Email Security Best Practices for Businesses: 2026 Checklist
Email security best practices for businesses in 2026: 2FA, SPF/DKIM/DMARC, MTA-STS, anti-phishing, admin roles, backups and a plan for incidents.
On this page
The most important email security best practices for a business are these. Turn on two-factor authentication for every account. Publish SPF, DKIM and DMARC for your domain. Enforce encryption in transit with MTA-STS. Add anti-phishing controls and train staff to report suspicious mail. Limit admin rights and review the audit logs. Keep restorable backups, and have a written plan for when an account is compromised.
Why email is still the main way in
Email is open by design: anyone in the world can send your staff a message. That makes it the cheapest route into a company. Credential phishing, fake invoices and malware attachments all arrive the same way. Securing email is not one product. It is a set of habits across accounts, your domain, inbound mail, people and recovery.
Below is a practical checklist, ordered roughly by impact.
1. Protect every account with 2FA
A stolen password is the most common starting point for a compromise. Two-factor authentication (2FA) with an authenticator app means a phished password alone is not enough to get in.
- Require 2FA for administrators, with no exceptions. One admin account can change everyone's settings.
- Encourage or require 2FA for all staff, and make sure everyone stores their recovery codes safely.
- Use app passwords for Outlook, Apple Mail or phone apps that connect over IMAP/SMTP, so the main password never sits in a mail client. Our guide to connecting email apps shows how.
- Set up a recovery email address, so password resets don't have to go through a helpdesk.
- Consider single sign-on (SSO) if your company already manages identities centrally.
Secure your domain and mail in transit
2. Authenticate your domain with SPF, DKIM and DMARC
These three DNS records tell the world which servers may send mail for your domain and how to treat forgeries. Gmail and Yahoo have required them from bulk senders since 2024, and having them improves delivery for everyone.
example.com. TXT "v=spf1 include:_spf.example-provider.com -all"
zm1._domainkey CNAME (provided by your email host)
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com"Start DMARC at p=none to collect reports. Fix any legitimate senders that fail, such as your CRM or invoicing tool, and then move to p=quarantine and p=reject. Details: SPF, DKIM and DMARC explained and DMARC policy setup.
3. Encrypt mail in transit
Mail between servers travels over TLS when both sides support it. Classic SMTP falls back to plain text if an attacker strips the encryption. MTA-STS tells other servers that your domain requires TLS with a valid certificate. TLS-RPT sends you reports when delivery fails. Read MTA-STS explained for the records.
Be honest with yourself about what this covers. TLS protects messages on the wire. It is not end-to-end encryption, so your email provider can still process the content, for example to filter spam.
4. Layer your inbound protection
Spam and virus filtering are the baseline. Phishing now needs more:
- An External tag on mail from outside, plus a notice when someone writes to you for the first time.
- Click-time link checking, so a link that turns malicious after delivery is still blocked.
- Impersonation and lookalike-domain detection for executives, finance staff, your bank and your key suppliers.
- A Report phishing button, plus the ability for an admin to remove a message from every mailbox.
- Zero-hour auto purge and quarantine for threats found after delivery.
Our guide to phishing protection for business email explains each layer. Finance teams should also read about business email compromise.
Govern admins and people
5. Limit admin rights and watch the logs
- Least privilege. Give helpdesk staff a helpdesk role and billing staff a billing role, rather than full admin rights.
- At least two owners, so the company is never locked out.
- Review the audit log after changes and during any incident. Export it if you need to keep it.
- Control external forwarding. Automatic forwarding to personal addresses is a common way for data to leak and a favourite trick after an account takeover.
- Offboard properly. When someone leaves, sign out their sessions, revoke their app passwords and decide who takes over their mail.
6. Train people, and make reporting easy
Technology catches most threats, but people catch the clever ones, if they know what to look for and reporting feels safe. Keep training short and practical:
- Check the sender address, not just the display name.
- Treat the External tag on a message "from" a colleague as a red flag.
- Never enter a password after clicking a link in an email. Open the service yourself instead.
- Confirm any change of bank details by phone, using a number you already have.
- Report anything odd with one click. Nobody is blamed for a false alarm.
7. Plan for recovery
Assume something will go wrong eventually: a deleted folder, a compromised account, ransomware on a laptop.
- Backups you can restore from. Know how to recover a user's deleted mail and how far back you can go.
- Retention policies for Trash and Junk, so old junk does not pile up but recent mail can still be recovered.
- An archive and legal hold if your industry requires records to be kept.
- A written incident runbook that says who resets passwords, who calls the bank, who checks the logs, and who tells customers.
Checklist at a glance
| Area | Practice | Priority |
|---|---|---|
| Accounts | 2FA for all staff, mandatory for admins; app passwords | Do now |
| Domain | SPF, DKIM, DMARC moving to p=reject | Do now |
| Transport | MTA-STS and TLS-RPT | This quarter |
| Inbound | External tag, link checking, impersonation detection, quarantine | Do now |
| Admin | Least-privilege roles, audit log review, forwarding policy | This month |
| People | Short training, one-click phishing reports | Ongoing |
| Recovery | Tested restores, retention, incident runbook | This quarter |
How Zomail covers the checklist
Zomail is designed so that most of this checklist is covered by its built-in settings:
- Accounts: TOTP 2FA with 10 recovery codes, mandatory for admins; app passwords; recovery email and self-service reset; remote sign-out; SSO with Google Workspace or Microsoft 365/Entra ID.
- Domain: a guided DNS page that checks SPF, DKIM (two CNAMEs with automatic key rotation), DMARC and MTA-STS/TLS-RPT, plus a DMARC reports dashboard.
- Transport: TLS in transit, MTA-STS enforced, and outbound DANE validation.
- Inbound: layered spam filtering and antivirus on every message and Drive upload. On top of that, the October 2026 anti-phishing controls: External tag, click-time link checking, Report phishing with organisation-wide purge, ZAP, quarantine, and impersonation and lookalike detection. See the anti-spam and anti-phishing guide.
- Admin: owner, admin, helpdesk and billing roles; an audit log with CSV export; message trace; external forwarding policies.
- Recovery: encrypted off-site backups, restore of a user's deleted mail, deleted users kept for 30 days, and an optional compliance archive with legal hold.
One honest limit: Zomail does not offer end-to-end encryption, S/MIME or PGP today.
If you want this checklist covered by default rather than assembled from add-ons, take a look at Zomail's Cloud and Private Mail plans. Prices are shown live on the pricing page.
FAQ
What is the single most important email security step?
Turn on two-factor authentication, starting with admin accounts. Most compromises begin with a stolen password, and 2FA stops a password alone from being enough.
Is email encrypted by default?
Between modern mail servers, usually yes, through TLS. But classic SMTP can fall back to plain text. MTA-STS makes TLS mandatory for mail delivered to your domain. TLS in transit is not the same as end-to-end encryption.
How often should we train staff on phishing?
Short, regular refreshers work better than a long annual course. A few minutes every quarter, plus a quick note whenever a new scam reaches your company, keeps awareness fresh.
Do small businesses really need DMARC?
Yes. Small companies are often impersonated precisely because their domains are unprotected. DMARC is free to publish, and major mailbox providers increasingly expect it from every sender.