Skip to content
Defensive · Service

Email Security & Anti-Phishing Infrastructure

BEC is 64% of cyber-insurance claims. Close the door.

Implementation of advanced email protection controls to mitigate phishing, malware, spoofing, and spam threats.

DMARC p=reject
End state for every engagement
12 sources
Avg. legitimate senders discovered
< 2%
Target false-positive quarantine
4 weeks
Typical DMARC ramp (none → reject)
Overview

Strengthens communication security and reduces the risk of credential compromise and business email fraud, through authentication (SPF, DKIM, DMARC), inbound gateway tuning, and user-reporting workflows that actually work.

What you receive
  • Authentication audit (SPF/DKIM/DMARC)
  • Gateway tuning & policy design
  • User-report workflow setup
  • Monthly posture review
  • Incident-replay runbook
Cadence
7-day engagement
Compliance mapping
NIST SP 800-177 (DMARC)PCI DSS 4.1HIPAA §164.312(e)ISO 27001 A.13.2.3SOC 2 CC6.7
Outcomes
  • Enforced DMARC protecting your domain from spoofing
  • Reduced BEC and phishing delivery to inbox
  • User-report workflow that triages in minutes
  • Auditor evidence for email-security controls
Methodology

How the engagement runs. Phase by phase.

PHASE 01

DMARC audit + RUA deployment

Inventory existing SPF/DKIM, deploy p=none, start aggregate collection.

1 week
PHASE 02

Sender catalog + SPF repair

Identify every legit sender, fix SPF records, align DKIM signing.

1 week
PHASE 03

Gateway policy tuning

Configure anti-spoof, attachment sandboxing, URL rewriting, external warnings.

3–5 days
PHASE 04

Report workflow + training

Deploy report button, wire SOC handoff, enable user feedback loop.

3 days
PHASE 05

Graduated DMARC enforcement

Quarantine at 10% → 50% → 100%, then reject. Monitor daily.

3–4 weeks
PHASE 06

Continuous posture

Monthly review, sender drift alerts, BEC rule tuning.

Ongoing
Tools & stack

What we actually use. No secrets.

Every tool earns its place. We publish our stack so your team can audit, review, and integrate with what we bring.

DM dmarcian / Valimail / EasyDMARC
dmarcian
MI Microsoft Defender for O365
Microsoft Defender for O365
GO Google Workspace Security
Google Workspace Security
PR Proofpoint / Mimecast / Abnormal
Proofpoint
MX MxToolbox + custom DNS diff
MxToolbox + custom DNS diff
UR URLhaus + VirusTotal API
URLhaus + VirusTotal API
RE Report-phish button (PhishAlarm / native)
Report-phish button
SO SOAR integrations (Cortex XSOAR / Tines)
SOAR integrations
DM dmarcian / Valimail / EasyDMARC
dmarcian
MI Microsoft Defender for O365
Microsoft Defender for O365
GO Google Workspace Security
Google Workspace Security
PR Proofpoint / Mimecast / Abnormal
Proofpoint
MX MxToolbox + custom DNS diff
MxToolbox + custom DNS diff
UR URLhaus + VirusTotal API
URLhaus + VirusTotal API
RE Report-phish button (PhishAlarm / native)
Report-phish button
SO SOAR integrations (Cortex XSOAR / Tines)
SOAR integrations
DMARC
  • DM dmarcian / Valimail / EasyDMARC
    dmarcian / Valimail / EasyDMARC
    Aggregate report (RUA) analysis and sender inventory
Gateway
  • MI Microsoft Defender for O365
    Microsoft Defender for O365
    Policy tuning: Safe Links, Safe Attachments, ATP
  • GO Google Workspace Security
    Google Workspace Security
    Attachment sandboxing, external warning, quarantine review
  • PR Proofpoint / Mimecast / Abnormal
    Proofpoint / Mimecast / Abnormal
    Advanced gateway policy design + BEC ML tuning
Diagnostics
  • MX MxToolbox + custom DNS diff
    MxToolbox + custom DNS diff
    Continuous SPF/DKIM/DMARC/MX health checks
Enrichment
  • UR URLhaus + VirusTotal API
    URLhaus + VirusTotal API
    Link and attachment IOC enrichment for triage
User
  • RE Report-phish button (PhishAlarm / native)
    Report-phish button (PhishAlarm / native)
    Single-click reporting with SOC handoff
Response
  • SO SOAR integrations (Cortex XSOAR / Tines)
    SOAR integrations (Cortex XSOAR / Tines)
    Auto-containment and takedown workflows
Techniques

How we do the work. Not just what.

