Every tenant we open contains at least one allow entry nobody can account for, added during an incident that closed years ago.
The audit covers five things: the authentication records, how the policies are configured, what is on the exception lists, how mail actually routes, and what rules sit on the mailboxes. The findings land in the last three almost every time, because the first two get looked after during projects and the exceptions pile up quietly in between.

- Five layersAuthentication, policy, exceptions, routing, mailboxes
- Allow entriesThe list nobody has reviewed since it was created
- CIS Control 9Email and web browser protections
- Already licensedMost findings need configuration, not purchase
Seven areas, and it is the exception lists that produce the findings.
Authentication records, and whether they do anything
All three records for every domain you send from, and that includes the ones only a marketing platform or an invoicing system ever uses. On top of the standard checks there is implicit authentication, which layers sender reputation, the history of that sender, the history of the recipient and behavioral analysis to pick out forgeries.
Impersonation protection, and whether the list is populated
Anti-phishing policies carry impersonation protection for named senders and sender domains, alongside mailbox intelligence and a phishing threshold you can move. The question worth asking is never whether the feature exists. It is whether the protected list currently names this year leadership team, the people in finance, and the counterparty domains that actually appear on payment instructions.
Spoof handling and the sender DMARC decision
Spoof intelligence covers every cloud mailbox, with an insight view for going through detected spoofed senders from both outside and inside your own domains. A separate setting governs what happens when a sender fails an explicit DMARC check and their own published policy says quarantine or reject. Whether you honor what they asked for is a decision somebody has to make, and in most tenants nobody ever consciously made it.
Link protection, including what it does not cover
No Safe Links policy exists by default, though the built-in protection preset covers every recipient once you hold at least one Defender for Office 365 license. The published exclusions matter here: it does nothing for mail-enabled public folders, handles only HTTP, HTTPS and FTP, leaves URLs in rich text messages alone, and skips anything signed with S/MIME.
The exception lists nobody has opened since the day they were written
Spoofed sender overrides sitting in the tenant allow and block list, allow entries added at speed to unblock a supplier mid-incident, do-not-rewrite entries buried in Safe Links policies, and transport rules that skip filtering for a particular sender or domain. These build up over years, almost nobody ever reviews them, and they are the most productive hour of any email audit by a wide margin.
Mail routing, connectors, and the path in
Inbound connectors, third party gateways sitting in front of or behind Microsoft, hybrid routing, and any path at all that delivers mail while skipping part of the filtering. Where two products both handle mail, one of them is very often doing considerably less than everyone assumes, and working out which one is a short exercise with a substantial answer at the end.
Mailbox-level configuration and forwarding
Automatic forwarding to outside addresses, inbox rules quietly moving or deleting mail from particular senders, delegate permissions handed out years ago and never taken back, and mailboxes carrying send-as rights nobody expected. Business email compromise leaves its fingerprints in precisely these places, and going through them deliberately turns up the residue of compromises nobody ever noticed.
The allow lists. Everybody adds to them, nobody reads them back, and every single entry is a permanent exception.
These behave exactly the way firewall rules do. Adding one solves an urgent problem this morning. Removing one produces no visible benefit whatsoever and carries a small risk of blocking mail somebody needed.
- Spoofed sender overrides live on the spoofed senders tab of the tenant allow and block list. Overturning a verdict in the spoof intelligence view writes a manual allow or block entry there, and entries can also be added by hand before spoof intelligence has ever seen that sender.
- The do-not-rewrite entries inside Safe Links policies are a second list with subtleties of their own. Only one such list ever applies to a given person, drawn from whichever policy wins on priority, because processing halts once the first policy applies and built-in protection is always evaluated last.
- Transport rules skipping filtering for a sender, a domain or an address range are the third list, and they carry the most weight because they can take mail out of processing altogether. They are also the hardest to notice, because they sit in mail flow rather than anywhere in the security portal.
- Not one of these lists expires on its own. An entry written years ago to unblock a supplier you stopped working with in 2023 is still sitting there, still waving through mail from a domain nobody in your company has any relationship with any more. Reading them takes an afternoon and it produces more findings per hour than anything else in the engagement.
Four things this turns up that reading the configuration never will.
