A convincing fake invoice can arrive at 09:12, look like it came from a regular supplier and be acted on before anyone has time to question it. For many organisations, email remains the main route into finance systems, customer data and internal conversations. This email security checklist helps UK businesses put sensible controls around that risk without making everyday work unnecessarily difficult.
The right measures depend on your size, sector and existing Microsoft 365 or hosted email setup. A small office may need straightforward managed protection and clear user guidance, while a multi-site organisation may require tighter access policies, central monitoring and formal incident procedures. The aim is the same: reduce the chance that a single message or stolen password disrupts the business.
Start with ownership and visibility
Email security can fail when it is treated as a one-off technical project. Someone in the organisation should own the policy, understand who administers the email platform and know where to get support when something suspicious happens. This does not mean an office manager needs to become a cyber security specialist. It means responsibilities are clear.
Keep an up-to-date record of email domains, mailboxes, shared inboxes, distribution lists and third-party systems that send messages on your behalf. Marketing platforms, CRM systems, website forms, payroll software and photocopiers can all send email using your domain. If they are overlooked, they can create delivery problems or weaken authentication settings later.
Review administrator accounts separately from ordinary user accounts. Admin rights should be limited to people who genuinely need them, with named accounts rather than shared credentials. When a member of staff changes role or leaves, access removal should be part of the standard leaver process, not an informal task that can be missed during a busy week.
Email security checklist: protect every account
A compromised mailbox is more than an inconvenience. Criminals can search old messages for bank details, impersonate a director, reset passwords for other services or set forwarding rules that quietly copy correspondence outside the business.
Require multi-factor authentication
Multi-factor authentication, often shortened to MFA, should be enabled for every email account, especially administrators and finance users. A password alone is easily stolen through phishing, reused from another breached service or guessed when it is weak.
Authenticator apps or security keys usually provide better protection than SMS codes, although SMS can still be preferable to having no MFA at all. Consider the practical needs of your team too. Staff without company smartphones, shared shift patterns and poor mobile signal at some sites may affect which method works best. The key is to choose an approach people can use reliably and support it properly.
Apply sensible password and sign-in rules
Use long, unique passwords and provide an approved password manager where appropriate. Avoid forcing frequent password changes without evidence of compromise, as this can encourage predictable variations and insecure note-taking. Instead, block known compromised passwords and require a change when risk is identified.
Sign-in policies should identify unusual activity, such as a login from an unexpected country, a new device or impossible travel between locations. Automated responses may challenge the user for MFA, block the session or alert an administrator. These controls need tuning. A blanket block on overseas access could be sensible for one business but disruptive for a team that travels regularly or works with overseas colleagues.
Remove unused access promptly
Dormant accounts, old shared mailboxes and former contractor access are common weaknesses. Carry out a regular access review, paying particular attention to accounts with administrative permissions, finance access and shared inboxes such as accounts@ or enquiries@.
Where a shared mailbox is needed, give access to named users rather than sharing its password. That preserves accountability and makes access easier to remove when responsibilities change.
Stop spoofed and malicious messages before they arrive
The most effective email security combines technical filtering with identity protection. A spam filter can identify many suspicious messages, but it cannot be expected to catch every tailored phishing attempt. Authentication records help receiving mail systems check whether messages claiming to come from your domain are legitimate.
Configure SPF, DKIM and DMARC
SPF identifies the systems authorised to send email for your domain. DKIM adds a digital signature that helps prove a message was not altered in transit. DMARC tells receiving systems what to do when these checks fail and provides reports that show who is using your domain.
These records need careful configuration. Moving straight to a strict DMARC reject policy without understanding all legitimate senders can cause valid messages to be quarantined or rejected. Begin by monitoring reports, fix any gaps and then move towards quarantine or reject once you have confidence in the setup. This is particularly valuable where customers, suppliers or the public need to trust messages from your organisation.
Use managed filtering and attachment controls
Your email protection should scan incoming and outgoing messages for known malware, suspicious links, impersonation attempts and risky attachments. It should also check messages after delivery where possible, because a web link that appears harmless at 9am may lead to a malicious site later in the day.
Review whether your business needs to receive file types commonly used to deliver malware. Blocking scripts and executable files is usually straightforward; more common formats such as Office documents require a more balanced policy. Financial teams may have legitimate reasons to receive spreadsheets, so use protected viewing, attachment sandboxing and user awareness rather than relying on a single rule.
Make people part of the defence
Phishing messages work because they exploit pressure, familiarity and normal business processes. A message that appears to come from a managing director asking for urgent payment is not necessarily badly written. Modern attacks can use real names, supplier information and copied branding.
Training should be short, relevant and repeated. Show colleagues the warning signs that apply to their jobs: unexpected MFA prompts, changed bank details, invoice requests, shared-document notifications and requests for confidential information. Encourage them to report suspicious messages without embarrassment. A quick report may protect the whole organisation.
For payment changes, use a separate verification process. A telephone call to a known number, not the number in the email, is a simple and effective control. No amount of filtering replaces a process that requires independent approval for high-value payments or changed supplier details.
Protect information after an email is sent
Email is often used to exchange personal data, contracts, commercial documents and credentials. Decide what information should not be sent by ordinary email and provide staff with a workable alternative, such as a secure file-sharing method or encrypted message service.
Set rules for forwarding. Automatic forwarding to personal addresses should normally be blocked, and external forwarding should be reviewed closely. This is a frequent tactic after an account takeover, but it can also cause accidental data leakage when staff try to work around poor access to business systems.
Retention policies also deserve attention. Keeping every mailbox forever increases the amount of sensitive material exposed if an account is compromised. Retain records for the period your legal, operational and contractual requirements demand, then dispose of them in a controlled way. For healthcare, education, public sector and regulated organisations, this should align with the organisation’s wider information governance arrangements.
Prepare for the moment something goes wrong
Even well-managed organisations receive malicious email and may face a compromised account. The difference is how quickly the issue is recognised, contained and investigated. Staff should know exactly how to report a suspect email or lost device, including an out-of-hours route where appropriate.
Your response plan should cover four practical actions: disable or secure the affected account, revoke active sessions and suspicious mailbox rules, identify what messages or files were accessed, and notify relevant people where required. Preserve evidence before deleting messages or resetting systems where possible. If a fraudulent payment is involved, contact the bank immediately as time matters.
Test the process at least annually. A short tabletop exercise can reveal whether contact details are current, who can make urgent decisions and whether your IT provider has the access needed to respond quickly. Backups remain essential for wider business resilience, but do not assume they solve email compromise on their own. You also need to protect backup access and confirm that recovery procedures work.
Keep the checklist under review
Email platforms, threats and working practices change. Review your controls after a security incident, a major system change, a merger, a new third-party supplier or a move to hybrid working. Regular reporting on blocked threats, failed sign-ins, MFA coverage and DMARC results gives decision-makers a clearer picture than an annual compliance exercise alone.
A dependable email security programme is not about adding complexity for its own sake. It is about making the secure action the normal action, with specialist advice and ongoing support available when the business needs it most.