Skip to main content
Email Security Audit, India

Find out in 3-5 days whether your email can be spoofed, intercepted, or quietly forwarded out.

A remote email security audit for Indian organisations on Microsoft 365 or Google Workspace. We examine SPF, DKIM and DMARC enforcement, MX and transport rules, anti-phishing and impersonation protection, external forwarding, mailbox delegation and OAuth grants, encryption in transit, your phishing-report workflow, and lookalike-domain exposure. You get a domain authentication scorecard, a staged DMARC roadmap to p=reject, and a findings report with prioritised fixes.

Security engineer reviewing email authentication records and tenant configuration during an email security audit
  • 3-5 daysTypical turnaround, fully remote
  • 40+Checks across DNS, tenant, and mailboxes
  • p=rejectThe DMARC enforcement goal
  • Both stacksMicrosoft 365 and Google Workspace
What the audit examines

Nine areas, from your DNS records to the rules inside each mailbox.

Email attacks succeed in the gaps between layers: a correct DMARC record undone by a forwarding rule, a strong password undone by an OAuth grant nobody reviewed. The audit covers every layer on one engagement so the gaps between them are visible.

SPF, DKIM and DMARC posture

Every domain and subdomain you own, checked for record presence, syntax, the SPF ten-lookup limit, DKIM signing on every sending source, and DMARC alignment. Not just whether records exist, but whether they would actually pass for the mail you legitimately send.

DMARC enforcement level

A DMARC record at p=none monitors and blocks nothing. We establish where each domain sits today, whether aggregate reports are being collected and read, and what stands between you and p=reject. Most Indian domains we check are either unprotected or parked at monitoring.

MX, connectors and transport rules

The path mail actually takes in and out: MX records, inbound connectors or gateways, and the transport rules or routing policies that can bypass filtering entirely. A single forgotten bypass rule can exempt an attacker from every control you have configured.

Anti-phishing and impersonation protection

Defender for Office 365 anti-phishing policies or Google Workspace spoofing and authentication controls, checked against what is licensed. The recurring finding: impersonation protection exists but the protected-sender list is empty, or names a leadership team from years ago.

External forwarding rules

Automatic forwarding to external addresses at the tenant, policy and mailbox level. Attackers who compromise a mailbox almost always set a forward or a hidden inbox rule first, so they can watch invoice conversations silently. We enumerate every one and ask who created it.

Mailbox delegation and OAuth grants

Delegate access, send-as rights, and third-party apps granted read or send access to mail through OAuth. Consent-phishing bypasses passwords and MFA entirely, and grants persist until someone revokes them. We list every grant with its scope and ask whether it should exist.

Encryption in transit

Whether your mail flows over TLS, whether MTA-STS or TLS reporting is published, and whether any partner connection silently falls back to plain text. Payment instructions and personal data crossing the internet unencrypted is a finding your compliance team needs to know about.

User-reported phishing workflow

What happens when a member of staff spots a suspicious mail. Is there a report button, does the report reach anyone, does anyone act on it, and how fast. A working report loop routinely catches campaigns hours before any filter update does, and most organisations have never tested theirs.

Lookalike-domain exposure

Domains that resemble yours: swapped letters, added hyphens, different endings. DMARC cannot stop these because the attacker authenticates their own domain perfectly. We check what is already registered near your name and what monitoring, if any, would tell you when the next one appears.

Why this audit, why now

Business email compromise is the attack that actually costs Indian businesses money.

Ransomware makes the headlines. Email fraud quietly drains accounts. The pattern is consistent across the cases we see: an attacker studies invoice conversations, then a payment instruction changes at exactly the right moment.

