Skip to main content

Cyber Security

Email security

Email security for businesses: phishing and spoofing protection, SPF, DKIM and DMARC, sandboxing, link protection, Microsoft 365 Defender and Exclaimer.

In short

Email security stops the attacks that arrive in staff inboxes: phishing, spoofed senders, malicious attachments and links, and the invoice fraud known as business email compromise. Dig IT Solutions configures SPF, DKIM and DMARC, Microsoft 365 Defender's attachment and link protection, anti-spoofing rules and Exclaimer signatures, so your email is harder to fake and safer to open.

When you need this

Signs this is the right conversation

  • A supplier's email was hacked and we nearly paid a fake invoice.
  • Someone is sending emails that look like they're from our MD.
  • Staff can't tell which emails are safe to click.
  • Our domain has been used to spam other people.
  • Every employee's email signature is different and some look unprofessional.

Scope

What we deliver

  • 01

    Domain authentication (SPF, DKIM, DMARC)

    DNS records configured and monitored so receiving servers can verify mail genuinely came from you, and so impersonation of your domain is rejected.

  • 02

    Attachment sandboxing and link protection

    Microsoft 365 Defender Safe Attachments and Safe Links detonate files and check URLs at click time, including inside Teams and Office documents.

  • 03

    Anti-phishing and impersonation rules

    Protection for named executives and your domains, mailbox intelligence and spoof detection tuned to reduce false positives.

  • 04

    Mailbox hardening

    External forwarding disabled, legacy protocols off, MFA enforced, suspicious inbox rules alerted, external sender tagging on.

  • 05

    Invoice fraud controls

    Alerts for payment-detail changes, clear staff guidance on verifying bank details by phone, and reporting buttons so suspect emails reach us fast.

  • 06

    Exclaimer email signatures

    Centrally managed signatures and disclaimers applied to every device and mailbox, so branding is consistent and staff can spot forgeries more easily.

Outcomes

What you get out of it

  • Fewer phishing emails reach staff, and fewer of those get clicked.
  • Your domain is much harder to impersonate.
  • Payment fraud attempts are caught before money moves.
  • Consistent, professional signatures on every message.

FAQ

Questions we are asked

Straight answers. If yours is not here, call 020 8482 4020 or 01992 939 365 and ask an engineer.
What are SPF, DKIM and DMARC?
They are three DNS records that let receiving mail servers check whether an email claiming to come from your domain is genuine. SPF lists the servers allowed to send for you, DKIM adds a cryptographic signature, and DMARC tells recipients what to do with mail that fails those checks and sends you reports. Together they make it much harder for criminals to spoof your address.
How does invoice fraud work and how do we stop it?
Criminals compromise or impersonate a supplier's or director's mailbox, then send a convincing request to change bank details or pay an urgent invoice. Technical controls such as DMARC, impersonation protection and forwarding alerts cut down the attempts that get through. The final defence is a process: any change to payment details is verified by phone on a known number before money moves.
Is Microsoft 365's built-in email security enough?
Microsoft 365 includes good protection, and Business Premium adds Defender for Office 365 with Safe Attachments, Safe Links and anti-phishing policies. The problem is that many tenants are left on defaults. Configured properly and combined with DMARC, MFA and staff training, it is adequate for most small businesses. We'll recommend an additional filtering layer only where there's a specific reason.
What should staff do if they think an email is a phishing attempt?
Don't click links, open attachments or reply. Use the report button in Outlook or forward the email to our helpdesk, and if it asks for a payment or password change, phone the apparent sender on a known number. If someone has already clicked or entered credentials, tell us immediately so we can reset the account and check for damage. Speed matters more than embarrassment.
Why does Dig IT Solutions recommend Exclaimer?
Exclaimer applies signatures centrally, so every email from every device carries the same branding, contact details and legal text without relying on staff to set it up. Consistency has a security benefit too: when every genuine internal email looks the same, a forged one stands out. It also gives marketing a place to add campaign banners without touching Outlook.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us