A convincing email that appears to come from a supplier can change bank details, request urgent payment, or share a malicious file in minutes. For a small business, one missed warning sign can lead to lost funds, exposed customer data, and disruption that lasts far longer than the email itself. This email security checklist focuses on the controls that make a practical difference without creating unnecessary friction for your team.
Email is often the front door to the rest of your business systems. It contains invoices, client conversations, contracts, password resets, cloud access notifications, and sensitive internal information. Protecting it needs more than spam filtering. It requires clear processes, secure account settings, and employees who know when to pause and verify a request.
Email Security Checklist for Your Business
Work through this checklist as part of your regular IT review. The right priorities will depend on your industry, the information you handle, and the systems connected to your email accounts, but these measures provide a strong foundation for most small and mid-sized businesses.
1. Turn on multifactor authentication for every account
Multifactor authentication, often called MFA, is one of the most effective ways to reduce account takeover risk. A stolen password alone should never be enough for someone to access a mailbox. Require MFA for email, administrator accounts, cloud storage, finance platforms, remote access tools, and any application that relies on email for password resets.
Authenticator apps or security keys generally provide better protection than text-message codes, which can be vulnerable to phone number fraud. However, the best method is the one your team will use consistently. Make sure recovery methods are controlled, former employees cannot retain access, and emergency administrator accounts are protected and reviewed.
2. Use strong, unique passwords and a password manager
Employees should not reuse the same password for work email, personal accounts, and other business systems. A breach at an unrelated service can expose credentials that attackers then test against Microsoft 365, Google Workspace, or other business email platforms.
A business password manager makes unique, long passwords realistic. It also reduces the temptation to keep credentials in browsers, notebooks, spreadsheets, or shared documents. Set a clear policy for password sharing: use approved shared vaults where necessary, never send passwords through email or chat.
3. Remove access as soon as roles change
Former staff, contractors, and temporary workers are a common source of overlooked access. When someone leaves, their email account should be disabled promptly, active sessions should be revoked, and mailbox forwarding rules should be checked. If the role involved financial approvals, payroll, customer data, or IT administration, review all related permissions as well.
For current employees, avoid giving everyone broad access simply because it is convenient. A person who only needs to read a shared mailbox should not automatically have permission to alter security settings or create mailbox rules. Least-privilege access takes a little planning, but it limits the damage if an account is compromised.
4. Train staff to spot phishing and impersonation
Modern phishing messages are not always poorly written or easy to identify. Attackers can copy a vendor’s branding, imitate an executive’s tone, or use information taken from social media and past breaches. The most dangerous emails often create urgency: a payment is overdue, a password expires today, or a manager needs a gift card immediately.
Train employees to verify unexpected requests through a separate channel. If a supplier emails new payment details, call a known phone number from your records, not the number in the message. If a senior leader requests confidential information or a fast transfer, confirm it by phone or in person. This simple habit is particularly valuable for finance and accounts teams.
Staff should report suspicious messages rather than quietly deleting them. A report may reveal that multiple people received the same attack, allowing your IT provider to block it before someone clicks.
5. Protect your domain from spoofing
A criminal does not need access to your mailbox to send messages that appear to come from your business domain. Domain authentication records help receiving email systems determine whether a sender is legitimate and reduce the chance that your customers, suppliers, and staff receive a spoofed message.
Your IT team should configure and monitor SPF, DKIM, and DMARC records. These are technical controls, but the business outcome is straightforward: stronger protection for your reputation and fewer opportunities for criminals to impersonate your organization. Configuration needs to be handled carefully, especially when you use third-party systems for marketing, invoicing, or customer communications. An overly strict policy without proper testing can block valid email.
6. Check mail forwarding rules and connected apps
Once an attacker gets into an email account, they may create a hidden forwarding rule to receive copies of messages outside your business. They may also set rules that move security warnings, invoices, or replies into obscure folders. These actions allow them to remain unnoticed while they monitor conversations.
Review forwarding rules regularly, especially for leadership, finance, and shared accounts. Restrict automatic forwarding to external addresses unless there is a documented business reason. Also review third-party applications that have permission to access mailboxes. Remove old integrations and investigate unfamiliar applications, particularly those granted broad read, send, or delete permissions.
7. Secure the devices that access email
Email security is only as strong as the laptop, desktop, or phone used to open the mailbox. Keep operating systems, browsers, office software, and antivirus tools updated. Require device screen locks and encryption, and make sure lost company devices can be remotely managed or wiped where appropriate.
Personal devices may be acceptable for some businesses, but they need boundaries. If staff use personal phones for email, decide what data can be accessed, whether app-level protection is required, and how business information will be removed when employment ends. The answer depends on your risk level and budget, but an informal approach usually creates problems later.
8. Apply extra controls to payments and sensitive requests
No email control can guarantee that a well-crafted impersonation attempt will never reach an inbox. Financial processes should therefore include a second layer of verification. Payment detail changes, new supplier setup, payroll amendments, and unusual transfer requests should never be approved from email alone.
Use a documented callback procedure and a dual-approval process for payments above an agreed threshold. Keep the process consistent even when a request seems to come from an owner, director, or trusted vendor. Attackers rely on exceptions, pressure, and people feeling reluctant to question authority.
9. Back up critical data and test recovery
Cloud email platforms offer useful protection, but retention and recovery requirements vary. Deleted messages, ransomware activity, accidental changes, and malicious mailbox rules can still create a significant operational issue. Consider whether your business needs independent backup for email, files, contacts, calendars, and collaboration data.
A backup only helps if it can be restored when needed. Test recovery periodically and confirm who has authority to request it. For businesses with legal, financial, health, or client confidentiality obligations, retention requirements may also need input from management or professional advisers.
10. Have a clear response plan for suspicious activity
Employees should know what to do if they click a suspicious link, enter credentials into a fake page, or notice unusual mailbox behavior. The correct response is to report it immediately, not to wait and hope nothing happened. Early action can stop an attacker from using a compromised account to target customers or redirect payments.
Your response plan should identify who to contact, how accounts will be secured, and how affected clients or suppliers will be notified if needed. At a minimum, your IT support team should be able to reset credentials, revoke sessions, review sign-in activity, remove malicious rules, scan devices, and assess whether other accounts are at risk.
Make Email Security a Routine Business Control
An email security checklist should not be a one-time project completed after a scare. Review account access when people join or leave, check security settings at least quarterly, and run phishing awareness reminders throughout the year. High-risk areas such as finance mailboxes, shared accounts, and administrator access deserve more frequent attention.
For Auckland businesses that need practical support, IT Sales & Services can help assess email security settings alongside the wider systems that keep your team operating. The goal is not to burden staff with technical rules. It is to build solutions that work, protect daily communication, and give your business a reliable path to respond when something does not look right.
The strongest email defenses combine technology with a team that feels confident stopping, checking, and reporting an unusual request. That small pause can protect far more than an inbox.