  • The wire-fraud pattern: a supplier or customer mailbox is compromised, the attacker reads months of genuine correspondence, and then a mail arrives on the real thread saying bank details have changed. The transfer goes to the attacker. Indian exporters, importers and firms making regular overseas payments see this constantly, and the losses per incident are frequently substantial, sometimes six-figure and occasionally far worse.
  • The invoice-fraud variant: the attacker registers a lookalike of your domain or your supplier's, and sends an invoice that looks exactly right. Accounts teams processing dozens of invoices a week are not going to spot one swapped letter in a domain name. Process controls and technical controls both matter here, and the audit tells you which technical ones you are missing.
  • CERT-In's 2022 directions require covered organisations to report specified cyber incidents, including unauthorised access to systems and data breaches, within six hours of noticing them. If you discover a compromised mailbox, that clock is already running. Knowing your email estate is clean before an incident is far cheaper than reconstructing what happened during one.
  • Mailboxes are full of personal data: customer details, employee records, KYC documents sitting in attachments. Under the DPDP Act, a breach of personal data carries notification obligations to the Data Protection Board and to affected individuals, and weak security safeguards are themselves a compliance failure. A leaked mailbox is not just an IT problem, it is a regulatory event.
Book the audit before the incident
Why GR IT for this audit

Four reasons this audit finds what a config review misses.

Reading policies tells you what was intended. The audit measures the gap between that and what your mail actually experiences, and that gap lives in exceptions, forwarding rules and OAuth grants.

Both platforms, one method

We run the same checklist across Microsoft 365 and Google Workspace, so organisations running both, or migrating between them, get one consistent picture instead of two vendor-shaped ones. Multi-domain groups are covered on a single engagement.

We read what nobody reviews

Allow lists, bypass transport rules, inbox rules, delegations, OAuth consents. These accumulate for years, never expire, and are where both misconfiguration and active compromise hide. Enumerating them is the highest-yield part of any email audit.

Honest about what DMARC fixes

DMARC at p=reject closes exact-domain spoofing completely, and does nothing about lookalike domains or a compromised supplier mailbox. We say so, and we cover the layers that address those too, rather than selling one record as the answer to fraud.

Remote-first across India

The entire audit runs remotely from our Gachibowli, Hyderabad HQ: DNS is public, and tenant evidence needs only read access. Chennai, Mumbai, Bengaluru, Delhi NCR or anywhere else, the engagement is identical and no travel is billed or needed.

The DMARC journey

From no record to p=reject, staged so legitimate mail never breaks.

The reason so many domains sit at p=none for years is that the next step carries a real risk of blocking your own invoices and newsletters. Staged correctly, with reporting watched at every step, that risk is engineered out. This is the roadmap the audit hands you.
  1. 01
    Stage 0· Where many Indian domains start

    No DMARC record

    Anyone on the internet can send mail with your exact domain in the From address, and receiving servers have no instruction to stop it. Your first move costs nothing: publish a record at p=none with a reporting address, which changes nothing about mail flow but starts the data collection everything else depends on.

    • DMARC record published at p=none with rua reporting
    • Aggregate reports collected somewhere legible
    • SPF and DKIM baseline captured for every domain
  2. 02
    Stage 1· Typically 2-4 weeks of observation

    p=none, monitoring

    Reports now show every source sending as your domain: your mail platform, your marketing tool, your invoicing system, and anything you forgot. This is the discovery stage, and it is the one that cannot be safely skipped. Every legitimate sender gets SPF and DKIM configured and aligned before anything is blocked.

    • Full inventory of every service sending as your domain
    • SPF within the ten-lookup limit, DKIM signed per sender
    • Alignment verified so DMARC actually passes for legitimate mail
  3. 03
    Stage 2· Stepped up in controlled increments

    p=quarantine, partial then full

    Failing mail now goes to spam rather than the inbox. We start at a partial percentage so any mistake affects a fraction of mail, watch the reports, then increase coverage. Each step is reversible in the time a DNS record takes to update, which is why this stage is safe when it is done patiently.

