Email Security Tips for Businesses: How to Protect Microsoft 365, Staff and Your Domain
Email remains essential to almost every business.
It is also one of the easiest ways for an attacker to reach your employees.
A single convincing message can lead to:
stolen Microsoft 365 credentials
fraudulent payments
malicious attachments
compromised mailboxes
fake supplier invoices
data theft
account impersonation
That means effective email security has to go much further than installing a spam filter.
The strongest approach combines identity security, email authentication, filtering, business processes, employee awareness and rapid incident response. The NCSC recommends exactly this kind of layered defence rather than relying on users to identify every malicious email themselves.
Why Email Accounts Are So Valuable to Attackers
A compromised mailbox can give an attacker much more than access to messages.
It may reveal:
customer and supplier relationships
invoices and payment discussions
password-reset emails
internal conversations
confidential documents
calendars
contact information
More importantly, access to a real mailbox allows attackers to impersonate somebody from inside a genuine business account.
That makes later fraud much more convincing than a basic spoofed phishing email.
The attacker might monitor an existing conversation for weeks and then intervene just as an invoice is due.
That is why mailbox security is really identity and business-process security, not simply email filtering.
1. Protect Every Account With Strong Authentication
Every employee should have multi-factor authentication.
But in 2026, businesses should also ask:
What type of MFA are we using?
Traditional SMS codes and conventional approval prompts are better than relying on passwords alone, but Microsoft increasingly recommends phishing-resistant authentication, including passkeys/FIDO2 and Windows Hello for Business.
This matters because sophisticated phishing attacks can attempt to capture not only the password but also the user's second authentication step.
A passkey changes that model by using cryptographic authentication rather than giving the employee a reusable password or code that can simply be typed into a fake website. Microsoft describes FIDO2 passkeys as phishing-resistant credentials suitable for strong authentication.
For privileged accounts, the case is even stronger.
Microsoft recommends phishing-resistant MFA for sensitive administrative roles through Conditional Access authentication strengths.
SMS MFA Is No Longer the End Goal
There is also an important upcoming Microsoft change.
From 1 September 2026, Microsoft says passkeys become the default authentication experience for Entra users enabled for SMS or voice authentication. Microsoft-provided SMS and voice delivery is then scheduled to retire on 1 February 2027.
If your Microsoft 365 environment still depends heavily on text-message MFA, now is a sensible time to review that strategy.
2. Configure SPF, DKIM and DMARC Properly
Your domain needs protection too.
SPF, DKIM and DMARC help receiving mail systems determine whether a message claiming to come from your domain is genuinely authorised.
Microsoft’s current email-authentication guidance treats the three technologies as complementary controls.
SPF
SPF identifies which mail systems are authorised to send email on behalf of your domain.
The NCSC recommends publishing SPF records covering the legitimate systems that send mail for your organisation.
DKIM
DKIM adds a cryptographic signature to outgoing messages.
Receiving systems can verify that signature and confirm the message was signed by an authorised domain.
DMARC
DMARC ties SPF and DKIM to the domain visible in the message's From address and defines what receiving organisations should do when authentication fails.
This is where many businesses stop too early.
A DMARC record configured only for monitoring can provide useful reports, but eventually the objective should normally be enforcement once every legitimate sender has been identified and aligned.
Microsoft's current guidance recommends DMARC for organisational domains and, where appropriate, moving towards an enforcement policy such as p=reject.
Do not jump straight to reject without checking:
Microsoft 365
CRM systems
marketing platforms
finance systems
website forms
ticketing systems
other third-party senders
A poorly planned DMARC rollout can block your own legitimate email.
3. Protect Domains You Don't Use for Email
Businesses often protect their main mail domain and forget everything else they own.
If your company owns several domains but only one sends email, the unused domains should still have appropriate anti-spoofing protection.
The NCSC specifically recommends protecting parked or non-mailing domains with restrictive SPF and DMARC records so criminals cannot easily impersonate them.
That is a small configuration change that can help protect your brand and customers.
4. Use Advanced Email Filtering
A modern email security platform should look beyond obvious spam.
Depending on the platform and licence, useful protections can include:
malicious-link analysis
attachment scanning
impersonation detection
spoof protection
sender reputation
behavioural signals
malware analysis
Microsoft 365 itself uses traditional SPF/DKIM/DMARC results alongside additional signals such as sender reputation, sender history, recipient history and behavioural analysis when evaluating inbound messages.
But no filtering system catches everything.
That is why security should assume some malicious messages will reach employees.
5. Make Financial Verification a Business Rule
One of the most dangerous email attacks does not need malware at all.
An attacker may impersonate:
a director
supplier
customer
finance employee
and request:
“Please pay this invoice using our new bank details.”
The best defence is not simply:
“Look carefully at the email.”
The organisation should have a fixed procedure.
Changes to bank details and unusual payments should be verified through a separate, previously trusted communication channel.
Do not use the telephone number included in the same email requesting the change.
The NCSC recommends independent verification as part of defending organisations against phishing and impersonation fraud.
For high-value transactions, dual approval may also be appropriate.
6. Block or Control External Auto-Forwarding
A compromised mailbox can be more useful to an attacker if they can silently copy messages elsewhere.
Attackers may create forwarding rules or inbox rules that:
redirect email
delete security alerts
hide replies
move particular conversations
Your existing article is right to treat this as an important control.
Unless there is a genuine business requirement, external automatic forwarding should normally be restricted and monitored.
If somebody needs forwarding for a legitimate workflow, document the exception.
