Skip to main content

Business systems

Email Security

Business email is both a communication channel and a password-reset route. If it is compromised, an attacker may impersonate staff and take over connected services.

Plain-English guidance · Last reviewed 24 July 2026

On this page

The business case

Why it matters

A convincing message sent from a real mailbox is difficult for customers and colleagues to spot. Attackers can study old conversations, alter payment details or create inbox rules that hide replies.

Email security combines identity controls with domain records and business process. SPF, DKIM and DMARC help receiving systems assess authorised mail, while independent verification helps people catch fraud that technology misses.

Know the exposure

Common risks

01

Mailbox takeover

Phished credentials, session theft and weak recovery can expose correspondence and password-reset links.

02

Business email compromise

Attackers impersonate leaders, suppliers or customers to redirect payments or sensitive information.

03

Domain spoofing

Missing or poorly maintained authentication policies make unauthorised use of the business domain harder to reject.

Investigate, do not ignore

Warning signs

  • Unexpected sign-ins, MFA changes, forwarding rules or deleted-message rules
  • Suppliers or customers report unusual invoices, links or tone
  • Messages fail authentication or legitimate senders are missing from the domain inventory
  • Payment details change by email without an independent verification process
  • Old shared mailboxes, delegates or third-party applications retain access

Reduce likelihood and impact

Practical steps

  1. 01

    Protect identities

    Use individual accounts, MFA, safe recovery details, limited administrators and regular review of sessions, delegates and applications.

  2. 02

    Inventory legitimate sending

    List the mail provider, website forms, marketing platforms, invoicing tools and other services authorised to use the domain.

  3. 03

    Configure domain authentication

    Implement and maintain SPF, DKIM and DMARC deliberately, monitor results and avoid breaking legitimate mail through an unplanned enforcement change.

  4. 04

    Verify sensitive requests

    Confirm payment, bank-detail, password-reset and sensitive-data requests through a trusted route independent of the message.

  5. 05

    Make reporting easy

    Give staff a quick way to report suspicious messages or accidental clicks, then preserve relevant evidence and review the affected account.

Defined website support

How AHANIX can help

AHANIX can support the website and domain-record parts of email security and coordinate changes with the organisation’s email provider.

  • Identify website forms and web services that send using the business domain
  • Review and update relevant SPF, DKIM and DMARC DNS records with provider instructions
  • Separate website delivery problems from tenant-wide mailbox or identity issues

Clear limits

What this cannot guarantee

  • Email authentication cannot guarantee delivery or stop every lookalike domain, compromised mailbox, malicious attachment or social-engineering attempt.
  • AHANIX does not operate a mail security gateway or provide full mailbox forensics, continuous monitoring or tenant-wide managed security.

Continue with existing resources

Relevant tools and guides

These links use existing AHANIX tools and guides for the next useful check or deeper explanation.

Common questions

Email security questions

What do SPF, DKIM and DMARC do?

SPF identifies permitted sending infrastructure, DKIM adds a verifiable signature and DMARC tells receivers how to evaluate aligned results and where to send reports. They must reflect the real sending services.

Can DMARC stop all spoofing?

No. It helps with unauthorised use of the exact protected domain when messages are evaluated correctly, but it does not stop lookalike domains or a compromised legitimate mailbox.

Why should bank-detail changes be verified outside email?

If either mailbox is compromised, replies can be intercepted or altered. Calling a previously known number or using another trusted route breaks that single channel of trust.

A scoped next step

Protect the domain behind website email

AHANIX can map website senders and coordinate the relevant DNS records with your email or IT provider.

Review website email setup

Continue in the Security Centre