Skip to main content
Email Security Audit, India

Find out in 3-5 days whether your email can be spoofed, intercepted, or quietly forwarded out.

A remote email security audit for Indian organisations on Microsoft 365 or Google Workspace. We examine SPF, DKIM and DMARC enforcement, MX and transport rules, anti-phishing and impersonation protection, external forwarding, mailbox delegation and OAuth grants, encryption in transit, your phishing-report workflow, and lookalike-domain exposure. You get a domain authentication scorecard, a staged DMARC roadmap to p=reject, and a findings report with prioritised fixes.

Security engineer reviewing email authentication records and tenant configuration during an email security audit
  • 3-5 daysTypical turnaround, fully remote
  • 40+Checks across DNS, tenant, and mailboxes
  • p=rejectThe DMARC enforcement goal
  • Both stacksMicrosoft 365 and Google Workspace
What the audit examines

Nine areas, from your DNS records to the rules inside each mailbox.

Email attacks succeed in the gaps between layers: a correct DMARC record undone by a forwarding rule, a strong password undone by an OAuth grant nobody reviewed. The audit covers every layer on one engagement so the gaps between them are visible.

SPF, DKIM and DMARC posture

Every domain and subdomain you own, checked for record presence, syntax, the SPF ten-lookup limit, DKIM signing on every sending source, and DMARC alignment. Not just whether records exist, but whether they would actually pass for the mail you legitimately send.

DMARC enforcement level

A DMARC record at p=none monitors and blocks nothing. We establish where each domain sits today, whether aggregate reports are being collected and read, and what stands between you and p=reject. Most Indian domains we check are either unprotected or parked at monitoring.

MX, connectors and transport rules

The path mail actually takes in and out: MX records, inbound connectors or gateways, and the transport rules or routing policies that can bypass filtering entirely. A single forgotten bypass rule can exempt an attacker from every control you have configured.

Anti-phishing and impersonation protection

Defender for Office 365 anti-phishing policies or Google Workspace spoofing and authentication controls, checked against what is licensed. The recurring finding: impersonation protection exists but the protected-sender list is empty, or names a leadership team from years ago.

External forwarding rules

Automatic forwarding to external addresses at the tenant, policy and mailbox level. Attackers who compromise a mailbox almost always set a forward or a hidden inbox rule first, so they can watch invoice conversations silently. We enumerate every one and ask who created it.

Mailbox delegation and OAuth grants

Delegate access, send-as rights, and third-party apps granted read or send access to mail through OAuth. Consent-phishing bypasses passwords and MFA entirely, and grants persist until someone revokes them. We list every grant with its scope and ask whether it should exist.

Encryption in transit

Whether your mail flows over TLS, whether MTA-STS or TLS reporting is published, and whether any partner connection silently falls back to plain text. Payment instructions and personal data crossing the internet unencrypted is a finding your compliance team needs to know about.

User-reported phishing workflow

What happens when a member of staff spots a suspicious mail. Is there a report button, does the report reach anyone, does anyone act on it, and how fast. A working report loop routinely catches campaigns hours before any filter update does, and most organisations have never tested theirs.

Lookalike-domain exposure

Domains that resemble yours: swapped letters, added hyphens, different endings. DMARC cannot stop these because the attacker authenticates their own domain perfectly. We check what is already registered near your name and what monitoring, if any, would tell you when the next one appears.

Why this audit, why now

Business email compromise is the attack that actually costs Indian businesses money.

Ransomware makes the headlines. Email fraud quietly drains accounts. The pattern is consistent across the cases we see: an attacker studies invoice conversations, then a payment instruction changes at exactly the right moment.

  • The wire-fraud pattern: a supplier or customer mailbox is compromised, the attacker reads months of genuine correspondence, and then a mail arrives on the real thread saying bank details have changed. The transfer goes to the attacker. Indian exporters, importers and firms making regular overseas payments see this constantly, and the losses per incident are frequently substantial, sometimes six-figure and occasionally far worse.
  • The invoice-fraud variant: the attacker registers a lookalike of your domain or your supplier's, and sends an invoice that looks exactly right. Accounts teams processing dozens of invoices a week are not going to spot one swapped letter in a domain name. Process controls and technical controls both matter here, and the audit tells you which technical ones you are missing.
  • CERT-In's 2022 directions require covered organisations to report specified cyber incidents, including unauthorised access to systems and data breaches, within six hours of noticing them. If you discover a compromised mailbox, that clock is already running. Knowing your email estate is clean before an incident is far cheaper than reconstructing what happened during one.
  • Mailboxes are full of personal data: customer details, employee records, KYC documents sitting in attachments. Under the DPDP Act, a breach of personal data carries notification obligations to the Data Protection Board and to affected individuals, and weak security safeguards are themselves a compliance failure. A leaked mailbox is not just an IT problem, it is a regulatory event.
Book the audit before the incident
Why GR IT for this audit

Four reasons this audit finds what a config review misses.

