We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Email security audit
Email security audit for US businesses

Every tenant we open contains at least one allow entry nobody can account for, added during an incident that closed years ago.

The audit covers five things: the authentication records, how the policies are configured, what is on the exception lists, how mail actually routes, and what rules sit on the mailboxes. The findings land in the last three almost every time, because the first two get looked after during projects and the exceptions pile up quietly in between.

Book an email security auditSee the five layers
Email security audit for US organizations
  • Five layersAuthentication, policy, exceptions, routing, mailboxes
  • Allow entriesThe list nobody has reviewed since it was created
  • CIS Control 9Email and web browser protections
  • Already licensedMost findings need configuration, not purchase
What we examine

Seven areas, and it is the exception lists that produce the findings.

Email and browser protection is Control 9 in version 8.1 of the CIS Critical Security Controls. Inside a Microsoft 365 tenant most of that capability is already paid for, which means what comes out of the audit is usually a list of configuration changes rather than a purchase order. That is a much easier conversation to have internally.

Authentication records, and whether they do anything

All three records for every domain you send from, and that includes the ones only a marketing platform or an invoicing system ever uses. On top of the standard checks there is implicit authentication, which layers sender reputation, the history of that sender, the history of the recipient and behavioral analysis to pick out forgeries.

Impersonation protection, and whether the list is populated

Anti-phishing policies carry impersonation protection for named senders and sender domains, alongside mailbox intelligence and a phishing threshold you can move. The question worth asking is never whether the feature exists. It is whether the protected list currently names this year leadership team, the people in finance, and the counterparty domains that actually appear on payment instructions.

Spoof handling and the sender DMARC decision

Spoof intelligence covers every cloud mailbox, with an insight view for going through detected spoofed senders from both outside and inside your own domains. A separate setting governs what happens when a sender fails an explicit DMARC check and their own published policy says quarantine or reject. Whether you honor what they asked for is a decision somebody has to make, and in most tenants nobody ever consciously made it.

Link protection, including what it does not cover

No Safe Links policy exists by default, though the built-in protection preset covers every recipient once you hold at least one Defender for Office 365 license. The published exclusions matter here: it does nothing for mail-enabled public folders, handles only HTTP, HTTPS and FTP, leaves URLs in rich text messages alone, and skips anything signed with S/MIME.

The exception lists nobody has opened since the day they were written

Spoofed sender overrides sitting in the tenant allow and block list, allow entries added at speed to unblock a supplier mid-incident, do-not-rewrite entries buried in Safe Links policies, and transport rules that skip filtering for a particular sender or domain. These build up over years, almost nobody ever reviews them, and they are the most productive hour of any email audit by a wide margin.

Mail routing, connectors, and the path in

Inbound connectors, third party gateways sitting in front of or behind Microsoft, hybrid routing, and any path at all that delivers mail while skipping part of the filtering. Where two products both handle mail, one of them is very often doing considerably less than everyone assumes, and working out which one is a short exercise with a substantial answer at the end.

Mailbox-level configuration and forwarding

Automatic forwarding to outside addresses, inbox rules quietly moving or deleting mail from particular senders, delegate permissions handed out years ago and never taken back, and mailboxes carrying send-as rights nobody expected. Business email compromise leaves its fingerprints in precisely these places, and going through them deliberately turns up the residue of compromises nobody ever noticed.

The most productive finding, every time

The allow lists. Everybody adds to them, nobody reads them back, and every single entry is a permanent exception.

These behave exactly the way firewall rules do. Adding one solves an urgent problem this morning. Removing one produces no visible benefit whatsoever and carries a small risk of blocking mail somebody needed.

