Impersonation protection
Confirm whether key executives and the organization’s own domain are protected against look-alike display-name and domain attacks.
Independent IT security review
Email remains the most common path into a tenant. The review reads anti-phishing, authentication, and mail flow settings together instead of trusting default protection alone.
Default protection is a starting point, not a finished configuration. The review checks what is actually enforced for the organization’s specific domains and executives.
Confirm whether key executives and the organization’s own domain are protected against look-alike display-name and domain attacks.
Review how spoofed senders are handled and whether legitimate third-party senders are documented rather than blanket-allowed.
Confirm anti-phishing policies actually apply to the intended recipients, not only a default tenant-wide policy left unmodified.
SPF, DKIM, and DMARC only work as a system. A gap in any one weakens the others and can leave spoofed mail simply unflagged.
Confirm records are published correctly for every sending source the organization actually uses, including third-party services.
Check whether DMARC exists only in monitoring mode or is actually enforcing rejection or quarantine as intended.
Inventory marketing, invoicing, and other services sending as the organization’s domain, since an overlooked one breaks alignment.
Safe Attachments and Safe Links, where licensed, only help if their scope and exceptions match how the organization actually works.
Confirm which mailboxes and applications (mail, Teams, SharePoint) are actually covered where these protections are licensed.
Review trusted sender and URL exceptions for ones that quietly reopen the exact path the policy was meant to close.
Document plainly when a protection depends on a licence tier the organization may not currently hold.
A detection with no owner does not protect anyone. The review checks the human process behind the technical controls.
Confirm how employees report suspicious mail and whether that path is actually monitored.
Identify who releases or confirms quarantined messages, and how false positives are handled without normalizing risky releases.
Distinguish this review from active incident response; a confirmed compromise needs containment, not a configuration review.
Next step
Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.