Every exception list gets read, entry by entry, with the question of who added it and why
The tenant allow and block entries, the do-not-rewrite lists inside Safe Links policies, and any transport rule that skips filtering. They build up in silence, none of them expires, and every one is a permanent exception created to solve something temporary. This is the single most productive hour of any email audit, and it is also the one nobody ever puts in their own calendar.
We trace the routing rather than trusting the diagram
Inbound connectors, third party gateways, hybrid paths, and any route at all that delivers mail while skipping part of the stack. Where two products both handle mail, working out which one is genuinely doing the work answers a question most companies have never thought to ask, and it occasionally saves an entire renewal.
We check the impersonation list against the current org chart
Impersonation protection defends the specific senders and domains you actually list. A list assembled during a deployment project protects whoever ran the company that year. Rebuilding it around the people who sign off payments today, and the counterparty domains that appear on real instructions today, is an afternoon of work with a direct and measurable effect on fraud exposure.
We look at mailboxes, because compromise leaves traces there
Forwarding to outside addresses, inbox rules moving or deleting mail from particular senders, delegate permissions, and send-as rights nobody expected. Business email compromise works through exactly these mechanisms, and going looking on purpose reliably turns up leftovers from compromises that were never spotted while they were happening.
Six situations, all common in American companies, where this is the right first thing to do.
A company that has just lost money to payment fraud, or very nearly did
Three layers matter here and the audit covers all of them: the authentication records that make forging your domain harder, impersonation protection for the people and the counterparty domains that appear on payment instructions, and the mailbox review that surfaces forwarding rules and delegate permissions a compromise left behind. Wire fraud arriving through a compromised or spoofed mailbox is the loss American businesses genuinely take, over and over.
An organization that has changed email platform or provider
A migration always leaves debris behind in the routing. Connectors still enabled, transport rules written for an arrangement that no longer exists, and exception entries carried over simply because nobody knew what they were for and did not dare delete them. Straight after a migration is when all of that is cheapest to find and when somebody can still remember what it was for.
A business running a third-party gateway alongside Microsoft
Where two products are both filtering and both potentially rewriting links, one of them is doing considerably less than anybody in the building believes. Working out which, and whether the arrangement leaves a gap or simply duplicates effort, is a short exercise that occasionally changes a renewal decision completely.
A business whose brand is being spoofed
When customers start reporting mail that appears to come from you, the answer sits in the authentication records for every domain you send from, and that includes the ones a marketing or invoicing platform quietly uses on your behalf. The audit establishes the complete sending inventory, which is almost always longer than the marketing team thinks it is.
An operator with many shared and functional mailboxes
Shared mailboxes, distribution lists and functional addresses collect delegate permissions and forwarding rules year after year, and almost no review covers them because they do not belong to a person. They are also, very often, exactly the mailboxes that receive supplier invoices, which makes them the ones that matter most.
An organization preparing for a questionnaire, audit, or insurance renewal
Email controls turn up in practically every customer security questionnaire, every insurance application and every SOC 2 or HIPAA assessment. A documented audit spanning authentication, policy, exceptions, routing and mailbox settings answers that whole section in one go, and because most of what it finds is configuration rather than something to buy, fixing it takes days.
How US organizations manage email security.
| Feature | Audited and maintained | Configured once, never reviewed | Defaults only |
|---|---|---|---|
All sending domains authenticated | Yes | Partly | No |
Impersonation protection populated | Yes | Empty or stale | Not licensed or not set |
Internal mail link scanning on | Yes | Often not | No |
Allow lists reviewed | Yes | Never | Not applicable |
Bypass transport rules known | Yes | No | Unknown |
Routing understood end to end | Yes | Partly | No |
External forwarding controlled | Yes | Sometimes | No |
Inbox rules reviewed for compromise traces | Yes | No | No |
Findings need purchase | Rarely | Not applicable | Sometimes |
Position against targeted fraud | Defended | Exposed | Exposed |
Five layers, and what the audit establishes at each.
