Skip to main content
← Back to all posts
email security··10 min read·By QuantM Security Team

How to Run an SMB Email Security Audit

Audit domains, identities, threat policies, mail flow, devices, data controls, logging, user reporting, response, and evidence. The result is a prioritized action register, not a certificate.

An SMB email security audit is a structured review of scope, configuration, coverage, ownership, operation, and evidence. It should identify gaps and assign corrective work. It is not a certification, penetration test, or guarantee that an incident will not occur.

1. Define scope before testing controls

Inventory domains, tenants, shared mailboxes, privileged accounts, mailing services, CRM and ticketing senders, mobile access, archives, security gateways, forwarding, connectors, OAuth applications, and endpoint coverage. Record the owner for each.

2. Review domain authentication and mail flow

Validate SPF, DKIM, and DMARC for every sending domain. Compare records with the authorized-sender inventory. Review DMARC reports and enforcement plans. Trace inbound and outbound mail flow through gateways and connectors so each inspection point is understood.

3. Review identity and privileged access

Measure MFA and Conditional Access coverage, authentication methods, emergency access, administrator roles, dormant accounts, guests, service accounts, and recovery procedures. Investigate exclusions rather than accepting a tenant-wide percentage alone.

4. Review threat policies and user reporting

Inspect anti-spam, anti-malware, anti-phishing, impersonation, Safe Links, Safe Attachments, quarantine, allow/block entries, and user-reporting configuration supported by the licence. Review false-positive handling and policy-change records.

Microsoft's anti-phishing tuning guidance recommends investigating delivery before changing policy.

5. Review devices, applications, and data

Confirm which managed and unmanaged devices can access email and files. Review endpoint coverage for email-borne attacks, app-protection rules, OAuth consent, external forwarding, DLP, encryption, retention, labels, and guest or external sharing where applicable.

6. Review logging and investigation capability

Verify access to message trace, audit logs, sign-in activity, alert and incident records, mailbox rules, forwarding, OAuth grants, and endpoint telemetry. Record retention limits and who can retrieve evidence after hours.

Microsoft's phishing investigation playbook provides a useful evidence sequence for Microsoft 365 incidents.

7. Review people and business workflows

Check onboarding, recurring training, phishing reporting, targeted coaching, and role-specific verification for payment, payroll, client-data, and account changes. Review whether employees can report a mistake without delay or fear.

8. Exercise the response path

Test at least one suspicious-message scenario from user report through search, investigation, account and session containment, endpoint action, communication, and evidence preservation. Include a payment-fraud branch if finance workflows are in scope.

Audit worksheet

Area Evidence Finding Risk Owner Due date Verification
Domain and mail flow Records, reports, connectors Document the gap High/medium/low with rationale Named person Date Retest method
Identity Coverage, methods, roles Document the gap High/medium/low with rationale Named person Date Retest method
Threat protection Policy export, exceptions Document the gap High/medium/low with rationale Named person Date Retest method
Device and data Inventory and policies Document the gap High/medium/low with rationale Named person Date Retest method
Response Exercise and incident records Document the gap High/medium/low with rationale Named person Date Retest method

Prioritize findings by business impact, exposure, control dependency, and remediation effort. Fix unprotected administrators, risky mail flow, unsupported systems, and missing response authority before lower-impact tuning.

The email security compliance evidence guide explains what to retain, and the complete control model connects the controls. An M365 Posture Review provides an external review of identity, email, sharing, and response readiness.