    • Quarantine applied at a partial percentage, then increased
    • Reports reviewed at each step for legitimate failures
    • Rollback path documented and tested
  4. 04
    Stage 3· The destination, then ongoing

    p=reject, enforcement

    Receiving servers now refuse mail that fails authentication for your domain. Exact-domain spoofing is closed permanently. Monitoring continues, because domains drift: a new marketing platform or a department signing up for a tool can silently add an unauthenticated sender, and the reports catch it before your own mail starts failing.

    • p=reject published across primary and parked domains
    • Subdomain policy set, unused domains locked down
    • Ongoing report review handed over or retained by us
Who needs this most

Six situations where this audit is the right next move.

Every organisation with a domain should be authenticated. These are the situations where the cost of not knowing is concrete and near-term.

Finance teams that wire money on emailed instructions

If a bank-detail change arriving by email could trigger a transfer, you are the exact target BEC is built for. The audit hardens the technical layer and flags where a verification-by-phone process must back it up, because no filter catches a mail from a genuinely compromised counterparty.

Exporters and importers on overseas invoice flows

Cross-border trade means invoices from counterparties you have never met, in time zones where a quick verification call is hard. That friction is precisely what invoice fraud exploits. Authentication, impersonation protection and lookalike monitoring narrow the attacker's room to work.

Companies that have already been spoofed

If customers or partners have received mail pretending to be you, the fix is enforcement: DMARC at p=reject makes exact-domain forgery bounce. The audit inventories every legitimate sender first so enforcement blocks the attacker and not your own invoices.

Companies whose mail lands in spam

Deliverability trouble usually traces to authentication, not content: a broken SPF record over its lookup limit, an unsigned sending service, or missing alignment. Google and other major receivers now require authentication from bulk senders, so this is a revenue problem, not a cosmetic one.

Organisations preparing for DPDP readiness

Mailboxes hold personal data, and the DPDP Act expects reasonable security safeguards around it. An email audit produces written evidence of controls over the system where most personal data actually moves, and findings your data-protection programme can action directly.

Organisations running both Microsoft 365 and Workspace

Mergers, subsidiaries and gradual migrations leave many Indian organisations running two mail platforms with two half-configured control sets. One audit across both surfaces the inconsistencies, including the domain that is enforced on one platform and wide open on the other.

Deliverables

Three documents you can act on, not a PDF that lives in a drawer.

Every finding is written so a competent administrator can implement it, and prioritised so the highest fraud-exposure items come first. If you want us to implement instead, the same documents become the work order.

Domain authentication scorecard

Every domain and subdomain you own, scored on SPF, DKIM, DMARC presence, alignment and enforcement level.

  • Per-domain pass and fail against each authentication check
  • SPF lookup count against the ten-lookup limit
  • Sending-source inventory with alignment status per service
  • Parked and unused domains flagged for lockdown

DMARC enforcement roadmap

The staged plan from wherever you are today to p=reject, with the observation windows and rollback points written in.

  • Stage-by-stage plan with entry and exit criteria
  • Per-sender remediation list before each stage
  • Reporting setup so progress is visible, not guessed
  • Realistic timeline, typically 6-10 weeks to full enforcement

Findings report with prioritised fixes

Everything the tenant and mailbox review found, ordered by what reduces fraud exposure fastest.

  • Executive summary your leadership can read in five minutes
  • Technical findings with severity and exact remediation steps
  • Forwarding rules, delegations and OAuth grants enumerated
  • CERT-In and DPDP-relevant observations flagged for compliance
Exposed vs hardened

What an exposed email posture looks like next to a hardened one.

