The 10-minute email security fix
Most small business security problems start in email: a stolen password, or a scammer pretending to be you. Two changes shut most of that down. Turn on multi-factor sign-in, and tell the world which servers are allowed to send mail for your domain.
Do these first
- Multi-factor authentication (MFA) on every email account, starting with the owner and admins
- A unique, long password for email, stored in a password manager
- SPF record published for your domain
- DKIM signing turned on in your email provider
- A DMARC record published, starting in monitoring mode
- A phone-call rule: any change to payment details gets confirmed by phone
Step by step
Turn on MFA for email
In Google Workspace, Microsoft 365, or your email provider's security settings, require a second step at sign-in. An authenticator app or a security key is better than text messages, but any MFA is far better than none.
Use a password manager
A password manager creates and remembers a different strong password for every account. Reusing one password is how a leak from one site becomes a break-in at your email.
Publish an SPF record
SPF is a DNS record listing the services allowed to send email as your domain. Your email provider's help pages give the exact value to add. If you also send through a newsletter or invoicing tool, include it too.
Turn on DKIM
DKIM adds a signature to your outgoing mail so receivers can tell it's really from you. In Google Workspace and Microsoft 365 it's a setting plus one DNS record your provider gives you.
Add a DMARC record
DMARC tells receivers what to do with mail that fails the checks. Start with a policy of 'none' so you can watch reports without blocking anything, then tighten it once your legitimate mail all passes.
Create a payment-change rule
A common scam is a fake email asking you or a customer to change bank details. Agree on a simple rule: any change to payment information is confirmed by calling a known number, never by replying to the email.
Common mistakes to avoid
- Sharing one email login between several people
- Setting DMARC straight to 'reject' before checking that all your real mail passes
- Relying on text-message codes as the only protection for an admin account
- Forgetting to disable accounts of former employees
Common questions
I don't manage my own DNS. Who can add these records?
Whoever controls your domain, usually your website host or domain registrar. If you're not sure who that is, we can find it for you as part of a Security Checkup.
Will this stop all phishing?
No single step does. These changes make it much harder for criminals to take over your accounts or impersonate your domain, which are the two most damaging cases. Team awareness covers the rest.
Want us to handle it?
Start with the free Online Health Check, or send a question. We'll tell you honestly whether you can do it yourself or whether it's worth a hand.