Skip to main content
Guidance

Email security and anti-spoofing

A guide for IT managers and systems administrators

Page 2 of 14

Recommended implementation plan

We recommend a phased approach to securing your email:
  1. Choose an anti-spoofing management tool
  2. Protect email in transit
  3. Configure anti-spoofing controls
  4. Send spoof emails to spam
  5. Spoof emails being rejected
  6. Continuous improvement

The size and complexity of your organisation, the amount of change occurring and resources available to you will determine exactly how long you need.

Once you have secured your emails in transit, and implemented a DMARC policy of 'reject' on all of your domains, you should regularly conduct health checks and fix any problems which show up.

You should create a basic plan for your implementation.

Published

Reviewed

Version

2.0