7. Monitor Sign-Ins and Authentication Changes
Email security should not stop at the inbox.
Monitor identity activity too.
Useful signals can include:
unusual sign-in locations
unfamiliar devices
risky sign-ins
repeated failures
unexpected MFA registrations
suspicious application access
administrator changes
The existing article already correctly emphasises that an alert has little value if nobody reviews it.
For a managed environment, the question should be:
Who sees serious identity alerts, and what happens next?
8. Review Mailbox Permissions
Mailboxes accumulate access over time.
An employee covers somebody's maternity leave.
Finance temporarily grants another person access.
A manager leaves.
Years later, the permissions may still exist.
Regularly review:
Full Access
Send As
Send on Behalf
shared mailbox membership
distribution-group ownership
access to finance/HR mailboxes
Remove access when it is no longer required.
This is simply least privilege applied to email.
9. Keep Administrator Accounts Out of Email
A privileged administrator account should not normally be used for everyday:
browsing
document work
If that account is compromised, the consequences can be dramatically worse than compromising an ordinary user's mailbox.
Use separate identities for administrative work and protect privileged accounts with stronger authentication and Conditional Access controls. Microsoft specifically recommends phishing-resistant MFA for sensitive administrative roles.
10. Secure the Device Accessing the Mailbox
A well-configured Microsoft 365 tenant cannot fully protect a mailbox being accessed from a badly compromised endpoint.
Business devices should therefore have appropriate controls such as:
endpoint protection
device encryption
current security updates
screen-lock policies
device management
For mobile access, Microsoft Intune and Conditional Access can also help organisations control which devices and applications are allowed to access business information.
The existing article is right to connect email security with endpoint security rather than treating the mailbox as an isolated system.
11. Train Employees — But Don't Make Them Your Email Filter
Security awareness remains important.
Employees should understand:
fake Microsoft 365 login pages
payment fraud
suspicious attachments
unexpected authentication prompts
impersonation
unusual bank-detail changes
But the NCSC explicitly recommends layered phishing defences, recognising that employees cannot reliably identify every malicious message.
So training should answer:
What looks unusual?
What should I verify?
How do I report it?
rather than:
“You must never be fooled.”
12. Make Reporting Extremely Easy
Employees should have an obvious way to report suspicious email.
That could include:
a Report Phishing button
helpdesk portal
dedicated security mailbox
IT telephone number
The faster IT learns about a suspicious message, the faster it can investigate whether other employees received the same attack.
And if somebody already clicked, entered credentials or approved an unexpected login, reporting becomes even more urgent.
A blame-oriented culture encourages delay.
A useful response is:
“Thanks for reporting it quickly. We'll investigate.”
13. Be Careful With Phishing Simulations
Simulated phishing can be useful, but don't turn it into an employee trap.
Use results to understand:
which attack themes work
which departments need extra support
how quickly employees report attacks
whether procedures are understood
The NCSC warns against overly punitive approaches because they can reduce trust and discourage reporting.
The most useful metric is not necessarily:
“How many people clicked?”
It may be:
“How quickly did somebody report it?”
14. Have an Email Compromise Playbook
This is where I would strengthen the original article most.
You should know what happens before somebody's Microsoft 365 mailbox is compromised.
A practical response may include:
1. Disable or secure the compromised identity.
2. Reset credentials where appropriate.
3. Revoke active sessions.
4. Review registered MFA methods.
5. Inspect recent sign-ins.
6. Check inbox and forwarding rules.
7. Review delegated mailbox permissions.
8. Check application/OAuth consent.
9. Search for malicious messages sent from the account.
10. Identify affected customers or suppliers.
11. Preserve logs and evidence.
12. Contact the bank immediately if financial fraud is involved.
The live article already contains much of this material; I would move it higher and make it one of the article's main pillars rather than item 20 in a long list.
15. Remember That Email Security Protects Your Customers Too
SPF, DKIM and DMARC do not merely protect employees.
They make it harder for criminals to impersonate your company to:
customers
suppliers
applicants
partners
The NCSC specifically frames email anti-spoofing as a way to make fake emails using your domain more difficult to send successfully.
Businesses can reinforce this technically and procedurally.
For example:
“We will never communicate changed bank details solely by email without additional verification.”
That gives customers something concrete to check when a fraudulent invoice appears.
A Practical Email Security Baseline for SMEs
Rather than treating email security as 20 unrelated tasks, I would organise it into six areas:
Identity: phishing-resistant MFA, separate administrator accounts, Conditional Access.
Domain: SPF, DKIM, DMARC and protection for unused domains.
Filtering: anti-phishing, malicious-link and attachment protection.
Business processes: independent payment verification and controlled forwarding.
People and devices: secure endpoints, awareness and simple reporting.
Response: monitoring, session revocation, mailbox-rule checks and a documented compromise procedure.
That structure makes it much easier for a business to see where its real gaps are.
How Hamilton Group Can Help
Hamilton Group can help businesses secure Microsoft 365 email against phishing, impersonation, account takeover and payment fraud.
We can assist with:
Microsoft 365 security reviews
SPF, DKIM and DMARC
phishing-resistant MFA and passkeys
Microsoft Entra ID
Conditional Access
Microsoft Defender
mailbox monitoring
email forwarding controls
security awareness
endpoint protection
incident-response planning
managed IT support
The objective isn't simply to stop spam.
It is to protect the identity, data, money and trust connected to every business mailbox.
Visit hgmssp.com or call 0330 043 0069 to discuss email and Microsoft 365 security.