Skip to content

A direct IT practice — Canadian professional firms

White Glove Request an introduction
Menu

Email security

Make the everyday inbox a harder target, on purpose.

Everyday security habits catch a lot. This is the technical layer behind them: filtering tuned past its defaults, sending domains authenticated, and quarantine reviewed as quiet recurring maintenance—so the inbox stays a harder target without turning every message into a decision someone has to make alone.

Stopping the message before it lands

Most everyday email risk is filtered out before anyone has to make a judgment call—when the filtering is actually tuned, not left on its defaults.

Anti-phishing and anti-spoofing filtering

Inbound mail is screened for impersonation patterns, look-alike sending domains, and known-bad senders before it reaches an inbox, not only checked against a generic spam list.

Attachment and link inspection

Attachments and links are checked for malicious content, including at the moment a link is actually clicked, not only when the message first arrives.

Domain authentication: SPF, DKIM, DMARC

Your own sending domain is configured so other mail systems can verify a message genuinely came from you, cutting down on spoofed sender addresses that impersonate your business.

Quarantine review and the impersonation risk behind it

Filtering catches most of it. What happens next—and who is actually being targeted—is where firms handling money need a closer look.

Routine quarantine review

Messages held back by filtering are reviewed on a regular cadence, so a legitimate email is not silently lost and a real attempt is not quietly ignored.

A verification habit, not a reflex

Releasing a quarantined message, or acting on one that requests a payment or account change, is a considered decision confirmed through a second channel—not a reflex.

Look-alikes and repeat attempts, tracked

Domains that closely resemble your own, and repeated attempts against the same mailbox, are tracked as a pattern worth watching, not discovered after the fact or dismissed as unrelated noise.

What this covers—and what it doesn’t

Naming this as its own discipline does not turn it into a different promise than the rest of routine IT care.

A configured layer, not a SOC

This is filtering, authentication, and routine review inside business-hours support—not a staffed, round-the-clock security operations centre watching every message in real time.

Confirmed compromise needs more

A mailbox that has actually been compromised, or a successful fraud transfer, needs a dedicated incident-response process and often legal or banking involvement beyond routine mail hygiene.

Formal threat-intelligence programs

Structured threat-hunting, dark-web monitoring, and formal security-operations engagements are specialist work, scoped and priced separately from this recurring layer.

Prepare this

A useful conversation starts with simple facts.

  • Current filtering in place for the mailbox platform you use
  • Whether SPF, DKIM, and DMARC are configured for your domain
  • Who reviews quarantined mail today, and how often
  • Any recent phishing, spoofing, or invoice-fraud attempts worth noting
  • Mailboxes that handle payments or sensitive approvals

Bring the context; keep credentials out of the message.

Request an introduction

Prepare a useful introduction

Describe the interruption, the change ahead, and how your team prefers to be kept informed. A short note is enough to begin a service-fit conversation.

Required fields are marked with an asterisk (*).

Never include passwords, keys, recovery codes, or account-access details.

Read the privacy policy to understand how this request will be handled.