When does email require security?
Problems we help solve
Email is one of the main channels of attack on a company. Even a properly functioning mailbox can be poorly secured if the domain does not have the right records, users do not have MFA, and message forwarding rules are not controlled.
- Customers receive messages impersonating the company's domain.
- Employees receive fake invoices, login links or transfer requests.
- Email accounts do not have MFA or use older login methods.
- There are unknown redirection and automatic reply rules in the mailboxes.
- There are no rules for attachments, links, spam and message quarantine.
Fit
Who is this service for?
Companies with Microsoft 365
We configure Exchange Online security, MFA, rules and domain protection.
Companies after a phishing attempt
We check accounts, logs, mailbox rules and traces of unauthorised access.
Companies with their own domain
We clean up SPF, DKIM and DMARC records to reduce address spoofing.
Sales and accounting teams
We are strengthening the protection of departments particularly exposed to false invoices and payments.
Service scope
What does email security cover?
Domain protection
We configure mechanisms that make it difficult to impersonate a company.
- SPF, DKIM and DMARC,
- verification of sending systems,
- DMARC policy recommendations.
Access to accounts
We secure login and limit the risk of inbox hijacking.
- MFA and conditional access,
- disabling older protocols,
- overview of privileged accounts.
Filters and rules
We organise protection against spam, phishing and malicious messages.
- anti-phishing policies,
- link and attachment protection,
- quarantine and reporting news.
Mailbox review
We check for items that often appear after an account is compromised.
- redirection rules,
- delegations and full access,
- login logs and unusual activities.
Outcomes
What will you receive?
- better secured domain and lower risk of spoofing,
- MFA, legacy protocols and mailbox access control,
- structured email rules, filters and quarantine,
- list of detected risks and recommended changes,
- documentation of configuration and rules for handling suspicious messages.
The scope may include a one-off review, security configuration, or ongoing email and alert support.
Delivery approach
How is the service delivered?
- Discovery. We determine the email system, domains and user problems.
- Overview. We check DNS, MFA, rules, filters, delegations and logs.
- Priorities. We indicate settings that require urgent correction.
- Configuration. We implement records, policies, rules and account security.
- Tests. We confirm email delivery and protection.
- Instructions. We provide recommendations for users and administrators.
Security standards
How do we carry out the work?
- We implement changes to DNS and email policies in stages so as not to block communication.
- We do not base protection solely on the anti-spam filter.
- We check inbox rules because they often reveal signs of account hijacking.
- We document exceptions for systems sending email from the company domain.
- We combine technical setup with simple phishing reporting rules.
Cost
What determines the price?
The price depends on the number of domains, mailboxes, tenants, email sending systems, the scope of log analysis, Microsoft 365 licence and the need for training or phishing tests.
FAQ
Frequently asked questions
Are SPF, DKIM and DMARC necessary?
They are very important if a company sends email from its own domain and wants to limit impersonation of the sender.
Is MFA enough to protect email?
MFA helps significantly, but it's worth combining it with filters, rule checking, logs and domain protection.
Is it possible to check if an account has been compromised?
We can analyse logins, mailbox rules, delegations and unusual activities in available logs.
Can changing DMARC stop sending emails?
Yes, if implemented without analysis of shipping sources. That's why we're starting carefully with monitoring and a gradual policy.
Will you prepare instructions for employees?
Yes. We can prepare simple rules for reporting suspicious messages and safe handling of attachments.