Email security best practices for a small business come down to five things: multi-factor authentication on every mailbox, email authentication so your domain cannot be spoofed, good filtering, encryption for sensitive messages, and staff who can spot a scam. Email is how most attacks start.
1. MFA on every mailbox
The single highest-value control. A stolen password alone should never be enough to read your email. Turn on multi-factor authentication for all users, including shared and admin accounts.
2. Authenticate your domain
SPF, DKIM and DMARC are DNS records that let receiving servers verify mail really came from you. Without them, anyone can send email that appears to be from your domain – the basis of business email compromise. DMARC set to reject is the goal.
3. Filtering
Business-grade filtering catches phishing, malware and impersonation before it reaches the inbox. Microsoft 365 and Google Workspace include a baseline; add-on filtering improves it further.
4. Encryption for sensitive mail
Use the encryption built into Microsoft 365 or Google Workspace for anything containing personal, financial or health information – or better, a secure portal instead of email.
5. Training and process
- Regular phishing awareness training
- A blame-free way to report suspicious messages
- Payment and bank-detail changes verified by phone, never by email reply
We configure all of this as part of our cybersecurity and cloud services.
Related security guides
- What a firewall does
- Multi-factor authentication explained
- Network segmentation
- EDR vs antivirus vs MDR
- Security awareness training
- How to prevent ransomware
Want this handled? See our cybersecurity service or talk to our Edmonton team.
Frequently asked questions
Is Microsoft 365 email secure by default?
It has a reasonable baseline, but MFA is often off, DMARC is usually not configured, and the default filtering can be tightened. The platform is capable; it needs setting up.
What is DMARC and do we need it?
DMARC tells receiving mail servers what to do with email that fails authentication checks for your domain. Set to ‘reject’, it stops most spoofing of your domain. Yes, a business should have it.
Should we encrypt all email?
Not all – encrypt anything with personal, financial or health data. For routine mail, authentication and filtering matter more.
How does Scandifix help?
We turn on MFA, configure SPF/DKIM/DMARC, tune filtering, set up encryption, and run staff training.