Skip to content
All resources
CybersecurityJuly 29, 2026·7 min read

The Five-Minute Security Checkup Every Business Should Run

Free checks that reveal whether scammers can impersonate your company, whether imposter domains already exist, whether your passwords have leaked, and whether that suspicious email is real. No signup, no software, no jargon.

By Cohesive Security

Most business owners have a nagging question in the back of their mind: “Are we actually secure, or have we just been lucky?” Answering it properly takes an assessment. But you can get a surprisingly useful read in about five minutes, for free, without installing anything or talking to anyone.

We publish a set of free security tools that run entirely in your browser. They’re the same quick checks we run when we first look at a new client’s setup. Here’s how to turn them into a five-minute checkup for your own business, and what your results actually mean.

Key takeaways:

  • Most businesses have never checked whether scammers can send email as their exact domain, or whether lookalike copies of that domain are already registered. Both checks take seconds.
  • If a password you use has appeared in a data breach, attackers already have it on a list. Checking takes ten seconds and doesn’t expose the password.
  • Length beats complexity: a passphrase of random words outperforms the cryptic 8-character passwords we were all taught to make.
  • When a suspicious email lands, its hidden headers usually tell the real story. You can read them without being technical.

Minute one: can someone spoof your email?

Start with the check that surprises people the most. The Email Security Checker looks at your domain’s public DNS records and grades your protection against impersonation: SPF (which servers are allowed to send as you), DKIM (a tamper-proof signature on your messages), and DMARC (the policy that tells Gmail and Outlook what to do with fakes).

Why it matters: business email compromise is one of the most expensive scams going, and it often starts with an email that appears to come from the owner’s exact address. If your DMARC policy is missing or set to “none”, receiving mail servers have no instruction to block those fakes. There’s a deliverability bonus too: Google and Microsoft now expect proper email authentication, so fixing it also helps your legitimate mail land in the inbox instead of spam.

Got a C or worse? You’re in the majority, and it’s fixable. These records are single lines of DNS, though DMARC needs a careful rollout so your invoicing and marketing tools don’t get caught in the net.

Minute two: does an imposter version of your domain exist?

Locking down your exact domain closes one door. Scammers have another: registering a near-copy, like yourcornpany.com instead of yourcompany.com, and emailing your customers or your bookkeeper from it. This is how invoice fraud usually starts, and the address looks close enough that busy people don’t notice.

The Domain Lookalike Checker generates about a hundred common variants of your domain (swapped letters, lookalike characters, different endings, add-ons like “-billing”) and checks which ones someone has already registered. The result to take seriously is a close copy with mail servers configured, because that one can send email.

A registered lookalike isn’t automatically fraud. Some belong to unrelated businesses or resellers, and one might even be a defensive registration of your own. But it’s worth knowing they exist, and worth registering one or two of the closest variants yourself as cheap insurance.

Minute three: has your password already leaked?

Now the uncomfortable one. Billions of passwords have been exposed in data breaches, and attackers feed those lists into automated tools that try them against email, banking, and business accounts around the clock. If a password you rely on is in one of those lists, its strength no longer matters. It’s public.

The Breached Password Checker tells you in seconds, without your password ever leaving your browser. It’s scrambled on your device, and only a fragment of the scramble (shared by thousands of other passwords) is used to query the Have I Been Pwned breach database. It’s the same privacy technique Chrome and major password managers use.

If you get a hit, stop using that password everywhere, starting with email. Email is the skeleton key, since it can reset almost everything else.

Minute four: how strong is what you’re using now?

Even a password that’s never leaked can be weak. The Password Strength Tester estimates how long a password would survive two realistic attacks: someone guessing at a login page, and someone cracking a stolen database with modern hardware. It flags the patterns attackers try first, like keyboard runs, years, and the classic “word plus a couple of numbers”.

While you’re there, try the passphrase generator. It builds passwords like “timid-defog-dotted-sled-mantra” from randomly chosen words. That looks casual, but each extra random word multiplies an attacker’s work thousands of times over, which is why security agencies like NIST now recommend long passphrases over short, cryptic ones.

The honest next step, though, isn’t a better memorized password. It’s a password manager generating a unique password for every account, protected by one strong passphrase and multi-factor authentication. That combination ends password reuse, which is how one breached website turns into a breached business.

Minute five: bookmark these for the moment something feels off

Two of the tools earn their keep the day a suspicious message arrives, so file them away now.

When an email asks for a payment, credentials, or urgency, its hidden headers usually settle the question. Paste them into the Email Header Analyzer and you’ll see where the message really came from, whether it passed the authentication checks from minute one, and red flags like replies quietly routed to a different domain. The page shows how to grab headers from Gmail, Outlook, or Apple Mail.

And because scams now arrive as squares as often as links: the QR Code Safety Checker decodes a photo of any QR code on your device and shows where it leads before you ever open it, flagging hidden shorteners, brand impersonation, and other tricks. Fake codes show up in emails, on invoices, even stickered over real ones on parking meters.

One caution in both directions: a failed check doesn’t always mean fraud, and a passed check isn’t a guarantee. When money is on the line, verify through a channel you already trust, like a phone number you know. If you’re ever unsure, forward the message to hello@cohesivesecurity.com and we’ll give you a quick, human read on it.

Got more than five minutes? Bring in the team

Two more tools turn this from a solo checkup into something your whole company benefits from.

The Spot the Phish Quiz shows nine realistic emails, some genuine and some scams modeled on what actually hits small businesses: fake CEO gift card requests, payroll redirect attempts, bogus login alerts. Take it yourself, then send it around the office and compare scores. It’s a lightweight preview of what real security awareness training does month after month.

And for the owner’s eyes: the Downtime Cost Calculator puts a dollar figure on the day your systems go down, using your own team size, labor costs, and revenue with the math shown. It’s the single best number for deciding how much prevention is worth to you.

What your five minutes just told you

If everything came back green, genuinely well done. You’re ahead of most small businesses, and the fundamentals that matter next are backups you’ve actually tested, multi-factor authentication everywhere, and someone watching for trouble.

If you found problems, you’re in good company, and you’ve just done something valuable: you found them before an attacker demonstrated them for you. Some fixes are ten-minute jobs. Others, like rolling out DMARC safely or moving a whole team onto a password manager, benefit from someone who has done it many times.

Either way, these tools check what’s visible from the outside. A real assessment goes deeper: how your Microsoft 365 is configured, whether your backups would actually restore, what happens when someone clicks the wrong link. That’s the free assessment we offer every business we talk to, no strings attached. Five minutes told you something. An hour with us will tell you the rest.

#cybersecurity#free tools#email security#passwords#phishing

Enjoyed this article?

Get more like it by email. Short, practical security tips for business owners. No jargon, no spam, unsubscribe anytime.

We only use your email to send the tips. Nothing else, and never shared.

Want help putting this into practice?

Our team can assess your environment and handle the heavy lifting. Start with a free, no-pressure conversation.