  • Spoofed sender overrides live on the spoofed senders tab of the tenant allow and block list. Overturning a verdict in the spoof intelligence view writes a manual allow or block entry there, and entries can also be added by hand before spoof intelligence has ever seen that sender.
  • The do-not-rewrite entries inside Safe Links policies are a second list with subtleties of their own. Only one such list ever applies to a given person, drawn from whichever policy wins on priority, because processing halts once the first policy applies and built-in protection is always evaluated last.
  • Transport rules skipping filtering for a sender, a domain or an address range are the third list, and they carry the most weight because they can take mail out of processing altogether. They are also the hardest to notice, because they sit in mail flow rather than anywhere in the security portal.
  • Not one of these lists expires on its own. An entry written years ago to unblock a supplier you stopped working with in 2023 is still sitting there, still waving through mail from a domain nobody in your company has any relationship with any more. Reading them takes an afternoon and it produces more findings per hour than anything else in the engagement.
Ask us to review your allow lists
How we approach it

Four things this turns up that reading the configuration never will.

Reading the policies tells you what somebody intended. The audit is about the distance between that intention and what a message actually goes through, and that distance lives in the exceptions, the routing and the mailboxes.

Every exception list gets read, entry by entry, with the question of who added it and why

The tenant allow and block entries, the do-not-rewrite lists inside Safe Links policies, and any transport rule that skips filtering. They build up in silence, none of them expires, and every one is a permanent exception created to solve something temporary. This is the single most productive hour of any email audit, and it is also the one nobody ever puts in their own calendar.

We trace the routing rather than trusting the diagram

Inbound connectors, third party gateways, hybrid paths, and any route at all that delivers mail while skipping part of the stack. Where two products both handle mail, working out which one is genuinely doing the work answers a question most companies have never thought to ask, and it occasionally saves an entire renewal.

We check the impersonation list against the current org chart

Impersonation protection defends the specific senders and domains you actually list. A list assembled during a deployment project protects whoever ran the company that year. Rebuilding it around the people who sign off payments today, and the counterparty domains that appear on real instructions today, is an afternoon of work with a direct and measurable effect on fraud exposure.

We look at mailboxes, because compromise leaves traces there

Forwarding to outside addresses, inbox rules moving or deleting mail from particular senders, delegate permissions, and send-as rights nobody expected. Business email compromise works through exactly these mechanisms, and going looking on purpose reliably turns up leftovers from compromises that were never spotted while they were happening.

Where this matters most

Six situations, all common in American companies, where this is the right first thing to do.

Email remains the primary delivery route for the attacks that actually cost US organizations money, and most of the defense is already licensed and partially configured.

A company that has just lost money to payment fraud, or very nearly did

Three layers matter here and the audit covers all of them: the authentication records that make forging your domain harder, impersonation protection for the people and the counterparty domains that appear on payment instructions, and the mailbox review that surfaces forwarding rules and delegate permissions a compromise left behind. Wire fraud arriving through a compromised or spoofed mailbox is the loss American businesses genuinely take, over and over.

An organization that has changed email platform or provider

A migration always leaves debris behind in the routing. Connectors still enabled, transport rules written for an arrangement that no longer exists, and exception entries carried over simply because nobody knew what they were for and did not dare delete them. Straight after a migration is when all of that is cheapest to find and when somebody can still remember what it was for.

A business running a third-party gateway alongside Microsoft

Where two products are both filtering and both potentially rewriting links, one of them is doing considerably less than anybody in the building believes. Working out which, and whether the arrangement leaves a gap or simply duplicates effort, is a short exercise that occasionally changes a renewal decision completely.

A business whose brand is being spoofed

When customers start reporting mail that appears to come from you, the answer sits in the authentication records for every domain you send from, and that includes the ones a marketing or invoicing platform quietly uses on your behalf. The audit establishes the complete sending inventory, which is almost always longer than the marketing team thinks it is.

An operator with many shared and functional mailboxes

Shared mailboxes, distribution lists and functional addresses collect delegate permissions and forwarding rules year after year, and almost no review covers them because they do not belong to a person. They are also, very often, exactly the mailboxes that receive supplier invoices, which makes them the ones that matter most.

An organization preparing for a questionnaire, audit, or insurance renewal

Email controls turn up in practically every customer security questionnaire, every insurance application and every SOC 2 or HIPAA assessment. A documented audit spanning authentication, policy, exceptions, routing and mailbox settings answers that whole section in one go, and because most of what it finds is configuration rather than something to buy, fixing it takes days.

