Email Security Settings Worth Turning On Today

If you could only improve the security of one system this month, email would be a strong candidate. It is how most phishing arrives, how many account takeovers begin and how fraudulent payment requests reach the business office. It also holds sensitive information, from resident details to financial documents.

The good news is that many valuable protections are settings, not products. Whether your organization uses Microsoft 365, Google Workspace or another service, the following are worth checking with your IT provider.

Require Multi-Factor Authentication

MFA is the single most effective step against stolen passwords. Require it for every mailbox, including shared and executive accounts, and turn off older sign-in methods that bypass it, often called legacy authentication or basic authentication. If your organization has mail clients using such protocols, plan to retire them.

Protect Your Domain From Spoofing

Three email standards help receiving mail systems verify that a message really came from your domain:

SPF (Sender Policy Framework): a DNS record listing the servers allowed to send email for your domain.

DKIM (DomainKeys Identified Mail): adds a digital signature to outgoing messages.

DMARC: tells receiving systems what to do with messages that fail SPF and DKIM checks, and provides reports about who is sending mail in your name.

A common path is to publish DMARC in monitoring mode, review reports to make sure legitimate senders such as your billing system and newsletter tool are properly configured, then move gradually to a policy that quarantines or rejects fraudulent mail. Done properly, this makes it much harder for criminals to send convincing messages that appear to come from your own domain.

Turn On Advanced Filtering

Basic spam filters catch only part of the problem. Look for features that provide:

Attachment scanning and sandboxing, which opens suspicious files in a safe environment

Link protection that checks URLs when clicked, not just when received

Impersonation protection for executives and key staff names

Detection of lookalike domains

Blocking of dangerous file types

Automatic removal of malicious messages that are discovered after delivery

These capabilities may require specific licenses, so check what your subscription includes.

Label External Messages

Add a visible banner or tag to messages from outside your organization. Staff are more cautious when they are reminded that a message claiming to be from the administrator actually came from an external address. Keep the banner short and consistent so it does not become noise.

Lock Down Forwarding and Rules

Attackers who gain access to a mailbox often create hidden rules to forward copies of messages to an outside address or to delete security alerts. Consider:

Blocking automatic forwarding to external addresses, with approved exceptions

Alerting when new mailbox rules or forwarding settings are created

Reviewing mailbox audit logs for suspicious sign-ins

Restricting who can create connectors or third-party app access

Control Third-Party App Access

Users can sometimes grant outside applications permission to read their mail with one click. Limit this so that only approved applications can be authorized, and review existing authorizations.

Encrypt Sensitive Messages

When staff must email protected health information outside the organization, use an encryption feature built into your email platform or a secure portal. Define when encryption is required, and consider rules that automatically encrypt messages containing patterns such as Social Security numbers. The HIPAA Security Rule addresses transmission security, and encrypting messages is a common way to meet that expectation.

Set Up Reporting and Response

Give users a simple way to report suspicious messages

Make sure someone reviews reports promptly

Create a procedure for removing a malicious message from all mailboxes

Know how to quickly reset a compromised account, revoke sessions and review activity

Add Sensible Retention and Backup

Email may be involved in legal or compliance matters. Define retention policies and consider backup of mailboxes, since cloud providers generally do not guarantee recovery of accidentally or maliciously deleted data beyond limited windows.

Quick Checklist

MFA on all accounts

Legacy authentication disabled

SPF, DKIM and DMARC published

Advanced filtering enabled

External sender banner on

Auto-forwarding restricted

Third-party app consent controlled

Encryption available for sensitive messages

Logging and alerting enabled

Help Is Available

These settings are simple in principle but easy to misconfigure. UnityCare IT can audit your email configuration, correct gaps and monitor for suspicious activity so your inbox is a little less hospitable to attackers.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172