Reading policies tells you what was intended. The audit measures the gap between that and what your mail actually experiences, and that gap lives in exceptions, forwarding rules and OAuth grants.

Both platforms, one method

We run the same checklist across Microsoft 365 and Google Workspace, so organisations running both, or migrating between them, get one consistent picture instead of two vendor-shaped ones. Multi-domain groups are covered on a single engagement.

We read what nobody reviews

Allow lists, bypass transport rules, inbox rules, delegations, OAuth consents. These accumulate for years, never expire, and are where both misconfiguration and active compromise hide. Enumerating them is the highest-yield part of any email audit.

Honest about what DMARC fixes

DMARC at p=reject closes exact-domain spoofing completely, and does nothing about lookalike domains or a compromised supplier mailbox. We say so, and we cover the layers that address those too, rather than selling one record as the answer to fraud.

Remote-first across India

The entire audit runs remotely from our Gachibowli, Hyderabad HQ: DNS is public, and tenant evidence needs only read access. Chennai, Mumbai, Bengaluru, Delhi NCR or anywhere else, the engagement is identical and no travel is billed or needed.

The DMARC journey

From no record to p=reject, staged so legitimate mail never breaks.

The reason so many domains sit at p=none for years is that the next step carries a real risk of blocking your own invoices and newsletters. Staged correctly, with reporting watched at every step, that risk is engineered out. This is the roadmap the audit hands you.
  1. 01
    Stage 0· Where many Indian domains start

    No DMARC record

    Anyone on the internet can send mail with your exact domain in the From address, and receiving servers have no instruction to stop it. Your first move costs nothing: publish a record at p=none with a reporting address, which changes nothing about mail flow but starts the data collection everything else depends on.

    • DMARC record published at p=none with rua reporting
    • Aggregate reports collected somewhere legible
    • SPF and DKIM baseline captured for every domain
  2. 02
    Stage 1· Typically 2-4 weeks of observation

    p=none, monitoring

    Reports now show every source sending as your domain: your mail platform, your marketing tool, your invoicing system, and anything you forgot. This is the discovery stage, and it is the one that cannot be safely skipped. Every legitimate sender gets SPF and DKIM configured and aligned before anything is blocked.

    • Full inventory of every service sending as your domain
    • SPF within the ten-lookup limit, DKIM signed per sender
    • Alignment verified so DMARC actually passes for legitimate mail
  3. 03
    Stage 2· Stepped up in controlled increments

    p=quarantine, partial then full

    Failing mail now goes to spam rather than the inbox. We start at a partial percentage so any mistake affects a fraction of mail, watch the reports, then increase coverage. Each step is reversible in the time a DNS record takes to update, which is why this stage is safe when it is done patiently.

    • Quarantine applied at a partial percentage, then increased
    • Reports reviewed at each step for legitimate failures
    • Rollback path documented and tested
  4. 04
    Stage 3· The destination, then ongoing

    p=reject, enforcement

    Receiving servers now refuse mail that fails authentication for your domain. Exact-domain spoofing is closed permanently. Monitoring continues, because domains drift: a new marketing platform or a department signing up for a tool can silently add an unauthenticated sender, and the reports catch it before your own mail starts failing.

    • p=reject published across primary and parked domains
    • Subdomain policy set, unused domains locked down
    • Ongoing report review handed over or retained by us
Who needs this most

Six situations where this audit is the right next move.

Every organisation with a domain should be authenticated. These are the situations where the cost of not knowing is concrete and near-term.

Finance teams that wire money on emailed instructions

If a bank-detail change arriving by email could trigger a transfer, you are the exact target BEC is built for. The audit hardens the technical layer and flags where a verification-by-phone process must back it up, because no filter catches a mail from a genuinely compromised counterparty.