Three positions

How US organizations manage email security.

The middle column is overwhelmingly the normal state. The tenant was configured properly during a project, the licenses are all held, and nothing has been looked at since the person who did the work moved on.
All sending domains authenticated
Audited and maintainedYes
Configured once, never reviewedPartly
Defaults onlyNo
Impersonation protection populated
Audited and maintainedYes
Configured once, never reviewedEmpty or stale
Defaults onlyNot licensed or not set
Internal mail link scanning on
Audited and maintainedYes
Configured once, never reviewedOften not
Defaults onlyNo
Allow lists reviewed
Audited and maintainedYes
Configured once, never reviewedNever
Defaults onlyNot applicable
Bypass transport rules known
Audited and maintainedYes
Configured once, never reviewedNo
Defaults onlyUnknown
Routing understood end to end
Audited and maintainedYes
Configured once, never reviewedPartly
Defaults onlyNo
External forwarding controlled
Audited and maintainedYes
Configured once, never reviewedSometimes
Defaults onlyNo
Inbox rules reviewed for compromise traces
Audited and maintainedYes
Configured once, never reviewedNo
Defaults onlyNo
Findings need purchase
Audited and maintainedRarely
Configured once, never reviewedNot applicable
Defaults onlySometimes
Position against targeted fraud
Audited and maintainedDefended
Configured once, never reviewedExposed
Defaults onlyExposed
Feature
Audited and maintained
Configured once, never reviewed
Defaults only
All sending domains authenticated
YesPartlyNo
Impersonation protection populated
YesEmpty or staleNot licensed or not set
Internal mail link scanning on
YesOften notNo
Allow lists reviewed
YesNeverNot applicable
Bypass transport rules known
YesNoUnknown
Routing understood end to end
YesPartlyNo
External forwarding controlled
YesSometimesNo
Inbox rules reviewed for compromise traces
YesNoNo
Findings need purchase
RarelyNot applicableSometimes
Position against targeted fraud
DefendedExposedExposed
The audit scope

Five layers, and what the audit establishes at each.

In most companies attention sits on the first two layers, because those are what a project delivers and gets signed off. The findings sit in the last three, because those are what accumulates in the gaps between projects when nobody is watching.

Layer

Authentication records

What we establish
All three authentication records, on every sending domain and subdomain
Typical finding
A marketing platform sending from a domain with nothing aligned, and a DMARC policy set to none

Layer

Policy configuration

What we establish
Anti-phishing, spoof handling, link protection and attachment handling
Typical finding
Impersonation protection licensed and the protected sender list empty

Layer

Exception lists

What we establish
The tenant allow and block entries, the do-not-rewrite lists, and the transport rules that skip filtering
Typical finding
Entries nobody can account for, left from incidents that closed years back

Layer

Mail routing

What we establish
Connectors, third party gateways, hybrid paths, and anything at all that skips the filtering
Typical finding
Two products both rewriting links, and only one of them accomplishing anything

Layer

Mailbox configuration

What we establish
External forwarding, inbox rules, delegates and send-as permissions
Typical finding
Forwarding rules left behind by a compromise nobody noticed when it happened
LayerWhat we establishTypical finding
Authentication recordsAll three authentication records, on every sending domain and subdomainA marketing platform sending from a domain with nothing aligned, and a DMARC policy set to none
Policy configurationAnti-phishing, spoof handling, link protection and attachment handlingImpersonation protection licensed and the protected sender list empty
Exception listsThe tenant allow and block entries, the do-not-rewrite lists, and the transport rules that skip filteringEntries nobody can account for, left from incidents that closed years back
Mail routingConnectors, third party gateways, hybrid paths, and anything at all that skips the filteringTwo products both rewriting links, and only one of them accomplishing anything
Mailbox configurationExternal forwarding, inbox rules, delegates and send-as permissionsForwarding rules left behind by a compromise nobody noticed when it happened
How an engagement runs

Five steps, and it is shorter than most audits.

