Email Security
Protect your email and reputation from phishing, spoofing, and domain abuse.
Effective email security reduces your organization's risk while helping legitimate messages reach their destination reliably.
Email is critical business infrastructure and remains a common target for attackers. Effective email security combines authentication, encryption, access controls, filtering, and monitoring to protect your domains, users, and communications.
Overview
Email security is more than spam filtering. Misconfigured sender authentication, insufficient transport security, insecure relay configurations, and inadequate monitoring can expose an organisation to phishing, domain spoofing, message interception, and delivery problems.
I help organisations assess, improve, and maintain their email infrastructure using established standards and open-source technologies.
The service can cover individual issues, such as implementing DMARC, or a broader review and hardening of an existing mail environment.
What I Can Help With
Sender Authentication
Review and implement sender authentication mechanisms to reduce domain spoofing and improve trust in legitimate email.
This can include:
- SPF configuration and auditing
- DKIM deployment and key management
- DMARC policy design
- DMARC migration from monitoring to enforcement
- Aggregate DMARC report analysis
- Identification of legitimate and unauthorised senders
Mail Server Hardening
Review and harden mail transfer agent configurations, particularly Postfix-based environments.
This can include:
- TLS configuration
- DANE
- MTA-STS
- TLS-RPT
- Relay access controls
- Secure SMTP configuration
- Configuration review and hardening
Anti-Spam & Anti-Phishing
Improve filtering and detection of unwanted or malicious email.
This can include:
- Rspamd or SpamAssassin configuration and tuning
- DNS blocklist integration
- Custom header analysis
- Greylisting
- Filtering policy review
- Analysis of false positives and false negatives
Secure Mail Relay
Configure secure outbound mail delivery for applications, servers, and other systems.
This can include:
- SMTP smart-host configuration
- SASL authentication
- TLS
- Rate limiting
- Relay access controls
Typical Outcomes
Depending on the existing environment and scope of the engagement, outcomes may include:
- Reduced risk of domain spoofing and impersonation
- Stronger protection against phishing and unwanted email
- Improved transport security between mail systems
- Better visibility into authentication and delivery problems
- More controlled and secure mail relay infrastructure
- Improved reliability of legitimate outbound email
- Clearer understanding of the organisation’s email security posture
The objective is not simply to deploy individual security mechanisms, but to establish an email environment that is secure, understandable, and maintainable.
How I Work
1. Assess
I review the existing environment, including DNS records, mail server configuration, authentication policies, filtering, transport security, and available monitoring data.
2. Identify
I identify configuration problems, security gaps, unnecessary complexity, and opportunities for improvement.
Findings are prioritised according to their practical impact rather than treating every deviation as equally important.
3. Recommend
I propose appropriate changes based on the organisation’s infrastructure, requirements, and operational constraints.
Where multiple approaches are possible, I explain the relevant trade-offs rather than prescribing technology without context.
4. Implement
Where included in the engagement, I implement the agreed changes to DNS, mail servers, filtering systems, authentication policies, or related infrastructure.
Changes can be introduced incrementally where appropriate - for example, moving a DMARC policy from monitoring toward enforcement.
5. Verify
Changes are tested and monitored to confirm that the intended controls work without unnecessarily disrupting legitimate mail.
Deliverables
Deliverables depend on the scope of the engagement and may include:
- Written assessment with prioritised recommendations
- DNS and mail server configuration changes
- SPF, DKIM, and DMARC configuration
- MTA security configuration
- Anti-spam and anti-phishing configuration
- DMARC and TLS-RPT monitoring
- Log analysis and verification
- Technical documentation
- Knowledge transfer
The exact deliverables are agreed before implementation begins.
Technologies & Standards
Depending on the environment, the service may involve technologies and standards including:
- Postfix
- Rspamd
- SpamAssassin
- SPF
- DKIM
- DMARC
- TLS
- DANE
- MTA-STS
- TLS-RPT
- SASL
- DNS
The specific technology is secondary to selecting controls that are appropriate for the environment and can be operated reliably over time.
Discuss Your Requirements
Email environments vary considerably, from a single domain using a hosted provider to organisations operating their own mail infrastructure.
If you have a specific email security problem, want an independent review of your current configuration, or are planning improvements to your mail infrastructure, get in touch to discuss the requirements and appropriate scope.