Home / FAQ
Frequently asked questions
Eighteen questions we are asked on nearly every discovery call, answered at the length they deserve. If yours is not here, call 845-672-7368.
How quickly can you start work?
Baseline audits normally begin within three to five business days of a signed scope. Active emergencies — a live blocklisting, a mail outage, a failed cutover — are triaged the same business day wherever capacity allows. Call 845-672-7368 rather than emailing if the situation is urgent.
Do you work with clients outside New York State?
Yes. About two thirds of our clients are outside the Hudson Valley, across eighteen states. Delivery is remote; on-site visits are included without travel charges within a two-hour drive of Poughkeepsie.
What exactly is in the baseline audit?
A written document, typically ten to eighteen pages: DNS and authentication findings, reputation and blocklist status, transport security, a mailbox estate review, continuity checks, and a risk register ranked critical / high / advisory with hour estimates against each item.
Do we have to sign a long contract?
No. Project work is scoped and fixed-fee. Retainers run for an initial ninety days and then month-to-month with thirty days notice. Nothing renews automatically without an email you have to reply to.
Do you resell Microsoft 365 or hosting?
No. We take no commission, referral fee or margin from any platform vendor. You purchase licenses directly and own the relationship, which keeps our advice honest and keeps you free to leave.
Can you work alongside our current IT provider?
That is a large share of what we do. Many managed service providers bring us in specifically for the mail layer. We will join their calls, work in their ticketing system and document everything to their standard.
What does DMARC enforcement actually change for us?
Once a domain publishes p=reject, mail that fails authentication and claims to be from you is refused outright by receiving systems. It largely ends direct-domain spoofing in phishing attempts against your customers and staff. Getting there safely takes a few weeks of reporting first.
Will enforcement break our existing email?
Not if it is staged. That is why we run p=none with reporting for several weeks, catalogue every legitimate sender that turns up, fix each one, then raise the policy in increments. Skipping the reporting phase is how people break payroll notifications.
How long does a Microsoft 365 migration take?
For up to 250 mailboxes, typically two to six weeks end to end. Most of that is preparation; the cutover itself is usually one evening or weekend. Two weeks of hypercare follow go-live.
Do migrations cause downtime?
Planned cutovers are scheduled outside working hours and use a coexistence period, so users should notice nothing on Monday morning beyond a one-time Outlook prompt. Inbound mail is queued rather than rejected during the switch.
We are on a blocklist right now. Can you help today?
Often, yes. Call us. We triage the listing source, stop whatever is causing it — usually a compromised mailbox, an open relay or a bad list — and then submit delistings. Submitting a delisting before fixing the cause simply gets you relisted.
Do you handle marketing email?
We support permission-based marketing infrastructure: authentication, IP warm-up, bounce handling and complaint loops. We do not write campaigns, and we will not work with purchased or scraped lists.
What are your support hours?
Monday to Friday, 8:30am to 6:00pm Eastern. Retainer clients also receive a 24/7 escalation number for genuine mail-flow emergencies.
How do you handle our credentials?
Least privilege, always. We ask for delegated administrative access rather than shared passwords wherever the platform supports it, credentials live in an encrypted vault with per-engineer access, and everything is revoked at the end of an engagement with written confirmation.
What happens to our data if we leave?
You get a handover call, all documentation, credentials and change logs. Working data is deleted on the schedule set out in our Privacy Policy. There is no exit fee and nothing is withheld.
Do you sign NDAs and complete vendor questionnaires?
Yes, routinely. Send yours with the discovery call request and we will have it back before the engagement letter.
How are you different from a general MSP?
Depth in one place. A generalist provider is very good across twenty disciplines; we have spent ten years in one. For most companies the right answer is both — keep your MSP and use us for the mail layer.
What if the audit finds nothing wrong?
It happens perhaps one time in fifteen, and we will tell you plainly. You keep the document, which is a useful thing to hand an insurer or an auditor, and we will not invent work to justify the fee.
Not sure where to start?
Begin with the baseline audit. Fixed fee, one week, and the findings document is yours whether or not you hire us for the remediation.