One to three weeks as a rule, all delivered remotely. Nearly all the evidence comes out of the tenant with read access alone, and most of what surfaces is a setting to change rather than a project to fund.
  1. 1

    Inventory the sending domains and check authentication

    Every domain and subdomain that sends mail carrying your name, and that means the marketing platform, the invoicing system, the ticketing tool and whatever else sends on your behalf. Then all three authentication records for each of them, including whether the record actually does what whoever wrote it intended.

  2. 2

    Review the policy configuration across every surface

    Anti-phishing, including the protected sender and domain lists, mailbox intelligence and where the phishing threshold sits. The spoof intelligence settings, and whether anybody ever decided to honor what other senders publish. Link protection across mail, internal mail, collaboration tools and documents. How attachments are handled and what quarantine does with them.

  3. 3

    Read every exception list

    The tenant allow and block entries including the spoofed senders tab, the do-not-rewrite entries in each Safe Links policy bearing in mind only one list ever applies to a given person, and every transport rule that skips filtering. Each entry gets the same three questions: who put it there, what for, and does that reason still exist.

  4. 4

    Trace the mail routing end to end

    Connectors in both directions, third party gateways sitting either side of Microsoft, hybrid arrangements, and any route that delivers mail while stepping around part of the stack. Where two products are both handling mail, we establish which one is genuinely doing what rather than assuming the arrangement behaves the way it was drawn.

  5. 5

    Review mailbox configuration and report with priorities

    Forwarding to outside addresses, inbox rules, delegate and send-as permissions, across personal, shared and functional mailboxes alike. Then a report ordered by what cuts fraud exposure fastest, which in most companies means the impersonation list, clearing out the exceptions, and switching on internal mail scanning. None of those three costs anything.

Straight answers

What organizations ask about email security audits.

Five layers in total. The authentication records on every sending domain. The policy configuration, meaning anti-phishing, spoof handling, and link and attachment protection. The exception lists, meaning tenant allow and block entries, do-not-rewrite lists and transport rules that skip filtering. The routing, meaning connectors and any third party gateway in the path. And the mailboxes themselves, meaning forwarding, inbox rules, delegates and send-as rights.

Usually not, which is one of the more pleasant characteristics of this particular engagement. Inside a Microsoft 365 tenant most of the capability is already paid for and half configured, so what surfaces tends to be settings nobody switched on, lists nobody filled in, and exceptions nobody removed. Every so often a genuine licensing gap does appear, and when it does you hear it plainly.

Because nothing expires them and nobody reads them. Each one went in for a genuine reason under time pressure, nearly always to unblock a supplier or a customer during something urgent. The urgency passes and the entry stays exactly where it is. Stretch that across several years and several administrators and the accumulated exceptions can seriously undermine a tenant that is otherwise well configured.

A mail flow rule that lifts messages out of some or all filtering according to the sender, the domain, an address range or a header. It is the most powerful exception in the whole system, because it acts ahead of the security stack rather than inside it, and simultaneously the least visible, because it sits in mail flow configuration rather than in the security portal where anybody reviewing security would think to look.

Yes, across every domain and subdomain sending under your name, and that list is invariably longer than the one somebody hands over at the start. Marketing platforms, invoicing systems, ticketing tools and help desk software all send on your behalf and every one needs authorizing properly. Separately we check whether you honor what other senders publish, which is a distinct decision that most tenants have never consciously taken.

On inbound mail the three standard checks are supplemented with sender reputation, the history of that sender, the history of the recipient, behavioral analysis and further techniques besides, all aimed at spotting a forged sender. The practical upshot is that your own records still matter and the platform is not leaning on them alone.

No, and the published exclusions are worth committing to memory. It does nothing for mail-enabled public folders, handles only HTTP, HTTPS and FTP link formats, offers no protection at all for URLs inside rich text messages, and skips anything signed with S/MIME. There is also no policy by default, although a built-in protection preset covers every recipient wherever at least one Defender for Office 365 license exists.