T.01

Sender inventory via RUA

Deploy DMARC p=none first, collect 2 weeks of aggregate reports, catalog every legitimate sender, including the shadow-IT ones finance forgot to tell you about.

T.02

Graduated DMARC rollout

p=none → p=quarantine (pct=10 → 50 → 100) → p=reject. Never jump straight to reject. You will break payroll.

T.03

BIMI preparation

Once DMARC enforcement is stable, enroll in BIMI with a VMC certificate so your brand logo shows in inbox. Reduces impersonation risk.

T.04

Gateway BEC rules

Name-display impersonation detection, look-alike domain blocking, external-reply-to flagging, financial-keyword inspection.

T.05

User-report workflow

One-click 'Report Phish' button that auto-creates SOC ticket, enriches IOCs, and provides user feedback within 4 hours.

T.06

Response automation

SOAR playbook: on user report, hunt similar messages across mailboxes, auto-quarantine, notify affected users, add IOCs to block list.

From the field

Real problems. Real fixes.

Anonymized incidents from actual engagements: what broke, why it mattered, and how we fixed it.

01
Problem

Client had SPF flattening their record to 15 DNS lookups, silently breaking half their legitimate mail.

Impact

Monthly invoices failed DMARC, customers flagged emails as spam, no one knew why.

Resolution

Audited lookup chain, split domain into subdomain scoping (billing.domain.com, hr.domain.com, etc), dropped lookup count to 4. Delivery rose 22% overnight.

02
Problem

Moving to p=reject blocked the CEO's third-party newsletter vendor. 60k customer emails bounced.

Impact

Marketing team threatened to veto the whole program.

Resolution

Discovered vendor during p=quarantine phase (would've caught it anyway). Added them to SPF and enabled DKIM signing on their sending domain. Cut-over postponed by 5 days; zero bounces at enforcement.

03
Problem

BEC attack slipped through Defender. Attacker used a look-alike domain (rn instead of m).

Impact

A/P team wired $180k before the finance controller noticed.

Resolution

Deployed a homograph/look-alike detection rule at the gateway, added external-sender warning banners to all finance-role inboxes, and ran a targeted simulation. Zero successful BEC in the 14 months since.

Data model

Email trust pipeline

From sender authentication to user feedback loop.

input
process
store
output
pass/fail clean suspicious feed External sender SPF / DKIM / DMARC Gateway (ATP / ML) Inbox delivery User report button SOAR containment IOC block list
Metrics we ship against

Targets, not promises.

Metric
Our target
Baseline (industry avg)
DMARC enforcement state
p=reject in 4 weeks
Industry: 32% at p=reject
Gateway false-positive rate
< 2%
Industry avg: 7–12%
User report adoption
> 35% of users in 90 days
Industry avg: 4%
BEC dwell time
< 30 min report-to-containment
Industry avg: 42 hours
Questions we hear

Answered plainly.

Have something we didn't cover? Ask us directly →

Will enforcing DMARC break legitimate email?
Not with our graduated approach. We run p=none for 2 weeks to inventory senders, then quarantine at 10%/50%/100% before reject. Every phase is reversible within minutes.
Do we need to replace our email gateway?
No. We tune what you have: Microsoft Defender, Google, Proofpoint, Mimecast, Abnormal. Replacement is a last resort, not a first recommendation.
What about B2B senders who haven't enabled DMARC?
We implement a gradual allow-list for strategic partners during their ramp, track their DMARC progress, and remove exceptions once they enforce.
Can you help with BIMI / VMC?
Yes. After DMARC enforcement is stable, we handle the VMC provisioning and DNS configuration to get your brand logo in supporting clients.