Exporters and importers on overseas invoice flows

Cross-border trade means invoices from counterparties you have never met, in time zones where a quick verification call is hard. That friction is precisely what invoice fraud exploits. Authentication, impersonation protection and lookalike monitoring narrow the attacker's room to work.

Companies that have already been spoofed

If customers or partners have received mail pretending to be you, the fix is enforcement: DMARC at p=reject makes exact-domain forgery bounce. The audit inventories every legitimate sender first so enforcement blocks the attacker and not your own invoices.

Companies whose mail lands in spam

Deliverability trouble usually traces to authentication, not content: a broken SPF record over its lookup limit, an unsigned sending service, or missing alignment. Google and other major receivers now require authentication from bulk senders, so this is a revenue problem, not a cosmetic one.

Organisations preparing for DPDP readiness

Mailboxes hold personal data, and the DPDP Act expects reasonable security safeguards around it. An email audit produces written evidence of controls over the system where most personal data actually moves, and findings your data-protection programme can action directly.

Organisations running both Microsoft 365 and Workspace

Mergers, subsidiaries and gradual migrations leave many Indian organisations running two mail platforms with two half-configured control sets. One audit across both surfaces the inconsistencies, including the domain that is enforced on one platform and wide open on the other.

Deliverables

Three documents you can act on, not a PDF that lives in a drawer.

Every finding is written so a competent administrator can implement it, and prioritised so the highest fraud-exposure items come first. If you want us to implement instead, the same documents become the work order.

Domain authentication scorecard

Every domain and subdomain you own, scored on SPF, DKIM, DMARC presence, alignment and enforcement level.

  • Per-domain pass and fail against each authentication check
  • SPF lookup count against the ten-lookup limit
  • Sending-source inventory with alignment status per service
  • Parked and unused domains flagged for lockdown

DMARC enforcement roadmap

The staged plan from wherever you are today to p=reject, with the observation windows and rollback points written in.

  • Stage-by-stage plan with entry and exit criteria
  • Per-sender remediation list before each stage
  • Reporting setup so progress is visible, not guessed
  • Realistic timeline, typically 6-10 weeks to full enforcement

Findings report with prioritised fixes

Everything the tenant and mailbox review found, ordered by what reduces fraud exposure fastest.

  • Executive summary your leadership can read in five minutes
  • Technical findings with severity and exact remediation steps
  • Forwarding rules, delegations and OAuth grants enumerated
  • CERT-In and DPDP-relevant observations flagged for compliance
Exposed vs hardened

What an exposed email posture looks like next to a hardened one.

Most organisations sit somewhere in the left column without knowing it, because nothing visibly breaks. The audit tells you exactly which rows apply to you.
Feature
Exposed posture
Configured once, never reviewed
Hardened posture
Audited and enforced
Exact-domain spoofing
Can someone send mail as your exact domain?
Possible, DMARC absent or at p=noneBlocked at p=reject
Sending-service inventory
Unknown, grown over yearsDocumented and aligned
SPF record health
Often over the lookup limit, silently failingWithin limits, monitored
Impersonation protection
Unlicensed, or licensed with empty listsPopulated with current leadership and finance
External auto-forwarding
Permitted, unreviewedBlocked by default, exceptions documented
Inbox rules and delegations
Never enumeratedReviewed, compromise artefacts removed
OAuth grants with mail access
Accumulating unseenEnumerated, unneeded grants revoked
Encryption in transit
Opportunistic, unverifiedTLS verified, MTA-STS considered
User phishing reports
No route, or reports go nowhereReport button wired to a person who acts
Six-hour incident clock readiness
Would start the investigation from zeroBaseline documented before any incident
How the audit runs

Five steps, 3-5 days, entirely remote.

DNS evidence is public. Tenant evidence needs read-only access, which you grant at the start and revoke at the end. No agents installed, no mail flow touched, no downtime.
  1. 1

    Scoping and access

    Day 1

    A short call to list your domains, platforms and known sending services. You grant read-only access to Microsoft 365, Google Workspace or both, plus a view of DNS. We confirm scope in writing before anything is examined.

  2. 2

    DNS and authentication review

    Day 1-2

    SPF, DKIM and DMARC for every domain and subdomain, lookup counts, alignment per sending service, MX records, TLS posture, and the lookalike-domain check. The domain authentication scorecard takes shape here.

  3. 3

    Tenant configuration review

    Day 2-3

    Anti-phishing and anti-spoofing policies, impersonation lists, transport and routing rules, allow and block lists, quarantine behaviour, and the settings that govern forwarding and encryption. Checked against what your licensing already includes.

  4. 4

    Mailbox, OAuth and workflow review

    Day 3-4

    External forwarding rules, hidden inbox rules, delegate and send-as permissions, OAuth applications with mail scopes, and how a user-reported phish actually travels through your organisation. This is where evidence of past compromise turns up when it exists.

  5. 5

    Report and readout

    Day 4-5

    The scorecard, the DMARC roadmap and the findings report, delivered with a live readout for your IT and finance stakeholders. Fixes are ordered by fraud-exposure reduction. If you want us to implement, the roadmap becomes the work order and access stays read-only until you approve changes.

Straight answers

Email security audit, the questions that decide it.

Not if the staging is respected, and this is the exact risk the roadmap is designed around. Mail breaks when a legitimate sender, your marketing platform, invoicing tool or CRM, was never authenticated and enforcement suddenly blocks it. Our sequence publishes monitoring first, watches aggregate reports for weeks to find every legitimate sender, authenticates and aligns each one, and only then steps through quarantine at a partial percentage before reject. Every step is reversible within a DNS update. Domains that go straight to reject without discovery are the ones that block their own newsletters on a weekend.

The audit itself is 3-5 days. The journey to p=reject typically takes 6-10 weeks end to end, and most of that is deliberate observation rather than work. Aggregate reports need a few weeks to reveal every sender, each sending service takes as long as its vendor takes to configure DKIM, and the enforcement steps are spaced so problems surface while they are still small. Anyone promising p=reject in a week is skipping the discovery, and the discovery is the part that protects your legitimate mail.

Read access, not admin. DNS records are public. For the tenant review we ask for a read-only role, Global Reader or an equivalent reporting role in Microsoft 365, and an equivalent read-level administrator role in Google Workspace, granted at the start and revoked when the audit ends. We do not change settings, send mail or install anything during the audit. If you engage us to implement fixes afterwards, changes happen through an approved change list with your admin or with elevated access you grant deliberately for that work.

Yes, and organisations running both get the most value from a single engagement. The authentication layer, SPF, DKIM, DMARC, MX and TLS, is identical DNS work regardless of platform. The tenant layer differs, so we map the same audit questions onto each platform's controls: Defender anti-phishing policies and transport rules on the Microsoft side, spoofing protections, compliance rules and routing settings on the Workspace side. The report presents one combined picture, which is where the inconsistencies between two platforms become visible.

They are inside the scope, not outside it, because they are the senders that break when DMARC is enforced carelessly. Marketing platforms, invoicing systems, HR portals, support desks, e-signature services, booking engines, anything that puts your domain in the From line needs SPF or DKIM configured and aligned. Discovery through DMARC reports plus a round of questions to finance, HR and marketing reliably finds senders IT did not know about, and each one goes on the remediation list with the exact records its vendor needs published.

The audit is a fixed 3-5 day engagement with fixed deliverables, and you can stop there. Two things argue for some continuity: the DMARC journey itself runs 6-10 weeks and benefits from someone watching the reports at each enforcement step, and domains drift afterwards as new tools get adopted. Options after the audit: we run the enforcement project to p=reject, we hand you the roadmap and reporting setup to run yourself, or ongoing report monitoring rolls into a managed services arrangement with our standard 30 minutes response SLA. Your choice, stated plainly in the proposal.

Three documents. The domain authentication scorecard: every domain scored on SPF, DKIM, DMARC, alignment and enforcement, with the full sending-source inventory. The DMARC enforcement roadmap: the staged plan to p=reject with entry criteria, observation windows and rollback points. The findings report: an executive summary readable in five minutes, then every technical finding with severity, evidence and step-by-step remediation, covering tenant policies, forwarding rules, delegations, OAuth grants, encryption and your phishing-report workflow, with CERT-In and DPDP-relevant items flagged for your compliance team.

Yes, and most clients ask us to. The findings split into three kinds of work: DNS changes, which are quick and low-risk; tenant configuration changes, which we implement through an approved change list so nothing surprises your users; and the staged DMARC enforcement, which is a managed mini-project over several weeks. Because most findings are configuration rather than new licences, remediation is usually measured in days of effort. The report is written so your own team could implement everything without us, which keeps the decision honestly yours.

Tell us that at scoping, because it changes the order of work. If there are active signs, unexplained transfers requested, rules you did not create, customers reporting strange mail from you, the mailbox review moves first: forwarding rules, inbox rules, OAuth grants, delegations and sign-in patterns, which is where BEC leaves its footprints. Remember the regulatory context: CERT-In's directions put specified incidents on a six-hour reporting clock once noticed, and a mailbox holding personal data may also engage DPDP breach notification. We help you establish facts fast so those decisions are made on evidence.

Only one kind of them. Your DMARC at p=reject stops mail forging your exact domain, which protects your customers and partners from mail pretending to be you. It does nothing about a lookalike domain, one letter different, because the attacker authenticates their own domain perfectly, and nothing about mail from a genuinely compromised supplier mailbox, which passes every check because it is real. Those two are the more common source of loss in India, which is why the audit also covers lookalike exposure, impersonation protection and your verification workflow, and why we will never sell DMARC alone as fraud prevention.

Neither names an email security audit as a requirement, and we will not pretend otherwise. The connection is practical. CERT-In's directions require covered entities to report specified incidents within six hours of noticing them; email compromise is among the most common incidents Indian organisations actually face, and an audited baseline makes detection and reporting dramatically faster. The DPDP Act expects reasonable security safeguards for personal data and provides for breach notification; mailboxes are where personal data concentrates. The audit produces written evidence of safeguards over that system, which is exactly what a compliance programme or an insurer questionnaire wants to see.

Invisible to them. The audit is read-only: DNS lookups are public, tenant evidence is gathered through reporting interfaces, and nothing about mail flow changes during the engagement. No agents, no plugins, no downtime, no test mails to your staff unless you explicitly ask for a phishing-report workflow test, which we then coordinate with your IT lead. Changes only happen in the implementation phase, if you commission it, and each change is scheduled and reversible.

No. The engagement is designed to be fully remote and is delivered that way for clients across India from our Gachibowli, Hyderabad HQ. Everything the audit needs, DNS records, read access to the tenant, and an hour of conversation with IT and finance, works identically over a screen from anywhere. Scoping calls and the final readout run on video at times that suit your team, and the initial reply to any enquiry comes within 4 business hours.

We scope per organisation and quote a fixed fee before any work starts, no hourly surprises. The drivers are simple: how many domains you own, whether you run one mail platform or both, and how many mailboxes are in scope for the configuration review. What we will do in the first conversation, free, is look up your public DMARC, SPF and DKIM posture and tell you what it says, because it is public information and it usually tells you whether this needs to be an audit or an afternoon.
Check yourself first

Fifteen questions you should be able to answer about your email.

These are the questions the audit works through. The first group is public DNS you can look up today. The second needs tenant access. The third is where compromise hides, and almost nobody can answer it without looking.

Authentication (public, check today)

  • Does your domain have a DMARC record at all?
    Look up _dmarc followed by your domain.
  • If yes, is the policy none, quarantine or reject?
    p=none blocks nothing.
  • Is your SPF record within its ten-lookup limit?
    It breaks silently when exceeded.
  • Is DKIM enabled for every sending service?
    Usually on for the platform, off for everything else.
  • Are unused and parked domains locked down?
    Attackers prefer the domains nobody watches.

Tenant configuration

  • Is impersonation protection populated and current?
    Leadership and finance names change.
  • Are transport rules bypassing your filters?
    The most powerful and least visible exception.
  • Is external auto-forwarding blocked by default?
    Per policy and per mailbox, both matter.
  • Is mail to partners forced over TLS?
    Payment instructions should never travel plain.
  • Do users have a working way to report phishing?
    And does anyone read what they report.

Where compromise hides

  • When were inbox rules last reviewed?
    Hidden rules are the classic BEC artefact.
  • Can you list every OAuth app with mail access?
    Consent phishing bypasses MFA entirely.
  • Who holds delegate or send-as rights, and why?
    Grants outlive the reason they were made.
  • Are lookalikes of your domain registered?
    DMARC cannot stop them; monitoring can spot them.
  • Would you meet a six-hour reporting clock?
    CERT-In directions do not wait for your investigation.
Next step

Look up your DMARC record today. If it says p=none, or nothing, start here.

Three-minute form, initial reply within 4 business hours. Tell us your domains and your platform, and we will tell you in the first conversation what your public records already reveal, before you commit to anything.