Updated: October 2026
Every company has one inbox that gets a convincing invoice this week. What stops it is a handful of settings you can change this afternoon. Here are the email security best practices that close the usual doors, in the order attackers walk through them, with a checklist at the end.
Why Email Is Still the Front Door
Email is where money and trust meet. A fake invoice, a changed bank account, a "quick favour" from the CEO: none of it needs malware, just a mailbox someone believes.
The FBI's 2025 Internet Crime Report counted 24,768 business email compromise complaints and just over $3 billion in reported losses. That's one crime type, in one country, from the victims who reported it.
The pattern behind those numbers is boring and repeatable. Steal a password, sign in, hide in the mailbox, wait for a payment conversation, then step into it. Each step has a setting that blocks it, and that's what this checklist is built around.
Lock the Accounts Before Anything Else
Filtering and training matter, but they come after identity. If an attacker can sign in, every other control is working against a real user.
Start with multifactor authentication on every mailbox, including shared and service accounts people forget about. Prefer phishing-resistant methods such as passkeys or FIDO keys for admins and finance. A plain push notification can be approved by a tired user at 11 p.m.
Then block legacy authentication. Older protocols like IMAP and POP can't do MFA, so a stolen password walks straight past it. Microsoft's own guidance on blocking legacy authentication says more than 99% of password spray attacks use those protocols. Conditional Access can block them, and tenants without it can turn on security defaults.
Passwords still matter here too. Attackers try the same short list everywhere, which is why a banned-password list pays off. Our breakdown of the most common passwords covers how.
Last, stop users from granting mailbox access to random apps. Some attacks skip the password entirely and trick a user into consenting to an app that reads mail. Require admin approval for new enterprise apps, and review what's already consented.
This r/sysadmin thread shows the pattern in the wild: a breached user, reset password and MFA, and then a mail-reading app registered two weeks earlier, still quietly holding access.
Prove Your Mail Is Yours
SPF, DKIM and DMARC let receiving servers check that mail claiming to be from your domain came from you. SPF lists your allowed senders, DKIM signs the message, and DMARC tells the world what to do when both fail. We walk through records and rollout in our DMARC guide, so here's the short version: publish all three, read the reports, and move DMARC toward reject.
It isn't optional for anyone who sends in volume. Google's sender guidelines have required SPF, DKIM and DMARC since February 2024 for anyone sending more than 5,000 messages a day to Gmail accounts, plus one-click unsubscribe for marketing mail.
One Microsoft 365 setting deserves a look while you're here. Direct Send lets devices like printers send to internal recipients without signing in, and attackers have abused it to spoof internal senders. If nothing in your office needs it, Set-OrganizationConfig -RejectDirectSend $true turns it off.
Shut the Forwarding Door
Forwarding is the quietest way to lose data. An attacker who gets in once creates an inbox rule that sends a copy of every message to an outside address, then leaves. The password reset that follows doesn't delete the rule.
In Microsoft 365, the switch lives in the outbound spam filter policy. Microsoft's page on external email forwarding lists three options: Automatic (system-controlled), On and Off. Microsoft itself recommends picking On or Off explicitly, because "system-controlled" behaves differently in different tenants. Set it to Off. Blocked forwards bounce with a 5.7.520 error, which makes the rare legitimate need easy to spot and allow.
Then check who was already forwarding. The Auto forwarded messages report in the Exchange admin center lists them. Google Workspace has a matching admin switch for automatic forwarding, and the same audit applies.
Keep watching after that. An alert on new inbox rules that forward, delete or move mail to obscure folders catches the next attempt while it's fresh.
Tag Outside Mail and Make Reporting One Click
A lot of BEC mail comes from outside, dressed up as inside. A visible "External" tag gives users a moment to notice. In Exchange Online, Set-ExternalInOutlook -Enabled $true adds a native External label in Outlook, and Microsoft notes it can take 24 to 48 hours to appear. If you already prepend "[EXTERNAL]" to subjects with a mail flow rule, turn that off first to avoid doubling up.
Reporting has to be easier than ignoring. Outlook's built-in Report button now does this across clients, and Microsoft has put its older Report Message and Report Phishing add-ins into maintenance mode ahead of deprecation. Send reports to a mailbox someone reads, and reply to the people who report. A thank-you is the cheapest security control there is.
When a Mailbox Gets Compromised Anyway
Controls reduce the odds. They don't make them zero, so write the first hour down before you need it.
This r/msp thread walks through a real case: a client clicked a "shared document" from a compromised friend, and the MSP had to work out what the attacker touched. The replies are a solid checklist on their own.
The order matters. Revoke sessions and reset the password together, or the attacker keeps a live token. Check MFA methods for anything added recently, then inbox rules and forwarding, then app consents. Pull the audit log for mail read, sent and deleted. Finally, warn the people the account emailed during the window, because they're next.
None of that works if audit logging was off. Confirm unified audit logging is enabled on every tenant now, while nothing is on fire.
Training That Changes Behaviour
Phishing simulations help when they teach one habit at a time. The habit that saves the most money is simple: any change to payment details gets confirmed by phone, using a number you already had, never one in the email.
Keep the rest short and frequent. Show real examples from your own filters, not stock images. Praise reporting, including false alarms. Our guide to security awareness training covers a rollout that people don't dread.
The Email Security Checklist
Use this as a quarterly review. Most items are a setting, not a purchase.
| Control | Where | Done |
|---|---|---|
| MFA on every mailbox, phishing-resistant for admins and finance | Entra ID / Google Admin | ☐ |
| Legacy authentication blocked | Conditional Access or security defaults | ☐ |
| Admin approval required for new app consents | Entra ID enterprise apps | ☐ |
| SPF, DKIM and DMARC published, DMARC moving to reject | DNS | ☐ |
| Direct Send rejected if nothing needs it | Exchange Online PowerShell | ☐ |
| External auto-forwarding set to Off | Outbound spam policy | ☐ |
| Existing forwards reviewed | Auto forwarded messages report | ☐ |
| Alerts on new forwarding or delete rules | Defender / SIEM | ☐ |
| External sender tag on | Set-ExternalInOutlook | ☐ |
| Report button live, reports go to a watched mailbox | Defender user reported settings | ☐ |
| Unified audit logging on | Microsoft Purview | ☐ |
| Payment-change callback rule written and trained | Finance process | ☐ |
Jonathan Edwards walks through the Microsoft 365 policies behind most of these rows in about 20 minutes, which is handy if you're setting them up for the first time.
Start With the Forwarding Switch
Email security comes down to a short list of switches and one habit. Lock the accounts, prove your mail, shut forwarding, tag outside mail, and make reporting easy.
If you only do one thing today, set external forwarding to Off and review who was forwarding before. When you're ready to add a dedicated filtering layer, our roundup of email security solutions compares the options.

Head Of Marketing
Hi all! My name is Vlad and I’ve been brought on to head the marketing team at Flamingo. Thankfully, this isn’t the first time I will be building a marketing department from scratch, so the experience should come in handy. Now it’s time to dive into the world of MSPs and find myself in this new world.
