Interactive controls are loading. Phone and email links are available.

Skip to main content

Email Security Audit

91% of cyber attacks begin with a phishing email. Our audit checks your SPF, DKIM, and DMARC configuration, tests whether attackers can spoof your domain, and assesses your organisation's resilience to email-based threats.

Why Email Security Matters for Your Business

91%

Attacks Start Here

91% of all cyber attacks begin with a phishing email - making your email infrastructure the most critical security boundary to defend

$2.7M

BEC Loss Average

Business Email Compromise cost Australian organisations an average of $2.7 million per incident in 2025 - often through spoofed executive emails

67%

Domains Unprotected

67% of Australian business domains lack proper DMARC enforcement, meaning anyone can send emails that appear to come from your company

$300

Affordable Protection

A comprehensive email security audit at $300 identifies gaps before attackers exploit them - typically the highest-ROI security investment available

What Our Email Security Audit Covers

SPF Configuration Analysis

Sender Policy Framework (SPF) tells receiving mail servers which IP addresses are authorised to send email on behalf of your domain. We analyse your SPF record for common misconfigurations - overly permissive rules (using +all instead of -all), exceeding the 10-lookup limit, missing authorised senders, and conflicting records. A misconfigured SPF record is worse than none at all because it creates a false sense of security while leaving your domain spoofable.

Record syntax validation
Lookup limit compliance
Authorised sender coverage
Permissiveness assessment

DKIM Signing Verification

DomainKeys Identified Mail (DKIM) adds a cryptographic signature to outgoing emails, proving they have not been tampered with in transit. We verify that DKIM is properly configured for all your sending sources - your primary mail server, marketing platforms (Mailchimp, Brevo, HubSpot), transactional email services, and any third-party systems sending on your behalf. We also check key strength (minimum 2048-bit RSA) and key rotation practices.

Signature validation
All senders verified
Key strength assessment
Third-party DKIM checks

DMARC Policy Assessment

Domain-based Message Authentication, Reporting & Conformance (DMARC) ties SPF and DKIM together and tells receiving servers what to do with emails that fail authentication - monitor (p=none), quarantine, or reject. We assess your DMARC policy strength, reporting configuration (rua/ruf), alignment settings, and subdomain coverage. Most organisations start at p=none and never progress to enforcement - we provide a roadmap to reach p=reject safely without blocking legitimate email.

Policy enforcement review
Reporting configuration
Alignment analysis
Enforcement roadmap

Domain Spoofing Simulation

We conduct controlled spoofing tests - attempting to send emails that appear to originate from your domain to test whether your authentication controls actually block impersonation in practice. This real-world validation goes beyond configuration review, revealing whether receiving mail servers honour your SPF/DKIM/DMARC policies. Many organisations have technically correct records that still allow spoofing due to alignment issues or overly permissive rules.

Real spoofing attempts
Practical validation
Alignment gap detection
Impersonation testing

Phishing Resilience Assessment

Beyond technical controls, we assess your organisation's human defences against phishing. This includes reviewing email filtering effectiveness, examining whether dangerous attachment types are blocked, checking if URL rewriting and sandboxing are active, and assessing whether external email warning banners are displayed. We test common phishing techniques - lookalike domains, compromised reply chains, and urgency-based social engineering - against your email gateway.

Email filter testing
Attachment blocking review
URL sandboxing check
Social engineering assessment

Mail Server Hardening Review

We examine your mail server configuration for security weaknesses - TLS enforcement (opportunistic vs mandatory), cipher suite strength, open relay testing, SMTP enumeration vulnerabilities, and MX record security. For Microsoft 365 and Google Workspace environments, we review tenant-level security settings including conditional access, legacy authentication protocols, and admin account protection that could allow account compromise even with strong email authentication.

TLS enforcement check
Open relay testing
Cipher suite review
Cloud tenant security

See How AI Can Transform Your Operations

Get a personalized demo and ROI assessment for your business in a 30-minute consultation.

No obligation30 min callDiscuss potential value

Email Security Audit Process

Phase 1
1 day

Configuration Discovery

  • Enumerate all domains and subdomains used for email sending
  • Retrieve and analyse SPF, DKIM, and DMARC DNS records
  • Identify all legitimate email sending sources (mail servers, marketing tools, SaaS platforms)
  • Review MX records and mail server configurations
  • Check TLS settings and certificate validity
  • Map email flow through any gateways, filters, or proxies
Phase 2
1-2 days

Testing & Simulation

  • Conduct controlled domain spoofing simulation
  • Test SPF/DKIM/DMARC enforcement from multiple external sources
  • Attempt delivery of common phishing payload types
  • Test email filtering against known malicious attachments and URLs
  • Check for open relay and SMTP enumeration vulnerabilities
  • Validate DKIM signing across all authorised sending sources
Phase 3
1 day

Reporting & Remediation Roadmap

  • Compile findings with risk ratings and exploitation evidence
  • Provide corrected DNS records ready for copy-paste implementation
  • Deliver DMARC enforcement roadmap (none → quarantine → reject)
  • Produce executive summary with business impact assessment
  • Conduct findings walkthrough call with your IT administrator
  • Offer 30-day follow-up check to verify implementation

Email Security Audit FAQs

What is an email security audit?

