Skip to content

What an Email Security Audit Should Check

What an Email Security Audit Should Check

What an Email Security Audit Should Check

A convincing invoice request sent from a familiar supplier address can reach a finance team in seconds. If one person acts before checking it, the result may be a fraudulent payment, exposed credentials or a wider compromise of the network. An email security audit examines the controls around those everyday messages, so weaknesses can be addressed before they interrupt the business.

For Irish organisations, email is not simply a communication tool. It carries purchase orders, payroll information, customer records, contracts and access to Microsoft 365 services. The audit therefore needs to look beyond spam filtering. It should establish who can access mailboxes, what data can leave the business, whether genuine messages are protected from impersonation and how quickly the organisation could respond to an incident.

Why an email security audit matters

Most email incidents do not begin with a dramatic technical failure. They begin with an old account that was never removed, an employee approving an unexpected sign-in prompt, or a supplier’s domain being copied closely enough to pass a hurried glance. Hybrid working has made these risks more difficult to see, particularly where users work across personal devices, mobile phones and several locations.

A useful audit turns assumptions into evidence. It identifies whether the protections configured in Microsoft 365 or another email platform are appropriate for the organisation, whether they are being used properly and whether they work together. It also gives directors and internal IT teams a clear prioritised plan rather than a long list of security settings with no business context.

The right depth depends on the business. A small firm with a limited number of mailboxes may need a focused review of identity, phishing controls and backup arrangements. A multi-site organisation handling sensitive customer or financial data may also need to review mail flow rules, delegated access, third-party applications, retention requirements and incident processes.

Begin with mailbox access and identity

Email security starts with identities. If an attacker gains control of a legitimate mailbox, even strong filtering may not prevent them reading correspondence, setting forwarding rules or sending credible messages to colleagues and customers.

The audit should review all active accounts, shared mailboxes, administrator accounts and external guest access. Accounts belonging to former staff, dormant test users and old contractors should be disabled or removed. Shared mailboxes need named owners, because an account without ownership is rarely reviewed with the care it requires.

Multi-factor authentication should be enforced for all users, with additional protection for administrators and finance staff. However, simply switching it on is not the end of the task. The review should check for legacy authentication methods, weak recovery options and conditional access policies that create unintended gaps. For example, blocking risky sign-ins is valuable, but a policy that makes remote access impractical may encourage people to find workarounds.

It is also sensible to examine delegated mailbox permissions. Executive assistants, accounts teams and managers may need access to shared communications, but permissions should match the current role and be reviewed regularly. The same applies to third-party applications that have been granted access to mailboxes through Microsoft 365.

Check protection against phishing and impersonation

Phishing controls need to reflect the types of messages your staff actually receive. A construction company may be targeted with false payment details and tender documents. A professional services firm may see fraudulent document-sharing requests. A business with overseas suppliers may be exposed to invoice diversion attempts that appear to come from an established contact.

An audit should assess anti-phishing, anti-spam and malware policies, including how suspicious attachments and links are handled. It should also review the process for releasing quarantined messages. Security that stops legitimate customer emails can affect sales and service, while settings that are too relaxed leave users to make difficult judgement calls unaided.

Impersonation protection deserves specific attention. Policies should identify high-risk people and domains, such as directors, finance contacts, key suppliers and close variations of the company name. The aim is not to block every unusual message. It is to flag or quarantine messages that show credible signs of fraud while giving staff a straightforward way to report anything suspicious.

Verify your domain’s email authentication

A business should be able to demonstrate that emails sent in its name are genuine. That requires correctly configured SPF, DKIM and DMARC records. These controls help receiving email systems assess whether a message is authorised to use your domain, reducing the opportunity for criminals to impersonate it.

This area often becomes complicated when a business uses several services to send email, such as Microsoft 365, a marketing platform, a customer relationship system, an accounts package or a website contact form. If a legitimate sender is omitted from SPF or DKIM, messages may fail authentication. If DMARC is set too aggressively before the environment is understood, legitimate communications can be rejected.

The audit should map every approved sending service, check the current records and review DMARC reporting. A staged approach is usually sensible: monitor first, correct unauthorised or misconfigured sources, then move towards stronger enforcement when the evidence supports it. This protects the brand without disrupting important messages.

Review mail flow, data handling and forwarding

Email rules can quietly create serious exposure. A compromised mailbox may be configured to forward messages externally, giving an attacker a continuing view of sensitive correspondence even after a password is changed. Staff may also create forwarding rules for convenience without understanding the data protection implications.

Review automatic forwarding, inbox rules, transport rules and external sharing permissions. Particular attention should be paid to rules that redirect invoices, HR records or customer information outside the organisation. Where external forwarding has a legitimate operational purpose, it should be documented, approved and monitored.

The audit should also assess how sensitive information is handled. Depending on the organisation, this may include payment information, personal data, commercially sensitive documents or confidential client material. Data loss prevention policies, message encryption and sensitivity labels can help, but only where they are configured around real working practices. Overly restrictive controls can slow teams down; weak controls can allow information to leave with no warning.

Make sure logs, alerts and response plans work

When a suspicious email is reported, the business needs answers quickly. Can the same message be found across other mailboxes? Can a malicious attachment be removed? Can affected accounts be signed out and investigated? Are the people responsible for these decisions available when an incident occurs?

An email security audit should check logging, alerting and retention settings, as well as the practical response process. Teams should know how to report a suspected phishing message, who investigates it and how staff, customers or suppliers will be informed if an account has been compromised.

This is also the point to check whether email forms part of wider continuity planning. Mailbox recovery, secure backup, administrator access and documented emergency contacts all matter if a service outage or cyber incident affects normal operations. Technology alone will not provide continuity if nobody knows who owns the next action.

Turn findings into an achievable plan

The best audit report separates urgent exposure from useful improvement. An exposed administrator account, missing multi-factor authentication or unauthorised forwarding rule should be treated differently from a longer-term programme to refine data classification. Clear priorities make it easier for leadership to approve action and for IT teams to deliver it without disrupting the working day.

A practical remediation plan should set out the issue, business risk, recommended action, owner and target date. It should also include a review cycle. Email threats, staff roles and cloud settings change over time, so a one-off audit can become outdated surprisingly quickly. Quarterly checks of high-risk controls, supported by a more complete annual review, are often a sensible starting point.

LANCAST can help businesses assess their Microsoft 365 and wider IT environment, implement proportionate controls and provide ongoing monitoring and support. The objective is not to make email harder to use. It is to give staff the confidence to work productively while the business retains control of one of its most critical systems.

A good next step is to test one real scenario: ask how your organisation would respond if a finance mailbox were compromised this afternoon. Any uncertainty around access, reporting, recovery or supplier communication is a useful place to begin.