Seven controls cover the majority of email risk for a small business — require multi-factor authentication on every account, filter aggressively and quarantine rather than deliver, use a password manager instead of complexity rules, move DMARC to enforcement, train people continuously rather than annually, keep an independent backup, and test with simulated phishing. Start with MFA and DMARC; between them they close the two largest gaps, and neither requires a budget.
This checklist is written for owners and managers without a dedicated IT team. Each step includes what to do, why it works, and where the common mistakes are.
Why Small Businesses Are Targeted
The assumption that you are too small to be worth attacking is backwards. Smaller organizations are attractive precisely because they hold real money and real data with fewer controls protecting them, and most attacks are opportunistic rather than targeted.
The scale is documented. The FBI's Internet Crime Complaint Center 2025 Annual Report recorded just over $3 billion in business email compromise losses across roughly 24,700 complaints — second only to investment fraud among reported categories. The overwhelming majority moved by wire or ACH, which is why recovery is so often impossible.
The 2025 report also added a dedicated section on artificial intelligence for the first time, logging more than 22,000 AI-related complaints and close to $893 million in associated losses. This matters for your training: the advice to watch for clumsy grammar and awkward phrasing no longer works. Generated phishing is fluent, contextual, and often researched.
Industry breach reporting also consistently finds the human element — phishing, credential misuse, and simple error — involved in the large majority of incidents. That is not a reason to blame employees. It is a reason to build controls that work even when someone makes a mistake.
Before You Start
Get administrative access to your email platform. Without it you cannot change policy.
List your users and their roles, identifying who handles money and sensitive data. Finance, HR, and anyone who can change payment details need the strongest protection.
Audit your current DNS. Check whether SPF, DKIM, and DMARC records exist and what your DMARC policy is set to. A free lookup tool will tell you in seconds. Many businesses have SPF and DKIM but no DMARC, or a DMARC record sitting at p=none that monitors without protecting.
Inventory forwarding rules. Attackers routinely create hidden auto-forwarding rules to exfiltrate mail quietly. Existing unexplained rules are worth investigating now, before you assume you are starting clean.
Set aside real time. MFA takes minutes. DMARC to enforcement takes weeks, because you need an observation period. Plan a phased rollout.
Step 1: Require MFA on Every Account
Multi-factor authentication is the single highest-leverage control available to you. Microsoft has reported that MFA blocks over 99.9% of automated account compromise attacks — the caveat being automated. Targeted attacks using real-time phishing proxies can defeat weaker factors, which is why the method matters.
Method | Phishing resistance | Use for |
|---|---|---|
Hardware security keys (FIDO2) | Strong — resists real-time proxying | Finance, executives, admins |
Authenticator apps (TOTP) | Moderate | General staff |
SMS codes | Weak — vulnerable to SIM swap | Avoid where possible |
Cover everyone, not just leadership. Attackers target accounts payable, HR, and helpdesk staff because they have useful access and less scrutiny.
Make it mandatory. Optional MFA is the most common failure — people skip it for convenience and the coverage gap is invisible until it matters.
Where MFA lives varies. It may be managed by your email platform, your identity provider, or your single sign-on layer. Confirm which system owns it in your environment rather than assuming it is covered.
💡 Pro Tip: Give a two-week grace period for enrolment, then enforce strictly. Announce the deadline twice. This cuts support load dramatically compared with a hard cutover.
Step 2: Filter Aggressively and Quarantine
Basic spam filtering does not stop targeted phishing, because the dangerous messages often contain no malicious payload at all — just a plausible request from a plausible sender.
Quarantine rather than deliver. Suspicious mail should be held for review, not dropped into inboxes with a warning banner people learn to ignore.
Review quarantine reports weekly. The patterns tell you what is being aimed at your business specifically.
Watch outbound too. A compromised account sending unusual volume is often the first detectable sign of takeover. Most businesses monitor only inbound.
Filtering capability varies substantially between providers, so confirm what yours offers rather than assuming enterprise-grade threat protection is included. If advanced filtering matters to your risk profile, make it an explicit evaluation criterion when choosing a platform.
Step 3: Use a Password Manager, Not Complexity Rules
Current NIST guidance (SP 800-63B) has moved away from what most businesses still do. The evidence-based position:
Length beats complexity. Long passphrases outperform short strings of mixed symbols.
Do not force periodic rotation. NIST specifically recommends against mandatory expiry. Forced 90-day changes produce predictable variations —
Spring2026!becomingSummer2026!— which is worse than a strong password kept until there is evidence of compromise.Do screen against known-breached passwords, and block obvious choices like your company name.
Rotate immediately on evidence of compromise, not on a calendar.
Provide a password manager. This is the control that actually changes behaviour. Unique credentials per site become effortless, which removes the reuse that makes credential-stuffing work. Established options run a few dollars per user monthly. Set up a shared vault for team credentials and separate personal vaults.
Step 4: Move DMARC to Enforcement
DMARC tells receiving servers what to do with mail that fails SPF and DKIM checks. Publishing a record is not the same as being protected, and this is where most organizations stall.
Valimail's 2026 State of DMARC Report found that 78% of domains now publish a DMARC record, but only 42% have reached enforcement — a 36-point gap the report calls the "Enforcement Gap." Enforcement rose only from 35% to 42% across 2025, which suggests a large number of organizations published p=none to satisfy mailbox provider mandates and stopped there.
The staged path:
p=nonefor two to four weeks. Collect reports and identify every legitimate service sending as your domain — CRM, invoicing, helpdesk, marketing platform. There will be more than you expect.p=quarantinefor another two to four weeks. Failures go to spam rather than being rejected, so a missed sender is recoverable.p=reject. Unauthenticated mail claiming your domain is refused.
Watch the SPF lookup limit. SPF permits a maximum of 10 DNS lookups. Every sending service consumes some, and exceeding the limit causes permanent failure rather than graceful degradation.
One important limit: DMARC protects your exact domain. It does nothing about lookalike domains — yourc0mpany.com — which the attacker owns and can authenticate perfectly. Those need defensive registration and trained staff.
NevTan Mail includes guided SPF, DKIM, and DMARC setup that generates and verifies each record, which removes the hand-editing where misconfiguration originates. For the mechanics, see why business emails land in spam and how domain authentication fixes it.
Step 5: Train Continuously, Not Annually
Annual training does not work. Tactics change and awareness decays within weeks.
Run short, frequent modules rather than one long session. Cover what your people will actually encounter: vendor bank-detail changes, invoice fraud, executive impersonation, payroll redirects.
Train for AI-generated phishing. The old heuristics are obsolete. Replace "spot the bad grammar" with procedure — verify, do not assess.
Build a reporting path. A dedicated address where people forward anything suspicious, with a commitment that reports are welcomed rather than treated as bother. Reporting rate is a better health metric than click rate.
Never punish failures. People who fear consequences hide mistakes, and a concealed click is far more expensive than an admitted one.
Step 6: Add Out-of-Band Verification for Money
This step was missing from most checklists and it is the one that stops the expensive attacks.
The rule: any request to send a wire, change payment details, update vendor banking, or buy gift cards must be verified through a different channel than the one it arrived on. A phone call to a number you already had — never a number in the email signature.
Why it catches what technology cannot: when an attacker compromises a real vendor's real mailbox and sends a real invoice with altered bank details, that message passes SPF, DKIM, and DMARC because it genuinely came from that domain. No authentication protocol will flag it. Only a call to a known number will.
No exceptions for executives. BEC runs on manufactured urgency and authority. A policy that exempts leadership has a hole exactly where attacks aim.
Our guide to protecting your company from business email compromise covers this in depth, including what to do in the first 72 hours if money has already moved.
Step 7: Keep an Independent Backup
Your email provider replicates data for availability, which protects against their hardware failing. It does not protect against deletion, because deletions replicate too. Recovering from a purged mailbox or a compromised account requires an independent copy.
Follow the 3-2-1 principle: three copies, two platforms, one off-site. Include shared mailboxes like support@ and billing@ in scope, since they are the most commonly omitted and often hold the most commercially significant threads.
Test restores quarterly. An untested backup is a hypothesis. Restore a single old message, verify metadata and attachments, then time a full mailbox restore.
Most email platforms are not backup services — that is a normal division of responsibility, not a shortcoming. Confirm what export or IMAP access your provider offers so a backup tool can connect. See our guide to business email backup for the full approach.
Bonus: Simulated Phishing
If budget allows, simulation is the best measurement tool available. Baseline first, then run monthly simulations mimicking real BEC patterns rather than generic phishing.
Track trends rather than individuals. If one department fails consistently, that is a training signal, not a discipline matter. Vary the scenarios — credential harvesting, attachments, vendor impersonation, executive fraud.
Dedicated platforms exist for this and are generally separate purchases from your email provider.
Common Mistakes
Optional MFA. The most common gap, and the most consequential.
Ignoring outbound mail. Compromised accounts announce themselves through unusual sending patterns, if anyone is watching.
Believing DMARC covers lookalike domains. It does not. This misconception is widespread enough to be dangerous.
Forcing password rotation. Contrary to current NIST guidance and counterproductive in practice.
Unmanaged mobile access. If people read work mail on personal phones, you need a policy covering lock screens, encryption, and remote wipe.
Never revisiting the setup. New hires, new tools, and new sending services all change your exposure. Review quarterly.
Frequently Asked Questions
How often should I review email security settings?
Quarterly for DMARC reports, user access lists, and admin rights. Annually for a fuller audit. Also review whenever you add a service that sends as your domain, since that affects SPF.
What does this cost?
MFA, DMARC, quarantine policies, and verification procedures are free — they are configuration and policy, not products. Password managers and training platforms typically run a few dollars per user monthly. DMARC monitoring services are optional and help mainly at larger scale.
Can I do this without an IT department?
Yes, for most of it. MFA, password management, verification procedure, and training are administrative decisions. DMARC is the most technical step, which is why guided setup from your provider is worth having.
What if I think an account is already compromised?
Reset the password and revoke all active sessions immediately. Check for forwarding rules the attacker may have created — this is the most commonly missed step and how attackers maintain access after a password reset. Then review sent items to see what went out, and notify anyone affected.
Is free consumer email secure enough for business?
No, and not primarily for encryption reasons. Free consumer email gives you no administrative layer to enforce policy, no way to revoke a departing employee's access, and no control over authentication for a domain you do not own. See business email on your own domain.
What is the difference between SPF, DKIM, and DMARC?
SPF declares which servers may send for your domain. DKIM adds a cryptographic signature proving a message was not altered. DMARC tells receiving servers what to do when either fails, and reports back to you. All three are now effectively required by major mailbox providers.
How do I choose a provider with security in mind?
Look for custom domain support, guided authentication setup, role-based admin controls, TLS encryption, and a business model that is not advertising. Then confirm separately where MFA is enforced and what export options exist, since those vary and are often assumed rather than verified.
Which step should I do first?
MFA, today. Then start DMARC at p=none so the observation window is already running while you work through the rest.
Where Your Email Platform Fits
Worth being clear about the division of labour, because bundling everything into one purchase is rarely how this works in practice.
Your email platform provides the foundation: business email on your own domain, authentication setup, encrypted connections, and admin controls for managing and revoking access. NevTan Mail covers this — guided SPF, DKIM, and DMARC verification, TLS-encrypted connections, role-based Admin and Super Admin controls, unlimited aliases and groups, and no ads or data selling on any plan, with 10 mailboxes free forever.
Separate layers handle the rest: backup and restore, phishing simulation, security awareness training, and password management are typically distinct products. Any vendor claiming to bundle all of it deserves specific questions about each capability.
And some of it is not a product at all. Out-of-band verification, least-privilege admin rights, and a culture where people report suspicious mail without fear cost nothing and prevent more loss than most software.
See what's included, compare pricing, or get started free.
Conclusion
Work the list in order of leverage. MFA today. DMARC monitoring started this week so the observation window runs while you handle everything else. A verification rule for payments, written down and applied to everyone including the founder. Then training, backup, and simulation as capacity allows.
None of this requires enterprise budget. It requires someone owning it and following through — which is genuinely the harder part, and the reason most checklists stay unfinished.
