Skip to main content
Service

Email security that stops people sending invoices as you

Filtering catches what arrives. SPF, DKIM and DMARC stop your own domain being used against your customers. Most businesses have the first and not the second.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Advanced email filtering plus correctly configured SPF, DKIM and DMARC — stopping both what arrives in your inbox and what gets sent using your domain.

Two different problems

“Email security” usually gets sold as one thing — filtering — and it addresses only half the risk.

What arrives. Phishing, malicious attachments, links that lead somewhere unpleasant. This is what filtering handles, and most businesses have something in place.

What gets sent as you. Anyone can compose an email claiming to be from your accounts address. Without the right DNS records, receiving mail servers have no way to tell that it is forged and will generally deliver it. Your customer receives an invoice that looks entirely legitimate, with different bank details.

The second problem damages your customers and your reputation rather than your inbox, which is precisely why it goes unaddressed for years. Nothing looks wrong from where you are sitting.

Fixing the outbound half

SPF, DKIM and DMARC are three DNS records. Configured correctly, forged mail claiming to be your domain gets rejected by the receiving server before a human sees it.

The catch is “correctly”. Partial SPF records that miss half your legitimate senders, DKIM that was never enabled, and DMARC set to p=none and left there for three years are all extremely common. A DMARC record in monitoring mode tells receiving servers to do nothing, which means the protection is not switched on.

Deployment is staged deliberately: monitoring first, so the reports reveal every system legitimately sending as you — the accounting platform, the CRM, the booking tool nobody remembered — then authorise those, then tighten policy to quarantine and finally reject. Skipping the staging is how a business blocks its own invoices.

Fixing the inbound half

Within Microsoft 365, the controls worth configuring properly are anti-phishing and impersonation policies (catching the display-name trick, where the name says John Taylor and the address is a Gmail account), safe links with click-time checking, safe attachments, and external sender warnings.

The one that catches the most real incidents, though, is not a filter at all: alerting on inbox rule creation. The first action after a mailbox compromise is almost always a hidden rule that forwards or deletes incoming mail so the real owner does not see the replies. Alerting on that is cheap, and it is how a compromise gets caught in hours rather than after the payment is gone.

Where this connects

Email security is the delivery mechanism for most attacks, but the damage usually happens elsewhere: a stolen credential used to log in, which is what multi-factor authentication limits, or a person acting on a convincing message, which is what awareness training addresses.

None of the three works alone. Together they cover the path an actual incident takes.

What you get with JTIT

Concrete deliverables, not vague promises.

Nobody can send mail as your domain

Correct SPF, DKIM and DMARC means a forged invoice claiming to come from your accounts address gets rejected before your customer sees it.

Impersonation detection inside the tenant

The display-name trick — 'John Taylor' from a Gmail address — is caught and flagged rather than delivered looking legitimate.

Links rewritten and checked on click

A link that was clean at delivery and weaponised an hour later is checked again at the moment someone clicks it, not just on arrival.

Mailbox rule monitoring

The first thing an attacker does with a compromised mailbox is create a hidden forwarding rule. We alert on rule creation, which is how these get caught early.

Attachment handling that assumes the worst

Macro-enabled documents, unusual archive formats and script files quarantined by policy rather than left to the user's judgement at 4:45pm.

Your staff learn the patterns

Filtering will never be perfect. Ongoing awareness training covers the ones that get through, because the last control is always a person.

How it works

A predictable, no-surprises process.

  1. 01

    Audit your DNS

    Check what SPF, DKIM and DMARC records actually exist. A partial or misconfigured SPF record is extremely common and provides close to no protection.

  2. 02

    Fix authentication first

    SPF, DKIM and DMARC brought to a correct configuration, then DMARC policy moved through monitoring to quarantine to reject as legitimate senders are confirmed.

  3. 03

    Layer filtering and impersonation controls

    Tenant policies for anti-phishing, safe links, safe attachments and external sender warnings, tuned so legitimate mail still lands.

  4. 04

    Monitor and train

    Mailbox rule alerts, quarantine review, and continuous staff training on the attacks that are actually reaching Australian businesses.

Frequently asked questions

What is business email compromise and why does it matter so much?

BEC is when an attacker uses email to fraudulently redirect a payment — typically by compromising a mailbox, watching genuine invoice conversations, and then sending a revised invoice with changed bank details at exactly the right moment. It works because nothing about the email is technically suspicious: it is a real conversation, often from a real address. It is consistently one of the highest-loss cybercrime categories reported in Australia, and the losses are usually not recoverable because the payment was authorised by your own staff.

What are SPF, DKIM and DMARC in plain terms?

Three DNS records that together prove mail claiming to be from your domain really is. SPF lists which servers may send as you. DKIM cryptographically signs your outbound mail. DMARC tells receiving servers what to do when the first two fail, and asks them to report back. Without them, anyone on the internet can send email that appears to come from your accounts address, and receiving mail servers have no basis to reject it.

We have Microsoft 365. Isn't email security included?

Microsoft 365 includes baseline filtering, and it is reasonable. What it does not do is configure your DNS authentication for you, tune anti-phishing and impersonation policies for your specific sender patterns, alert on suspicious mailbox rule creation, or review quarantine. Those are configuration and monitoring tasks, and in most tenants we audit they have never been done.

Will tightening email security block legitimate mail?

It can, if it is done carelessly — which is why DMARC is deployed in stages. Policy starts at monitoring only, so you gather reports on everything sending as your domain without rejecting anything. Legitimate senders you had forgotten about — your accounting platform, a marketing tool, a booking system — get authorised, and only then does policy tighten. Skipping that sequence is how businesses accidentally block their own invoices.

Is email filtering enough on its own?

No. Filtering is probabilistic and always will be. A well-crafted message from a genuinely compromised supplier mailbox contains nothing for a filter to object to. That is why the controls layer: authentication stops forgery, filtering stops volume attacks, MFA limits the damage of a stolen password, and training covers the residue.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote