Email Security Settings Every Business Should Review

Close-up of a gloved hand interacting with a laptop in a sleek, modern office environment.

Email security depends on more than strong passwords. A forgotten mailbox rule, an account without multifactor authentication, or a permissive sharing setting can expose messages and business data. Review your email platform’s configuration regularly, especially after staff changes, security incidents, or system updates. Use the checklist below to identify settings that deserve attention, confirm who is responsible for them, and document any changes so your team can maintain a consistent baseline.

Check Authentication and Sign-In

Require multifactor authentication for every account, including administrators and remote users. Prefer phishing-resistant methods, such as security keys or passkeys, where your platform supports them. Avoid relying on text messages as the only second factor if stronger options are available. Confirm that recovery methods belong to the account holder and that old phone numbers or personal email addresses have been removed.

Review your email authentication records for SPF, DKIM, and DMARC. SPF identifies approved systems that can send mail for your domain; DKIM adds a verifiable signature; DMARC tells receiving systems how to handle messages that fail checks and provides reporting. Make changes carefully: inventory legitimate senders first, then monitor results before tightening enforcement to avoid disrupting valid mail.

Limit Account and Admin Access

Give each person an individual account and assign only the permissions needed for their role. Avoid shared logins, which make it harder to identify who accessed a mailbox or changed a setting. Separate administrative accounts from everyday email accounts, and restrict admin privileges to named staff who need them. Review delegated access and shared mailboxes for stale permissions.

Set a reliable process for staff departures and role changes. Disable sign-in promptly, revoke active sessions and app passwords, remove forwarding or delegation, and transfer business records to an approved owner. Check that external contractors lose access when their work ends. Keep a record of who approved each exception and when it should be reviewed.

Inspect Forwarding and Mailbox Rules

Check both administrator-level forwarding settings and rules inside individual mailboxes. Attackers who take over an account may quietly forward messages to an outside address, move security alerts into an obscure folder, or mark incoming mail as read. Remove rules nobody can explain, and verify that approved forwarding destinations are business-controlled and still required.

Where possible, block automatic forwarding to external addresses by default and allow exceptions only through an approval process. Alert administrators when a user creates a new forwarding rule or changes mailbox permissions. Include inbox rules, delegates, connected apps, and send-as permissions in the review; forwarding is only one way an intruder can preserve access or copy messages.

Review Protection and Recovery Settings

Confirm that spam, phishing, malware, and impersonation protections are enabled and configured for your organization. Review quarantine settings so users know how to report a suspicious message without releasing it carelessly. Make reporting easy, and ensure someone monitors reported messages and can remove similar messages from other inboxes when your platform allows it.

Check session duration, sign-in alerts, blocked legacy authentication, and controls for third-party apps. Remove integrations that no longer serve a business need, and restrict any app that requests broad mailbox access. Verify that email data is included in an appropriate backup or retention plan, and test that authorized staff can recover what they need. Record your baseline and repeat the review on a set schedule.

A focused settings review can uncover quiet routes to mailbox access and data loss before they become incidents. Assign an owner, document approved exceptions, and revisit authentication, permissions, forwarding, and recovery controls regularly. If you need help checking your configuration, Queenstown Email Security can discuss a practical review for your business.