Locking Down Email Across Nearly 30 Domains
A hosting platform carried 29 business domains that had accumulated over the years. Some had strong email security, some had none, and several had records pointing at services that no longer existed.
The challenge
Criminals impersonate businesses by sending email that appears to come from their domain. Fixing that across dozens of domains, some using our mail server, some Microsoft 365 or Google, and some sending from websites, means getting every record exactly right, because one mistake can stop legitimate email.
What we did
- A full audit: Every DNS zone and mail domain checked for SPF, DKIM, DMARC, stale records and risky settings
- Impersonation blocked: SPF tightened on 14 domains, and DMARC set to reject on 13, including 9 domains that never send email and were easy targets
- Signing added: DKIM signing set up on domains that were missing it
- Stale records removed: Records pointing at retired services deleted before anyone could take advantage of them
- Encryption enforced: DANE and MTA-STS added to the mail server, so other servers must use verified encryption when delivering mail, plus CAA records controlling who can issue certificates
- Kept that way: Daily automated checks alert us if anything drifts
The result
- Harder to impersonate: Domains that send no email can no longer be used to fake messages from the business
- Encrypted in transit: Mail to and from the server is encrypted and verified
- Problems found early: The audit uncovered a delivery fault caused by a broken record at another organisation’s domain, which we diagnosed and worked around
- Attacks slowed: Around 900 password-guessing attempts a day are now blocked faster and for longer
Services involved
Not sure who can send email as your business? Call 04 282 0045 or send us a message.