Exchange Online & Email Security
10 checks · 2 sub-categories
Email is both the target and the tool in most Australian business cybercrime. This section covers the settings that stop someone spoofing your domain, quietly forwarding your mail to a Gmail address, or operating inside a compromised mailbox without leaving a trace.
Domain authentication
SPF record published and correct
Verifies your SPF record exists, lists the right senders, and doesn't exceed the DNS lookup limit that silently breaks it.
DKIM enabled for every accepted domain
DKIM signing is not on by default for custom domains in Microsoft 365. We check every accepted domain, not just the primary one.
- CIS 4.7
DMARC policy published and enforced
A policy of p=none gives visibility only. We report whether yours is actually set to quarantine or reject, and whether reports are going anywhere useful.
- ACSC — email hardening guidance
External sender tagging enabled
Outlook's native External tag gives staff an instant visual cue that a message claiming to be from the boss came from outside.
Mailbox and mail flow controls
Automatic external forwarding blocked
The outbound anti-spam policy should block auto-forwarding to external addresses. This is the single most common exfiltration mechanism after a mailbox compromise.
- Privacy Act / NDB — preventing unauthorised disclosure
Existing forwarding and inbox rules reviewed
We enumerate every mailbox rule that forwards, redirects or deletes mail — including the classic 'move anything mentioning invoice to RSS Feeds' rule attackers create.
Sign-in blocked on shared mailboxes
Shared mailboxes have real accounts behind them. If sign-in isn't blocked, they're licence-free, MFA-free doors into the tenant.
Modern authentication enforced for Exchange and Outlook
Confirms basic authentication is disabled across every Exchange protocol so MFA cannot be bypassed by an older client.
- Essential Eight — Multi-factor authentication
- CIS 1.2
Transport rules reviewed for risky exceptions
Rules that bypass spam filtering, allow-list a domain or silently BCC a copy of all mail are all reported.
Mailbox auditing enabled organisation-wide
Without mailbox auditing you cannot answer the question every insurer and regulator asks after a breach: what did they actually read?
- Privacy Act / NDB — breach assessment
- CIS 5.3
Want to know where you actually stand?
Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.