Layer
Authentication records
- What we establish
- All three authentication records, on every sending domain and subdomain
- Typical finding
- A marketing platform sending from a domain with nothing aligned, and a DMARC policy set to none
Layer
Policy configuration
- What we establish
- Anti-phishing, spoof handling, link protection and attachment handling
- Typical finding
- Impersonation protection licensed and the protected sender list empty
Layer
Exception lists
- What we establish
- The tenant allow and block entries, the do-not-rewrite lists, and the transport rules that skip filtering
- Typical finding
- Entries nobody can account for, left from incidents that closed years back
Layer
Mail routing
- What we establish
- Connectors, third party gateways, hybrid paths, and anything at all that skips the filtering
- Typical finding
- Two products both rewriting links, and only one of them accomplishing anything
Layer
Mailbox configuration
- What we establish
- External forwarding, inbox rules, delegates and send-as permissions
- Typical finding
- Forwarding rules left behind by a compromise nobody noticed when it happened
Five steps, and it is shorter than most audits.
- 1
Inventory the sending domains and check authentication
Every domain and subdomain that sends mail carrying your name, and that means the marketing platform, the invoicing system, the ticketing tool and whatever else sends on your behalf. Then all three authentication records for each of them, including whether the record actually does what whoever wrote it intended.
- 2
Review the policy configuration across every surface
Anti-phishing, including the protected sender and domain lists, mailbox intelligence and where the phishing threshold sits. The spoof intelligence settings, and whether anybody ever decided to honor what other senders publish. Link protection across mail, internal mail, collaboration tools and documents. How attachments are handled and what quarantine does with them.
- 3
Read every exception list
The tenant allow and block entries including the spoofed senders tab, the do-not-rewrite entries in each Safe Links policy bearing in mind only one list ever applies to a given person, and every transport rule that skips filtering. Each entry gets the same three questions: who put it there, what for, and does that reason still exist.
- 4
Trace the mail routing end to end
Connectors in both directions, third party gateways sitting either side of Microsoft, hybrid arrangements, and any route that delivers mail while stepping around part of the stack. Where two products are both handling mail, we establish which one is genuinely doing what rather than assuming the arrangement behaves the way it was drawn.
- 5
Review mailbox configuration and report with priorities
Forwarding to outside addresses, inbox rules, delegate and send-as permissions, across personal, shared and functional mailboxes alike. Then a report ordered by what cuts fraud exposure fastest, which in most companies means the impersonation list, clearing out the exceptions, and switching on internal mail scanning. None of those three costs anything.
What organizations ask about email security audits.
Fifteen questions you ought to be able to answer about your own email security.
Authentication
- Do you know every domain that sends as you?Including marketing and invoicing platforms.
- Is DMARC published, and at what policy?None, quarantine, or reject.
- Is DKIM signing every sending source?Third-party senders are the usual gap.
- Is SPF within its lookup limit?Adding senders breaks it silently.
- Do you honor other senders' DMARC policies?A separate setting, rarely decided.
Policy
- Is the impersonation protected sender list current?Leadership and finance change.
- Are counterparty domains protected?The ones on payment instructions.
- Is internal-to-internal mail scanned for links?A separate setting.
- Can users click through a malicious link warning?Recommended off.
- Are phishing thresholds set deliberately?They are adjustable.
Exceptions and routing
- How many allow entries exist?And can anybody explain them.
- Are there bypass transport rules?The most powerful exception.
- Is another product also processing mail?One of them may be doing nothing.
- Is external forwarding permitted anywhere?Check per mailbox, not per policy.
- When did anyone last review inbox rules?Compromise leaves traces here.
The pages around this one.
Defender for Office 365
The policy configuration layer in depth, including impersonation protection and Safe Links.
Microsoft 365 security audit
The whole tenant, of which email is one layer: identity, sharing, devices, and audit evidence.
Google Workspace security audit
The same exercise where your email runs on Gmail rather than Exchange Online.
Go and open the tenant allow list, then count how many entries you can actually account for.
Five minutes, and it is the most reliable single indicator of whether your email security reflects a decision somebody took recently or simply the sediment of everything that ever happened. Every audit we have run has turned up at least one entry nobody could explain.
Related Services
Explore more solutions that work great with this service
Microsoft 365 Security Audit
Independent Microsoft 365 tenant security audit for US organizations
Learn moreGoogle Workspace Security Audit
Google Workspace security audit for US organizations worked through
Learn moreMicrosoft Defender
Advanced endpoint and email threat protection
Learn moreCyber Incident Response
Cyber incident response for US businesses. 24/7 on-call IR engineers
Learn moreM365 Tenant Management
Your tenant run properly, end to end
Learn more