Because business email compromise runs on them. Somebody with access to a mailbox will typically write a rule that moves or deletes anything from a finance address, or quietly sets forwarding to an outside address, so the actual owner never sees the conversation happening in their name. Going through these deliberately turns up leftovers from compromises nobody noticed at the time with depressing regularity.

Often there is more point, not less. Where two products both filter mail, how they interact almost never matches the diagram. One may be rewriting links the other then cannot read. One may be trusted through connector configuration in a way that quietly skips filtering altogether. Establishing what each is genuinely doing is a short exercise with a substantial answer, and it does sometimes change a renewal decision.

No, and both are worth doing because they measure different things. A simulation tells you whether your people click. This tells you whether the technology would have stopped the message arriving in front of them at all, and whether an exception somewhere would have waved it through regardless. Running simulations while the configuration is still incomplete tests your staff against attacks the platform was never instructed to stop.

Yes, and most clients ask for exactly that. Since the bulk of it is configuration rather than purchasing, the fixing tends to take days rather than becoming a project. The order we recommend is the impersonation list first, then clearing the exceptions, then internal mail scanning and the click-through setting, because between them those four move fraud exposure furthest for the least disruption to anybody.

Once a year as a floor, plus after any change to routing, after a platform migration, and after any significant change to who leads the company or runs finance, since the impersonation list depends on both of those. The exception lists in particular want their own review rhythm, because they grow continuously and nothing anywhere in the platform ever prompts a human to look at them. Each engagement is scoped individually around how many sending domains exist, whether another vendor gateway is in the path, and how many mailboxes are in scope.
Questions the audit answers

Fifteen questions you ought to be able to answer about your own email security.

This is the list we work through. Most companies answer the first block confidently, some of the second, and virtually none of the third without going and checking.

Authentication

  • Do you know every domain that sends as you?
    Including marketing and invoicing platforms.
  • Is DMARC published, and at what policy?
    None, quarantine, or reject.
  • Is DKIM signing every sending source?
    Third-party senders are the usual gap.
  • Is SPF within its lookup limit?
    Adding senders breaks it silently.
  • Do you honor other senders' DMARC policies?
    A separate setting, rarely decided.

Policy

  • Is the impersonation protected sender list current?
    Leadership and finance change.
  • Are counterparty domains protected?
    The ones on payment instructions.
  • Is internal-to-internal mail scanned for links?
    A separate setting.
  • Can users click through a malicious link warning?
    Recommended off.
  • Are phishing thresholds set deliberately?
    They are adjustable.

Exceptions and routing

  • How many allow entries exist?
    And can anybody explain them.
  • Are there bypass transport rules?
    The most powerful exception.
  • Is another product also processing mail?
    One of them may be doing nothing.
  • Is external forwarding permitted anywhere?
    Check per mailbox, not per policy.
  • When did anyone last review inbox rules?
    Compromise leaves traces here.
Related reading

The pages around this one.

Defender for Office 365

The policy configuration layer in depth, including impersonation protection and Safe Links.

Learn more

Microsoft 365 security audit

The whole tenant, of which email is one layer: identity, sharing, devices, and audit evidence.

Learn more

Google Workspace security audit

The same exercise where your email runs on Gmail rather than Exchange Online.

Learn more
Next step

Go and open the tenant allow list, then count how many entries you can actually account for.

Five minutes, and it is the most reliable single indicator of whether your email security reflects a decision somebody took recently or simply the sediment of everything that ever happened. Every audit we have run has turned up at least one entry nobody could explain.

Book an email security auditSee the audit practice

Related Services

Explore more solutions that work great with this service

Microsoft 365 Security Audit

Independent Microsoft 365 tenant security audit for US organizations

Learn more

Google Workspace Security Audit

Google Workspace security audit for US organizations worked through

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more

Cyber Incident Response

Cyber incident response for US businesses. 24/7 on-call IR engineers

Learn more

M365 Tenant Management

Your tenant run properly, end to end

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA