Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Email & fraud

Securing corporate email

Almost every attack starts with a message. Two answers coexist: training people — which we cover elsewhere — and making it technically hard to impersonate your domain. It is that second part, often neglected, which this case is about.

The challenge

Your domain is a signature — it still has to be protected

Without explicit configuration, anyone can send a message that appears to come from your domain. The three records that prevent it — SPF, DKIM, DMARC — have been around for a long time, but frequently remain incomplete, or published in monitoring mode, which amounts to observing the spoofing without blocking it.

The second blind spot is the outbound flow. An organisation whose domain is spoofed sees its reputation degrade, its legitimate messages land in junk folders, and its partners receive fraudulent payment requests in its name. The damage is as commercial as it is technical.

The third is the reaction. Once a malicious message has cleared the filter and reached mailboxes, the only question that counts is: how quickly do we know it is there, and can we pull it back everywhere? That takes a simple reporting channel and a removal capability, not just a high-performing filter.

What is at stake
  • Domain open to spoofing for want of DMARC at reject
  • Legitimate messages treated as junk, reputation degraded
  • Fraudulent transfer requests in the name of the management
  • Reporting made awkward, so incidents surface too late
  • No way to pull back a message already delivered
Diagram

Each stage removes what the previous one let through

A message's journey and its control points 1Inboundmessage2SPF · DKIMDMARC3Filtering& reputation4Attachment& link check5Inbox6Report& pull back
Authentication removes spoofing, filtering removes volume, analysis removes booby-trapped content. What remains depends on reporting — and on the ability to pull back a message already delivered.
Our approach

How we proceed

We start with domain authentication, which produces the sharpest gain for the least effort.

01

Domain stocktake

A survey of the existing records, of the services allowed to send on your behalf — marketing tools, line-of-business applications, providers — and of what is already spoofing the domain.

02

Authentication at reject

Bringing SPF and DKIM into line for every legitimate sender, then moving DMARC to reject step by step, watching the reports so that no legitimate flow is blocked.

03

Filtering and hardening

Tuning the gateway and the platform's protections: attachment and link analysis, a banner on external messages, targeted rules for payment fraud scenarios.

04

Reporting and removal

Putting a report button in the mail client, the handling process behind it, and the procedure for pulling back a message that has already been delivered.

05

Monitoring and exercise

Following the DMARC reports and the domain reputation, connecting the alerts to monitoring, and running a social engineering campaign to measure what still gets through.

Services involved

Several disciplines, a single point of contact

The technical and the human sides validate each other: a campaign measures what the filtering actually lets through.

Deliverables
  • Inventory of the domain's legitimate senders
  • SPF, DKIM and DMARC at reject, documented
  • Filtering configuration and anti-fraud rules
  • Reporting channel and removal procedure
  • Follow-up of DMARC reports and reputation
Frequently asked questions

Frequently asked questions

That is the real risk, which is why it is never done straight away. We start in monitoring mode, read the reports to list every service sending on your behalf, bring them into line, and only then move to reject — often in steps.

It handles volume well. It does not protect your domain against outbound spoofing — that comes from the DNS records — and says nothing about your ability to pull back a message already delivered. These are three separate matters.

Technically: anti-spoofing, a banner on external messages, rules on look-alike domains. But the decisive measure is procedural — any change of bank details is verified through a channel other than the one that requested it.

Awareness acts on the person receiving; this work acts on what reaches them and on what your domain allows an attacker to do. The two complement each other: we cover the human side in a dedicated use case.

Can someone write in your name?

A stocktake of the domain needs nothing installed, and gives the answer within hours.