedIncludedIncluded
Expanded interpretation and remediation planNot includedIncludedIncluded
Monthly rechecks and email change alertsNot includedNot includedIncluded
Authorized phishing campaignsNot included; future campaigns priced separatelyNot included; future campaigns priced separatelyNot included; future campaigns priced separately
Best for
A limited, affordable first answerIncludedNot includedNot included
A complete one-time action planNot includedIncludedNot included
Ongoing awareness of changesNot includedNot includedIncluded

Know what this page does not promise.

  • This is not a complete security audit, penetration test, or vulnerability assessment.
  • QuillHatch uses public evidence and HTTPS checks; it never needs or receives your passwords.
  • Custom DKIM selectors may require the documentation from your email provider.
  • The check does not guarantee protection or replace a qualified security review.

Phishing simulations are still coming soon. They are not sold, included in monitoring, or bundled into either report; future campaigns will be priced separately.