Most organisations sit somewhere in the left column without knowing it, because nothing visibly breaks. The audit tells you exactly which rows apply to you.
Feature
Exposed posture
Configured once, never reviewed
Hardened posture
Audited and enforced
Exact-domain spoofing
Can someone send mail as your exact domain?
Possible, DMARC absent or at p=noneBlocked at p=reject
Sending-service inventory
Unknown, grown over yearsDocumented and aligned
SPF record health
Often over the lookup limit, silently failingWithin limits, monitored
Impersonation protection
Unlicensed, or licensed with empty listsPopulated with current leadership and finance
External auto-forwarding
Permitted, unreviewedBlocked by default, exceptions documented
Inbox rules and delegations
Never enumeratedReviewed, compromise artefacts removed
OAuth grants with mail access
Accumulating unseenEnumerated, unneeded grants revoked
Encryption in transit
Opportunistic, unverifiedTLS verified, MTA-STS considered
User phishing reports
No route, or reports go nowhereReport button wired to a person who acts
Six-hour incident clock readiness
Would start the investigation from zeroBaseline documented before any incident
How the audit runs

Five steps, 3-5 days, entirely remote.

DNS evidence is public. Tenant evidence needs read-only access, which you grant at the start and revoke at the end. No agents installed, no mail flow touched, no downtime.
  1. 1

    Scoping and access

    Day 1

    A short call to list your domains, platforms and known sending services. You grant read-only access to Microsoft 365, Google Workspace or both, plus a view of DNS. We confirm scope in writing before anything is examined.

  2. 2

    DNS and authentication review

    Day 1-2

    SPF, DKIM and DMARC for every domain and subdomain, lookup counts, alignment per sending service, MX records, TLS posture, and the lookalike-domain check. The domain authentication scorecard takes shape here.

  3. 3

    Tenant configuration review

    Day 2-3

    Anti-phishing and anti-spoofing policies, impersonation lists, transport and routing rules, allow and block lists, quarantine behaviour, and the settings that govern forwarding and encryption. Checked against what your licensing already includes.

  4. 4

    Mailbox, OAuth and workflow review

    Day 3-4

    External forwarding rules, hidden inbox rules, delegate and send-as permissions, OAuth applications with mail scopes, and how a user-reported phish actually travels through your organisation. This is where evidence of past compromise turns up when it exists.

  5. 5

    Report and readout

    Day 4-5

    The scorecard, the DMARC roadmap and the findings report, delivered with a live readout for your IT and finance stakeholders. Fixes are ordered by fraud-exposure reduction. If you want us to implement, the roadmap becomes the work order and access stays read-only until you approve changes.

Straight answers

Email security audit, the questions that decide it.

Check yourself first

Fifteen questions you should be able to answer about your email.

These are the questions the audit works through. The first group is public DNS you can look up today. The second needs tenant access. The third is where compromise hides, and almost nobody can answer it without looking.

Authentication (public, check today)

  • Does your domain have a DMARC record at all?
    Look up _dmarc followed by your domain.
  • If yes, is the policy none, quarantine or reject?
    p=none blocks nothing.
  • Is your SPF record within its ten-lookup limit?
    It breaks silently when exceeded.
  • Is DKIM enabled for every sending service?
    Usually on for the platform, off for everything else.
  • Are unused and parked domains locked down?
    Attackers prefer the domains nobody watches.

Tenant configuration

  • Is impersonation protection populated and current?
    Leadership and finance names change.
  • Are transport rules bypassing your filters?
    The most powerful and least visible exception.
  • Is external auto-forwarding blocked by default?
    Per policy and per mailbox, both matter.
  • Is mail to partners forced over TLS?
    Payment instructions should never travel plain.
  • Do users have a working way to report phishing?
    And does anyone read what they report.

Where compromise hides

  • When were inbox rules last reviewed?
    Hidden rules are the classic BEC artefact.
  • Can you list every OAuth app with mail access?
    Consent phishing bypasses MFA entirely.
  • Who holds delegate or send-as rights, and why?
    Grants outlive the reason they were made.
  • Are lookalikes of your domain registered?
    DMARC cannot stop them; monitoring can spot them.
  • Would you meet a six-hour reporting clock?
    CERT-In directions do not wait for your investigation.
Next step

Look up your DMARC record today. If it says p=none, or nothing, start here.

Three-minute form, initial reply within 4 business hours. Tell us your domains and your platform, and we will tell you in the first conversation what your public records already reveal, before you commit to anything.