Every tenant we audit has at least one allow entry nobody can explain, added during an incident that ended years ago.
An email security audit examines authentication records, the policy configuration, the exception lists, the mail routing and the mailbox rules. The findings are consistently in the last three, because the first two get attention during projects and the exceptions accumulate quietly between them.

- Five layersAuthentication, policy, exceptions, routing, mailboxes
- Allow entriesThe list nobody has reviewed since it was created
- CIS Control 9Email and web browser protections
- Already licensedMost findings need configuration, not purchase
Seven areas, and the exceptions are where the findings are.
Authentication records, and whether they do anything
Sender policy framework, domain keys identified mail and domain-based message authentication for every sending domain, including the ones used only by a marketing platform or an invoicing system. Microsoft also applies implicit email authentication, enhancing those standard checks with sender reputation, sender history, recipient history and behavioural analysis to identify forged senders.
Impersonation protection, and whether the list is populated
Defender for Office 365 anti-phishing policies configure impersonation protection for specific message senders and sender domains, plus mailbox intelligence and adjustable phishing thresholds. The audit question is not whether the feature exists but whether the protected sender list contains the current leadership team, the finance function and the counterparty domains that appear on payment instructions.
Spoof handling and the sender DMARC decision
All cloud mailboxes get spoof intelligence, with the spoof intelligence insight for reviewing detected spoofed senders from external and internal domains. A separate setting controls what happens where a sender fails explicit DMARC checks and their own published policy is quarantine or reject. Whether you honour that is a decision, and in most tenants it has never been made deliberately.
Link protection, including what it does not cover
There is no default Safe Links policy, though the built-in protection preset provides coverage to all recipients for customers with at least one Defender for Office 365 licence. The published exclusions matter for an audit: it does not work on mail-enabled public folders, supports only HTTP, HTTPS and FTP formats, does not protect URLs in rich text format messages, and ignores S and MIME signed messages.
The exception lists nobody has read since they were written
Spoofed sender overrides in the Tenant Allow Block List, allow entries added to unblock a supplier during an incident, do not rewrite entries in Safe Links policies, and transport rules that bypass filtering for a sender or a domain. These accumulate over years, they are almost never reviewed, and they are the single most productive part of an email audit.
Mail routing, connectors and the path in
Inbound connectors, third-party gateways in front of or behind Microsoft, hybrid routing, and any path that delivers mail while bypassing part of the filtering stack. Where two products both process mail, one of them is frequently doing less than anybody believes, and establishing which is a short exercise with a substantial answer.
Mailbox-level configuration and forwarding
Automatic forwarding to external addresses, inbox rules that move or delete mail from specific senders, delegate permissions granted years ago and never removed, and mailboxes with unexpected send-as rights. Business email compromise leaves traces in exactly these places, and reviewing them proactively finds the ones from compromises nobody detected.
The allow lists. Nobody reviews them, everybody adds to them, and each entry is a permanent exception.
Exception lists in email security behave exactly like firewall rules. Adding an entry solves an urgent problem. Removing one has no visible benefit and a small chance of blocking legitimate mail.
- Spoofed sender overrides sit on the spoofed senders tab of the Tenant Allow Block List. Microsoft states that overriding a verdict in the spoof intelligence insight creates a manual allow or block entry there, and entries can also be created manually before spoof intelligence detects the sender.
- Do not rewrite entries in Safe Links policies are a second list, with their own subtleties. Only one such list applies to any user, from whichever single policy wins on priority, because policy processing stops after the first policy is applied and built-in protection is always applied last.
- Transport rules that bypass filtering for a sender, a domain or an IP address are the third list, and they are the most powerful because they can exempt mail from processing entirely. They are also the least visible, because they live in mail flow rather than in the security portal.
- None of these lists expires. An entry added in 2021 to unblock a supplier relationship that ended in 2023 is still there, still permitting mail from a domain nobody at your organisation now controls a relationship with. Reviewing them is an afternoon and it is consistently the highest-yield hour of the audit.
Four things an email audit finds that a configuration review does not.
We read every exception list and ask who added it and why
Tenant allow and block entries, do not rewrite lists in Safe Links policies, and transport rules that bypass filtering. These accumulate silently, they never expire, and each is a permanent exception created for a temporary reason. It is the highest-yield hour of any email audit and the one nobody schedules for themselves.
We trace the routing rather than trusting the diagram
Inbound connectors, third-party gateways, hybrid paths and any route that delivers mail while bypassing part of the stack. Where two products both process mail, establishing which one is actually doing the work resolves a question most organisations have never asked and occasionally saves a renewal.
We check the impersonation list against the current organisation chart
Impersonation protection covers the specific senders and sender domains you name. A list built during a deployment project protects the leadership team of that year. Rebuilding it around who currently signs off payments, and which counterparty domains appear on real instructions, is an afternoon of work with a direct effect on fraud exposure.
We look at mailboxes, because compromise leaves traces there
External forwarding, inbox rules that move or delete mail from specific senders, delegate permissions and unexpected send-as rights. Business email compromise operates through exactly these mechanisms, and a proactive review reliably finds artefacts from compromises that were never detected at the time.
Six UAE situations where an email audit is the right first move.
A firm that has experienced or narrowly avoided payment fraud
The audit covers all three layers that matter for this: authentication records that make forgery harder, impersonation protection for the people and counterparty domains involved in payment instructions, and the mailbox review that finds forwarding rules and delegate permissions left behind by a compromise.
An organisation that has changed email platform or provider
Migrations leave routing artefacts: connectors that are still active, transport rules written for the old arrangement, and exception entries carried across because nobody knew what they were for. Auditing after a migration is when those are cheapest to find and most likely to still be explicable.