An email security audit assesses how well your domain is protected against email-based attacks - spoofing, phishing, business email compromise, and interception. We check the three core email authentication protocols (SPF, DKIM, DMARC), test whether attackers can send emails impersonating your domain, review your mail server security, and assess your email filtering effectiveness. The result is a clear picture of your email security posture with actionable steps to close gaps.

How much does an email security audit cost?

Our Email Security Audit is $300 AUD. This includes SPF, DKIM, and DMARC analysis for your primary domain, domain spoofing simulation testing, mail server hardening review, a phishing resilience assessment, a detailed report with corrected DNS records, and a DMARC enforcement roadmap. Additional domains can be added for $100 each. The audit is also included in our Full Business Security Assessment at $1,200.

What are SPF, DKIM, and DMARC?

SPF (Sender Policy Framework) specifies which servers can send email from your domain. DKIM (DomainKeys Identified Mail) adds a cryptographic signature proving emails have not been tampered with. DMARC (Domain-based Message Authentication, Reporting & Conformance) ties them together and tells receiving servers what to do with emails that fail authentication. Together, they prevent attackers from sending emails that appear to come from your domain - but only if all three are correctly configured and enforced.

Can someone really send emails as our company?

If your DMARC policy is set to p=none (or missing entirely), the answer is likely yes. Without enforcement, anyone can send an email that appears to come from your domain - to your clients, suppliers, or employees. This is called domain spoofing and it is the foundation of Business Email Compromise (BEC) attacks, which cost Australian organisations millions annually. Our spoofing simulation test demonstrates exactly what an attacker can do today.

We use Microsoft 365 / Google Workspace - are we already protected?

Microsoft 365 and Google Workspace provide excellent built-in spam filtering, but neither automatically configures SPF, DKIM, or DMARC enforcement for your custom domain. We frequently find organisations using these platforms with p=none DMARC policies, weak SPF records, or DKIM not enabled for third-party senders. The platform protects your inbox; our audit ensures your domain cannot be impersonated outbound.

What is Business Email Compromise (BEC)?

BEC is a targeted attack where criminals impersonate a trusted person - usually a CEO, CFO, supplier, or solicitor - via email to trick employees into transferring funds, sharing credentials, or disclosing sensitive information. BEC attacks cost Australian businesses $2.7 million per incident on average. They rely on domain spoofing (sending from your actual domain) or lookalike domains (yourdomain.com vs yourdoma1n.com). Our audit tests both vectors.

How long does the email security audit take?

The full audit takes 3-4 business days from start to report delivery. Day one covers configuration discovery and DNS analysis. Days two and three involve spoofing simulation, phishing resilience testing, and mail server review. The report is delivered by day four, followed by a findings walkthrough call at your convenience. If urgent issues are found (e.g., completely missing DMARC), we notify you immediately.

Will the audit affect our email delivery?

No. Our testing is non-invasive. Spoofing simulation emails are sent from external infrastructure (not through your mail servers) to test whether receiving servers honour your authentication policies. We never modify your DNS records, mail server configuration, or email filtering rules. The audit observes and tests - it does not change anything.

What is a DMARC enforcement roadmap?

Moving from p=none (monitor only) to p=reject (block spoofed emails) requires careful planning to avoid accidentally blocking legitimate email. Our roadmap guides you through the process: first enabling DMARC reporting to identify all legitimate senders, then ensuring each sender has valid SPF and DKIM, then moving to p=quarantine, and finally to p=reject. We include timeline estimates and checkpoint criteria for each stage.

Do you check our email filtering and anti-spam settings?

Yes. We review your email gateway or cloud filtering configuration - checking whether dangerous attachment types are blocked, URL rewriting and sandboxing are enabled, external email warning banners are displayed, and advanced threat protection features are active. We also test filter effectiveness by sending controlled test emails with common phishing characteristics to see what gets through.

Our domain already has DMARC - do we still need an audit?

Having a DMARC record is only the first step. Many organisations have DMARC set to p=none (which only monitors, does not block), have misconfigured alignment settings, or have SPF records that exceed the 10-lookup limit (causing silent failures). Our audit validates that your configuration actually works in practice - not just that the DNS records exist. We frequently find "green-tick" configurations that still allow spoofing.

Can you help us implement the fixes, or just report them?

Our standard $300 audit includes a report with corrected DNS records that your IT administrator can copy-paste into your DNS provider. For organisations without internal IT resources, we offer a hands-on implementation add-on where our team configures SPF, DKIM, and DMARC directly in your DNS and email platform - ensuring everything is set up correctly and monitored through the enforcement journey.

Stop Attackers Impersonating Your Domain

A $300 email security audit reveals whether your business is vulnerable to spoofing, phishing, and business email compromise - with a clear roadmap to fix it.