Common Email Security Mistakes Small Businesses Make
Avoid the most common email security mistakes small businesses make including weak MFA, missing SPF/DKIM, shared accounts, and lack of staff training.
Not enabling MFA on email accounts
- Email accounts are the most common target for attackers.
- Without MFA, a stolen or guessed password gives an attacker full access to email, contacts, and often the ability to reset passwords for other services.
- MFA is free in Microsoft 365 and takes minutes to enable per user.
Using shared accounts for email
- Shared accounts make it impossible to know who did what and complicate access removal when someone leaves.
- If a shared account is compromised, it is harder to trace and contain.
- Each person should have their own named account. Shared mailboxes and distribution groups exist for shared access scenarios.
Missing or misconfigured SPF, DKIM, and DMARC
- These DNS records help prevent attackers from sending email that appears to come from your domain.
- Without them, your email domain can be spoofed, damaging your reputation and making phishing attacks against your customers and partners easier.
- Many small businesses skip these because they sound technical, but they are straightforward to configure with guidance.
No staff training on email threats
- Staff are the first line of defense. If no one knows what a phishing email looks like, technical controls can only do so much.
- Regular, short reminders about suspicious links, unexpected attachments, and urgent payment requests are more effective than one-time training.
- Encourage staff to report suspicious emails without fear of being wrong. A quick report is better than a clicked link.
Email forwarding rules not reviewed
- Attackers who gain access to an account often create hidden forwarding rules to silently monitor email.
- Review forwarding rules periodically, especially after any suspicious activity.
- Consider whether auto-forwarding to external addresses is necessary for your business or if it creates unnecessary risk.
Frequently Asked Questions
How do I know if my email domain is properly secured?
Check your SPF, DKIM, and DMARC records. Microsoft 365 includes tools to help configure these. A technology provider can review your DNS records and email configuration to identify gaps.
What should I do if I think an email account has been compromised?
Change the password immediately, enable or reset MFA, check for forwarding rules, review recent sign-in activity, and notify anyone who may have received suspicious email from the compromised account.
How often should staff be trained on email security?
Short, regular reminders work best. A brief monthly email tip or quarterly 15-minute review is more effective than a one-time annual training that is quickly forgotten.
Need help?
Maine CyberTech helps Maine businesses review email security settings, configure MFA, set up SPF/DKIM/DMARC, and train staff on recognizing email threats. Contact us for an email security review.
Contact Us