← Microsoft 365 audit scope

Exchange Online & Email Security

10 checks · 2 sub-categories

Email is both the target and the tool in most Australian business cybercrime. This section covers the settings that stop someone spoofing your domain, quietly forwarding your mail to a Gmail address, or operating inside a compromised mailbox without leaving a trace.

Domain authentication

  • SPF record published and correct

    Verifies your SPF record exists, lists the right senders, and doesn't exceed the DNS lookup limit that silently breaks it.

  • DKIM enabled for every accepted domain

    DKIM signing is not on by default for custom domains in Microsoft 365. We check every accepted domain, not just the primary one.

    • CIS 4.7
  • DMARC policy published and enforced

    A policy of p=none gives visibility only. We report whether yours is actually set to quarantine or reject, and whether reports are going anywhere useful.

    • ACSC — email hardening guidance
  • External sender tagging enabled

    Outlook's native External tag gives staff an instant visual cue that a message claiming to be from the boss came from outside.

Mailbox and mail flow controls

  • Automatic external forwarding blocked

    The outbound anti-spam policy should block auto-forwarding to external addresses. This is the single most common exfiltration mechanism after a mailbox compromise.

    • Privacy Act / NDB — preventing unauthorised disclosure
  • Existing forwarding and inbox rules reviewed

    We enumerate every mailbox rule that forwards, redirects or deletes mail — including the classic 'move anything mentioning invoice to RSS Feeds' rule attackers create.

  • Sign-in blocked on shared mailboxes

    Shared mailboxes have real accounts behind them. If sign-in isn't blocked, they're licence-free, MFA-free doors into the tenant.

  • Modern authentication enforced for Exchange and Outlook

    Confirms basic authentication is disabled across every Exchange protocol so MFA cannot be bypassed by an older client.

    • Essential Eight — Multi-factor authentication
    • CIS 1.2
  • Transport rules reviewed for risky exceptions

    Rules that bypass spam filtering, allow-list a domain or silently BCC a copy of all mail are all reported.

  • Mailbox auditing enabled organisation-wide

    Without mailbox auditing you cannot answer the question every insurer and regulator asks after a breach: what did they actually read?

    • Privacy Act / NDB — breach assessment
    • CIS 5.3

Want to know where you actually stand?

Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.