Skip to content

Cybersecurity

Email Security & Phishing Protection

We harden business email at three levels: inbound filtering and phishing protection, correct SPF, DKIM and DMARC records so your domain cannot be spoofed, and MFA with a review of the forwarding rules attackers set up quietly after a mailbox has already been compromised.

Who it is for

  • Businesses handling invoices and payment instructions by email
  • Companies whose domain has been used to impersonate them
  • Organisations without MFA or without forwarding rule review
  • Shipping companies where operational instructions arrive by email

When we are NOT the right choice

  • If staff training is the requirement, which we do not provide
  • If there is no access to the domain DNS zone
  • If MFA cannot be enabled

PROCESS

The process

Indicative times from signature of the proposal, subject to hardware availability. Every project is shaped to the size and the needs of the client.

  1. 01Current state review

    We check SPF, DKIM and DMARC, MFA coverage, and the active forwarding rules across all mailboxes.Time: 2-5 working daysDeliverable: Findings report by severity

  2. 02DNS record remediation

    We correct the records so your own mail is delivered and forged mail carrying your domain is rejected.Time: 1-2 daysDeliverable: Correct SPF, DKIM and DMARC records

  3. 03Filtering and rules

    We configure inbound filtering and rules for high risk attachments and links.Time: During implementationDeliverable: Active filtering with logging

  4. 04MFA and forwarding review

    We enable MFA and remove suspicious forwarding rules. It is the first thing an attacker sets up after a compromise.Time: During implementationDeliverable: MFA everywhere and rules cleaned up

  5. 05Monitoring and reporting

    We monitor DMARC reports and incidents, and report periodically on what was detected.Time: Ongoing, under agreementDeliverable: DMARC and incident reporting

What is included

  • Review of SPF, DKIM, DMARC and MFA coverage
  • Correction of the domain DNS records
  • Inbound filtering and phishing protection
  • MFA enablement across all users
  • Review and cleanup of forwarding rules
  • Periodic findings reporting

What is not included

  • Staff training and phishing simulations
  • Penetration testing
  • Legal and compliance services
  • Incident investigation requiring forensic evidence standards

Technology and equipment

  • Microsoft 365
  • Exchange Online
  • SPF / DKIM / DMARC
  • Bitdefender
  • Microsoft Entra ID

From practice

Two findings repeat in almost every review. The first is DNS records that let anyone send mail carrying the company domain. The second is forwarding rules on mailboxes, created by someone who is not the owner.

The second is always the more alarming, because it means the compromise has already happened and nobody noticed. That is why the forwarding rule check comes first, before anything else.

Prerequisites

  • Access to the domain DNS zone
  • Administrative access to the email environment
  • A decision to enable MFA for all users
  • A list of mailboxes that approve payments or contracts

Cost

The initial review and remediation are quoted as a project. Ongoing monitoring, DMARC reporting and incident response sit within the support agreement, at a monthly charge per user.

We do not publish a price list. Every proposal follows a site survey and separates hardware from labour.

What moves the cost

  • Number of mailboxes and domains
  • Complexity of the existing DNS records
  • Whether third party systems send using your domain
  • SLA level for incident response

Frequently asked questions

Why do we receive messages that appear to come from us?

Because without correct SPF, DKIM and DMARC records, anyone can send mail that looks like it came from your domain. Those records are what allow a recipient to reject the forgery.

What does an attacker do once inside a mailbox?

Typically they create a forwarding or hiding rule, so they can read the correspondence without being noticed. That is why forwarding rule review is part of every check we run.

Do you run staff training?

No, we do not provide awareness training or phishing simulations. We focus on the technical measures: filtering, domain records, MFA and rule review.

Is MFA enough on its own?

It is the highest return measure, but not sufficient alone. Without correct DNS records your domain remains exploitable outward, even when your own accounts are protected.

NEXT STEP

Request an email security review

We check SPF, DKIM, DMARC, MFA and forwarding rules, and deliver a findings report ordered by severity.

GET IN TOUCH

Tell us what you need

Four fields. An engineer replies, not a sales desk.

Fields marked * are required.

By sending this form you accept the processing of your details under our Privacy Policy.