Cyber Security
Email security
Email security for businesses: phishing and spoofing protection, SPF, DKIM and DMARC, sandboxing, link protection, Microsoft 365 Defender and Exclaimer.
In short
Email security stops the attacks that arrive in staff inboxes: phishing, spoofed senders, malicious attachments and links, and the invoice fraud known as business email compromise. Dig IT Solutions configures SPF, DKIM and DMARC, Microsoft 365 Defender's attachment and link protection, anti-spoofing rules and Exclaimer signatures, so your email is harder to fake and safer to open.
When you need this
Signs this is the right conversation
- A supplier's email was hacked and we nearly paid a fake invoice.
- Someone is sending emails that look like they're from our MD.
- Staff can't tell which emails are safe to click.
- Our domain has been used to spam other people.
- Every employee's email signature is different and some look unprofessional.
Scope
What we deliver
Domain authentication (SPF, DKIM, DMARC)
DNS records configured and monitored so receiving servers can verify mail genuinely came from you, and so impersonation of your domain is rejected.
Attachment sandboxing and link protection
Microsoft 365 Defender Safe Attachments and Safe Links detonate files and check URLs at click time, including inside Teams and Office documents.
Anti-phishing and impersonation rules
Protection for named executives and your domains, mailbox intelligence and spoof detection tuned to reduce false positives.
Mailbox hardening
External forwarding disabled, legacy protocols off, MFA enforced, suspicious inbox rules alerted, external sender tagging on.
Invoice fraud controls
Alerts for payment-detail changes, clear staff guidance on verifying bank details by phone, and reporting buttons so suspect emails reach us fast.
Exclaimer email signatures
Centrally managed signatures and disclaimers applied to every device and mailbox, so branding is consistent and staff can spot forgeries more easily.
Outcomes
What you get out of it
- Fewer phishing emails reach staff, and fewer of those get clicked.
- Your domain is much harder to impersonate.
- Payment fraud attempts are caught before money moves.
- Consistent, professional signatures on every message.
FAQ
Questions we are asked
What are SPF, DKIM and DMARC?
How does invoice fraud work and how do we stop it?
Is Microsoft 365's built-in email security enough?
What should staff do if they think an email is a phishing attempt?
Why does Dig IT Solutions recommend Exclaimer?
Insights
Further reading
Cyber Security
Phishing attacks explained: how they work and how to spot them in 2026
What phishing is, the forms it takes in 2026 (QR codes, MFA fatigue, Microsoft 365 consent prompts) and how UK small businesses spot and stop it.
Cyber Security
Cyber security basics for employees: a 12-point checklist for UK staff
A practical cyber security checklist for employees in UK small businesses: phishing, passwords, MFA, devices, data handling and how to report an incident.
Microsoft 365 & Cloud
Microsoft 365 security settings checklist: 14 settings to check before an attacker does
A numbered Microsoft 365 security checklist for UK SMEs: MFA, legacy authentication, admin accounts, Conditional Access, SPF, DKIM, DMARC, audit logs, Intune.
Next step
Talk to an engineer, not a sales script
Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

