Email security has three jobs
- Protect accounts: MFA, named administrators, recovery and prompt offboarding.
- Authenticate the domain: Inventory senders, configure SPF/DKIM/DMARC and inspect real mail results.
- Protect decisions: Verify bank-detail changes and unusual requests outside the email thread.
- Buy for a gap: Check the protections included with your exact mail edition first.
Last updated: September 24, 2026
A secure-looking email can come from a compromised real account, and a spoofed message can use a lookalike domain. Sender authentication, filtering and human verification address different failure paths. The FTC's small-business guidance explains SPF, DKIM and DMARC; Microsoft's email-authentication guide also shows why a pass or fail must be interpreted in the context of actual message headers.
1. Protect mailboxes and administrators
List all mail administrators, finance mailboxes, shared mailboxes and delegated users. Require MFA for human accounts; use phishing-resistant methods where your platform and team support them. Keep recovery contacts under business control and remove departed staff from the mail tenant and connected apps. Review forwarding rules, delegated access and suspicious sign-ins after any reported compromise. A shared mailbox should have named delegates rather than a shared password. See the password-manager guide for account ownership and recovery.
Verification: export enrollment and exceptions, sample a leaver, and make sure the person who receives alerts knows how to respond. Buying a higher mail tier is not a substitute for configuring existing identity settings.
2. Authenticate every legitimate sending path
Inventory staff mail, invoices, CRM, marketing, support, ticketing and website forms. Each service that sends as your domain needs an accountable owner. Publish one valid SPF record for authorized senders; enable DKIM signing for each platform; then use DMARC reports and real message headers to check alignment with the visible From domain. Google's sender guidelines recommend SPF, DKIM and DMARC and explain that unauthenticated mail can be rejected or marked as spam.
Move a domain toward DMARC quarantine or reject only after legitimate senders are identified and aligned. An abrupt change can block invoices, support mail or customer notices. A DNS lookup can show a published record but cannot prove that all real mail passes alignment. Follow the email-security testing workflow and check messages sent through each provider.
3. Make payment changes hard to spoof
A request to change bank details, urgently transfer funds or bypass approvals is a process event, not just an email-filtering event. Finance calls a number already held in supplier records, never one supplied in the request, and records a second approver for material transfers. When a transfer appears fraudulent, contact the bank immediately and activate the BEC response procedure. FBI IC3's BEC guidance describes this fraud pattern and the need for prompt reporting.
4. Run a monthly operating check
| Check | Owner | Evidence |
|---|---|---|
| MFA and privileged access | Identity admin | Enrollment/exception export |
| New or removed mail senders | Mail admin | Sender inventory and DNS change log |
| Authentication of actual outbound messages | Mail admin | Headers from each sending service |
| Filtering and user reports | Mail/security owner | Reviewed alerts and false positives |
| Bank-detail changes | Finance lead | Callback and approval record |
If you use Microsoft 365 Business Premium, check its included Defender for Office 365 Plan 1 features and your actual configuration before paying for another filter; the plan review explains its limits. Teams on other mail plans should make the same edition-level inventory before comparing an add-on.
Do this first
Name the mail and finance owners, verify administrator MFA, inventory domain senders and put a known-number callback into the payment workflow. Those four steps reveal what a new product would still need to solve.
Sources checked September 24, 2026: FTC email-authentication guidance, Google sender guidelines, Microsoft email-authentication operations guide, and FBI IC3 BEC information. This is documentation-based guidance, not an audit of your mail tenant.