If you could only improve the security of one system this month, email would be a strong candidate. It is how most phishing arrives, how many account takeovers begin and how fraudulent payment requests reach the business office. It also holds sensitive information, from resident details to financial documents.
The good news is that many valuable protections are settings, not products. Whether your organization uses Microsoft 365, Google Workspace or another service, the following are worth checking with your IT provider.
MFA is the single most effective step against stolen passwords. Require it for every mailbox, including shared and executive accounts, and turn off older sign-in methods that bypass it, often called legacy authentication or basic authentication. If your organization has mail clients using such protocols, plan to retire them.
Three email standards help receiving mail systems verify that a message really came from your domain:
SPF (Sender Policy Framework): a DNS record listing the servers allowed to send email for your domain.
DKIM (DomainKeys Identified Mail): adds a digital signature to outgoing messages.
DMARC: tells receiving systems what to do with messages that fail SPF and DKIM checks, and provides reports about who is sending mail in your name.
A common path is to publish DMARC in monitoring mode, review reports to make sure legitimate senders such as your billing system and newsletter tool are properly configured, then move gradually to a policy that quarantines or rejects fraudulent mail. Done properly, this makes it much harder for criminals to send convincing messages that appear to come from your own domain.
Basic spam filters catch only part of the problem. Look for features that provide:
Attachment scanning and sandboxing, which opens suspicious files in a safe environment
Link protection that checks URLs when clicked, not just when received
Impersonation protection for executives and key staff names
Detection of lookalike domains
Blocking of dangerous file types
Automatic removal of malicious messages that are discovered after delivery
These capabilities may require specific licenses, so check what your subscription includes.
Add a visible banner or tag to messages from outside your organization. Staff are more cautious when they are reminded that a message claiming to be from the administrator actually came from an external address. Keep the banner short and consistent so it does not become noise.
Attackers who gain access to a mailbox often create hidden rules to forward copies of messages to an outside address or to delete security alerts. Consider:
Blocking automatic forwarding to external addresses, with approved exceptions
Alerting when new mailbox rules or forwarding settings are created
Reviewing mailbox audit logs for suspicious sign-ins
Restricting who can create connectors or third-party app access
Users can sometimes grant outside applications permission to read their mail with one click. Limit this so that only approved applications can be authorized, and review existing authorizations.
When staff must email protected health information outside the organization, use an encryption feature built into your email platform or a secure portal. Define when encryption is required, and consider rules that automatically encrypt messages containing patterns such as Social Security numbers. The HIPAA Security Rule addresses transmission security, and encrypting messages is a common way to meet that expectation.
Give users a simple way to report suspicious messages
Make sure someone reviews reports promptly
Create a procedure for removing a malicious message from all mailboxes
Know how to quickly reset a compromised account, revoke sessions and review activity
Email may be involved in legal or compliance matters. Define retention policies and consider backup of mailboxes, since cloud providers generally do not guarantee recovery of accidentally or maliciously deleted data beyond limited windows.
MFA on all accounts
Legacy authentication disabled
SPF, DKIM and DMARC published
Advanced filtering enabled
External sender banner on
Auto-forwarding restricted
Third-party app consent controlled
Encryption available for sensitive messages
Logging and alerting enabled
These settings are simple in principle but easy to misconfigure. UnityCare IT can audit your email configuration, correct gaps and monitor for suspicious activity so your inbox is a little less hospitable to attackers.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172