A business running a third-party gateway alongside Microsoft
Where two products both filter and both potentially rewrite links, one of them is doing less than anybody believes. Establishing which, and whether the arrangement creates a gap or merely a duplication, is a short exercise and it occasionally reframes a renewal decision entirely.
A business whose brand is being spoofed
Where customers report receiving mail that appears to come from you, the answer lies in the authentication records for every domain you send from, including the ones a marketing or invoicing platform uses. The audit establishes the full sending inventory, which is usually larger than the marketing team believes.
An operator with many shared and functional mailboxes
Shared mailboxes, distribution lists and functional addresses accumulate delegate permissions and forwarding rules over years, and they are rarely covered by any review because they are not people. They are also frequently the mailboxes that receive supplier invoices, which makes them the ones that matter.
An organisation preparing for a security questionnaire or audit
Email controls appear in essentially every customer security questionnaire and most regulatory expectations. A documented audit covering authentication, policy, exceptions, routing and mailbox configuration answers the section comprehensively, and because most findings are configuration rather than purchase, the remediation is quick.
How UAE organisations manage email security.
| Feature | Audited and maintained | Configured once, never reviewed | Defaults only |
|---|---|---|---|
All sending domains authenticated | Yes | Partly | No |
Impersonation protection populated | Yes | Empty or stale | Not licensed or not set |
Internal mail link scanning on | Yes | Often not | No |
Allow lists reviewed | Yes | Never | Not applicable |
Bypass transport rules known | Yes | No | Unknown |
Routing understood end to end | Yes | Partly | No |
External forwarding controlled | Yes | Sometimes | No |
Inbox rules reviewed for compromise traces | Yes | No | No |
Findings need purchase | Rarely | Not applicable | Sometimes |
Position against targeted fraud | Defended | Exposed | Exposed |
Five layers, and what the audit establishes at each.
| Layer | What we establish | Typical finding | |
|---|---|---|---|
| Authentication records | SPF, DKIM and DMARC for every sending domain and subdomain | A domain used by a marketing platform with no alignment, and a DMARC policy at none | |
| Policy configuration | Anti-phishing, spoof handling, link protection and attachment handling | Impersonation protection licensed and the protected sender list empty | |
| Exception lists | Tenant allow and block entries, do not rewrite lists, and bypass transport rules | Entries nobody can explain, from incidents that closed years ago | |
| Mail routing | Connectors, third-party gateways, hybrid paths and anything that bypasses filtering | Two products wrapping links, one of which is doing nothing | |
| Mailbox configuration | External forwarding, inbox rules, delegates and send-as permissions | Forwarding rules from a compromise nobody detected at the time |
Five steps, and it is shorter than most audits.
- 1
Inventory the sending domains and check authentication
Every domain and subdomain that sends as your organisation, including marketing platforms, invoicing systems, ticketing tools and anything else that sends on your behalf. Then sender policy framework, domain keys identified mail and domain-based authentication for each, including whether the record does what its author intended.
- 2
Review the policy configuration across every surface
Anti-phishing including the impersonation protected sender and domain lists, mailbox intelligence and phishing thresholds. Spoof intelligence settings and the decision on honouring other senders published policies. Link protection across email, internal mail, collaboration and documents. Attachment handling and quarantine behaviour.
- 3
Read every exception list
Tenant allow and block entries including the spoofed senders tab, do not rewrite entries in each Safe Links policy noting that only one list applies per user, and transport rules that bypass filtering. Each entry gets a question: who added it, why, and does the reason still exist.
- 4
Trace the mail routing end to end
Inbound and outbound connectors, third-party gateways in front of or behind Microsoft, hybrid arrangements, and any path that delivers mail while bypassing part of the stack. Where two products process mail, we establish which is doing what rather than assuming the arrangement works as designed.
- 5
Review mailbox configuration and report with priorities
External forwarding, inbox rules, delegate and send-as permissions across user, shared and functional mailboxes. Then a report ordered by what reduces fraud exposure fastest, which for most organisations is the impersonation list, the exception cleanup and internal mail scanning, none of which requires a purchase.
What organisations ask about email security audits.
Fifteen things you should be able to answer about your email security.
Authentication
- Do you know every domain that sends as you?Including marketing and invoicing platforms.
- Is DMARC published, and at what policy?None, quarantine or reject.
- Is DKIM signing every sending source?Third-party senders are the usual gap.
- Is SPF within its lookup limit?Adding senders breaks it silently.
- Do you honour other senders DMARC policies?A separate setting, rarely decided.
Policy
- Is the impersonation protected sender list current?Leadership and finance change.
- Are counterparty domains protected?The ones on payment instructions.
- Is internal to internal mail scanned for links?A separate setting.
- Can users click through a malicious link warning?Recommended off.
- Are phishing thresholds set deliberately?They are adjustable.
Exceptions and routing
- How many allow entries exist?And can anybody explain them.
- Are there bypass transport rules?The most powerful exception.
- Is another product also processing mail?One of them may be doing nothing.
- Is external forwarding permitted anywhere?Check per mailbox, not per policy.
- When did anyone last review inbox rules?Compromise leaves traces here.
Open your tenant allow list and count the entries you can explain.
It is a five minute check and it is the most reliable indicator of whether your email security reflects a current decision or an accumulated history. Every audit we have run has found at least one entry nobody could account for.
Related Services
Explore more solutions that work great with this service
DMARC Audit UAE
Stop exact-domain spoofing, and keep your mail delivering
Anti-Phishing Policies
Impersonation protection, spoof handling and thresholds
Safe Links
Time-of-click URL checks in mail, Teams and Office
Defender for Office 365
Plan 1 versus Plan 2, and the ten second way to tell which you have
Phishing Protection
Defender for Office 365, DMARC, simulation campaigns
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
Attack Simulation Training
Phishing simulation you probably already own, including QR codes
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly