Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Every company has one inbox that gets a convincing invoice this week. What stops it is a handful of settings you can change this afternoon. Here are the email security best practices that close the usual doors, in the order attackers walk through them, with a checklist at the end.

Why Email Is Still the Front Door

Email is where money and trust meet. A fake invoice, a changed bank account, a "quick favour" from the CEO: none of it needs malware, just a mailbox someone believes.

The FBI's 2025 Internet Crime Report counted 24,768 business email compromise complaints and just over $3 billion in reported losses. That's one crime type, in one country, from the victims who reported it.

The pattern behind those numbers is boring and repeatable. Steal a password, sign in, hide in the mailbox, wait for a payment conversation, then step into it. Each step has a setting that blocks it, and that's what this checklist is built around.

Lock the Accounts Before Anything Else

Filtering and training matter, but they come after identity. If an attacker can sign in, every other control is working against a real user.

Start with multifactor authentication on every mailbox, including shared and service accounts people forget about. Prefer phishing-resistant methods such as passkeys or FIDO keys for admins and finance. A plain push notification can be approved by a tired user at 11 p.m.

Then block legacy authentication. Older protocols like IMAP and POP can't do MFA, so a stolen password walks straight past it. Microsoft's own guidance on blocking legacy authentication says more than 99% of password spray attacks use those protocols. Conditional Access can block them, and tenants without it can turn on security defaults.

Passwords still matter here too. Attackers try the same short list everywhere, which is why a banned-password list pays off. Our breakdown of the most common passwords covers how.

Last, stop users from granting mailbox access to random apps. Some attacks skip the password entirely and trick a user into consenting to an app that reads mail. Require admin approval for new enterprise apps, and review what's already consented.

This r/sysadmin thread shows the pattern in the wild: a breached user, reset password and MFA, and then a mail-reading app registered two weeks earlier, still quietly holding access.

Prove Your Mail Is Yours

SPF, DKIM and DMARC let receiving servers check that mail claiming to be from your domain came from you. SPF lists your allowed senders, DKIM signs the message, and DMARC tells the world what to do when both fail. We walk through records and rollout in our DMARC guide, so here's the short version: publish all three, read the reports, and move DMARC toward reject.

It isn't optional for anyone who sends in volume. Google's sender guidelines have required SPF, DKIM and DMARC since February 2024 for anyone sending more than 5,000 messages a day to Gmail accounts, plus one-click unsubscribe for marketing mail.

One Microsoft 365 setting deserves a look while you're here. Direct Send lets devices like printers send to internal recipients without signing in, and attackers have abused it to spoof internal senders. If nothing in your office needs it, Set-OrganizationConfig -RejectDirectSend $true turns it off.

Shut the Forwarding Door

Forwarding is the quietest way to lose data. An attacker who gets in once creates an inbox rule that sends a copy of every message to an outside address, then leaves. The password reset that follows doesn't delete the rule.

In Microsoft 365, the switch lives in the outbound spam filter policy. Microsoft's page on external email forwarding lists three options: Automatic (system-controlled), On and Off. Microsoft itself recommends picking On or Off explicitly, because "system-controlled" behaves differently in different tenants. Set it to Off. Blocked forwards bounce with a 5.7.520 error, which makes the rare legitimate need easy to spot and allow.

Then check who was already forwarding. The Auto forwarded messages report in the Exchange admin center lists them. Google Workspace has a matching admin switch for automatic forwarding, and the same audit applies.

Keep watching after that. An alert on new inbox rules that forward, delete or move mail to obscure folders catches the next attempt while it's fresh.

Tag Outside Mail and Make Reporting One Click

A lot of BEC mail comes from outside, dressed up as inside. A visible "External" tag gives users a moment to notice. In Exchange Online, Set-ExternalInOutlook -Enabled $true adds a native External label in Outlook, and Microsoft notes it can take 24 to 48 hours to appear. If you already prepend "[EXTERNAL]" to subjects with a mail flow rule, turn that off first to avoid doubling up.

Reporting has to be easier than ignoring. Outlook's built-in Report button now does this across clients, and Microsoft has put its older Report Message and Report Phishing add-ins into maintenance mode ahead of deprecation. Send reports to a mailbox someone reads, and reply to the people who report. A thank-you is the cheapest security control there is.

When a Mailbox Gets Compromised Anyway

Controls reduce the odds. They don't make them zero, so write the first hour down before you need it.

This r/msp thread walks through a real case: a client clicked a "shared document" from a compromised friend, and the MSP had to work out what the attacker touched. The replies are a solid checklist on their own.

The order matters. Revoke sessions and reset the password together, or the attacker keeps a live token. Check MFA methods for anything added recently, then inbox rules and forwarding, then app consents. Pull the audit log for mail read, sent and deleted. Finally, warn the people the account emailed during the window, because they're next.

None of that works if audit logging was off. Confirm unified audit logging is enabled on every tenant now, while nothing is on fire.

Training That Changes Behaviour

Phishing simulations help when they teach one habit at a time. The habit that saves the most money is simple: any change to payment details gets confirmed by phone, using a number you already had, never one in the email.

Keep the rest short and frequent. Show real examples from your own filters, not stock images. Praise reporting, including false alarms. Our guide to security awareness training covers a rollout that people don't dread.

The Email Security Checklist

Use this as a quarterly review. Most items are a setting, not a purchase.

ControlWhereDone
MFA on every mailbox, phishing-resistant for admins and financeEntra ID / Google Admin☐
Legacy authentication blockedConditional Access or security defaults☐
Admin approval required for new app consentsEntra ID enterprise apps☐
SPF, DKIM and DMARC published, DMARC moving to rejectDNS☐
Direct Send rejected if nothing needs itExchange Online PowerShell☐
External auto-forwarding set to OffOutbound spam policy☐
Existing forwards reviewedAuto forwarded messages report☐
Alerts on new forwarding or delete rulesDefender / SIEM☐
External sender tag onSet-ExternalInOutlook☐
Report button live, reports go to a watched mailboxDefender user reported settings☐
Unified audit logging onMicrosoft Purview☐
Payment-change callback rule written and trainedFinance process☐

Jonathan Edwards walks through the Microsoft 365 policies behind most of these rows in about 20 minutes, which is handy if you're setting them up for the first time.

Start With the Forwarding Switch

Email security comes down to a short list of switches and one habit. Lock the accounts, prove your mail, shut forwarding, tag outside mail, and make reporting easy.

If you only do one thing today, set external forwarding to Off and review who was forwarding before. When you're ready to add a dedicated filtering layer, our roundup of email security solutions compares the options.

Vladislav Marchenko

Head Of Marketing

Hi all! My name is Vlad and I’ve been brought on to head the marketing team at Flamingo. Thankfully, this isn’t the first time I will be building a marketing department from scratch, so the experience should come in handy. Now it’s time to dive into the world of MSPs and find myself in this new world.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

About OpenFrame

In the cloud, on US soil. Your data stays stateside.
OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
Turn on MFA for every mailbox, block legacy authentication, publish SPF, DKIM and DMARC, set external auto-forwarding to Off, tag outside mail, and give users a one-click Report button. Add a callback rule for any change to payment details.
Open the outbound spam filter policy in Microsoft Defender and set automatic forwarding to Off instead of Automatic. Blocked forwards bounce with a 5.7.520 error. Then check the Auto forwarded messages report in the Exchange admin center for anyone already forwarding outside.
No. DMARC stops attackers from sending as your exact domain, but it does nothing about lookalike domains or mail sent from a real account that was compromised. Pair it with MFA, forwarding controls, external sender tags and a callback rule for payments.
Revoke sessions and reset the password together, then remove any MFA methods added recently. Delete suspicious inbox rules and forwarding, remove unapproved app consents, pull the audit log for mail read, sent and deleted, and warn the people the account emailed.