We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Email security audit
Email security audit, UAE

Every tenant we audit has at least one allow entry nobody can explain, added during an incident that ended years ago.

An email security audit examines authentication records, the policy configuration, the exception lists, the mail routing and the mailbox rules. The findings are consistently in the last three, because the first two get attention during projects and the exceptions accumulate quietly between them.

Book an email security auditSee the five layers
Email security audit for UAE organisations
  • Five layersAuthentication, policy, exceptions, routing, mailboxes
  • Allow entriesThe list nobody has reviewed since it was created
  • CIS Control 9Email and web browser protections
  • Already licensedMost findings need configuration, not purchase
What we examine

Seven areas, and the exceptions are where the findings are.

Email and web browser protections is control 9 in the CIS Critical Security Controls at version 8.1. In a Microsoft 365 tenant most of the capability is already licensed, which means the audit output is usually a set of configuration changes rather than a purchase, and that is a considerably easier conversation.

Authentication records, and whether they do anything

Sender policy framework, domain keys identified mail and domain-based message authentication for every sending domain, including the ones used only by a marketing platform or an invoicing system. Microsoft also applies implicit email authentication, enhancing those standard checks with sender reputation, sender history, recipient history and behavioural analysis to identify forged senders.

Impersonation protection, and whether the list is populated

Defender for Office 365 anti-phishing policies configure impersonation protection for specific message senders and sender domains, plus mailbox intelligence and adjustable phishing thresholds. The audit question is not whether the feature exists but whether the protected sender list contains the current leadership team, the finance function and the counterparty domains that appear on payment instructions.

Spoof handling and the sender DMARC decision

All cloud mailboxes get spoof intelligence, with the spoof intelligence insight for reviewing detected spoofed senders from external and internal domains. A separate setting controls what happens where a sender fails explicit DMARC checks and their own published policy is quarantine or reject. Whether you honour that is a decision, and in most tenants it has never been made deliberately.

Link protection, including what it does not cover

There is no default Safe Links policy, though the built-in protection preset provides coverage to all recipients for customers with at least one Defender for Office 365 licence. The published exclusions matter for an audit: it does not work on mail-enabled public folders, supports only HTTP, HTTPS and FTP formats, does not protect URLs in rich text format messages, and ignores S and MIME signed messages.

The exception lists nobody has read since they were written

Spoofed sender overrides in the Tenant Allow Block List, allow entries added to unblock a supplier during an incident, do not rewrite entries in Safe Links policies, and transport rules that bypass filtering for a sender or a domain. These accumulate over years, they are almost never reviewed, and they are the single most productive part of an email audit.

Mail routing, connectors and the path in

Inbound connectors, third-party gateways in front of or behind Microsoft, hybrid routing, and any path that delivers mail while bypassing part of the filtering stack. Where two products both process mail, one of them is frequently doing less than anybody believes, and establishing which is a short exercise with a substantial answer.

Mailbox-level configuration and forwarding

Automatic forwarding to external addresses, inbox rules that move or delete mail from specific senders, delegate permissions granted years ago and never removed, and mailboxes with unexpected send-as rights. Business email compromise leaves traces in exactly these places, and reviewing them proactively finds the ones from compromises nobody detected.

The most productive finding, every time

The allow lists. Nobody reviews them, everybody adds to them, and each entry is a permanent exception.

Exception lists in email security behave exactly like firewall rules. Adding an entry solves an urgent problem. Removing one has no visible benefit and a small chance of blocking legitimate mail.

  • Spoofed sender overrides sit on the spoofed senders tab of the Tenant Allow Block List. Microsoft states that overriding a verdict in the spoof intelligence insight creates a manual allow or block entry there, and entries can also be created manually before spoof intelligence detects the sender.
  • Do not rewrite entries in Safe Links policies are a second list, with their own subtleties. Only one such list applies to any user, from whichever single policy wins on priority, because policy processing stops after the first policy is applied and built-in protection is always applied last.
  • Transport rules that bypass filtering for a sender, a domain or an IP address are the third list, and they are the most powerful because they can exempt mail from processing entirely. They are also the least visible, because they live in mail flow rather than in the security portal.
  • None of these lists expires. An entry added in 2021 to unblock a supplier relationship that ended in 2023 is still there, still permitting mail from a domain nobody at your organisation now controls a relationship with. Reviewing them is an afternoon and it is consistently the highest-yield hour of the audit.
Ask us to review your allow lists
How we approach it

Four things an email audit finds that a configuration review does not.

Reading the security policies tells you what was intended. The audit is about the gap between that and what mail actually experiences, and that gap lives in exceptions, routing and mailboxes.

We read every exception list and ask who added it and why

Tenant allow and block entries, do not rewrite lists in Safe Links policies, and transport rules that bypass filtering. These accumulate silently, they never expire, and each is a permanent exception created for a temporary reason. It is the highest-yield hour of any email audit and the one nobody schedules for themselves.

We trace the routing rather than trusting the diagram

Inbound connectors, third-party gateways, hybrid paths and any route that delivers mail while bypassing part of the stack. Where two products both process mail, establishing which one is actually doing the work resolves a question most organisations have never asked and occasionally saves a renewal.

We check the impersonation list against the current organisation chart

Impersonation protection covers the specific senders and sender domains you name. A list built during a deployment project protects the leadership team of that year. Rebuilding it around who currently signs off payments, and which counterparty domains appear on real instructions, is an afternoon of work with a direct effect on fraud exposure.

We look at mailboxes, because compromise leaves traces there

External forwarding, inbox rules that move or delete mail from specific senders, delegate permissions and unexpected send-as rights. Business email compromise operates through exactly these mechanisms, and a proactive review reliably finds artefacts from compromises that were never detected at the time.

Where this matters most

Six UAE situations where an email audit is the right first move.

Email remains the primary delivery route for the attacks that actually cost UAE organisations money, and most of the defence is already licensed and partially configured.

A firm that has experienced or narrowly avoided payment fraud

The audit covers all three layers that matter for this: authentication records that make forgery harder, impersonation protection for the people and counterparty domains involved in payment instructions, and the mailbox review that finds forwarding rules and delegate permissions left behind by a compromise.

An organisation that has changed email platform or provider

Migrations leave routing artefacts: connectors that are still active, transport rules written for the old arrangement, and exception entries carried across because nobody knew what they were for. Auditing after a migration is when those are cheapest to find and most likely to still be explicable.

A business running a third-party gateway alongside Microsoft

Where two products both filter and both potentially rewrite links, one of them is doing less than anybody believes. Establishing which, and whether the arrangement creates a gap or merely a duplication, is a short exercise and it occasionally reframes a renewal decision entirely.

A business whose brand is being spoofed

Where customers report receiving mail that appears to come from you, the answer lies in the authentication records for every domain you send from, including the ones a marketing or invoicing platform uses. The audit establishes the full sending inventory, which is usually larger than the marketing team believes.

An operator with many shared and functional mailboxes

Shared mailboxes, distribution lists and functional addresses accumulate delegate permissions and forwarding rules over years, and they are rarely covered by any review because they are not people. They are also frequently the mailboxes that receive supplier invoices, which makes them the ones that matter.

An organisation preparing for a security questionnaire or audit

Email controls appear in essentially every customer security questionnaire and most regulatory expectations. A documented audit covering authentication, policy, exceptions, routing and mailbox configuration answers the section comprehensively, and because most findings are configuration rather than purchase, the remediation is quick.

Three positions

How UAE organisations manage email security.

The middle column is the overwhelming norm. The tenant was configured properly during a project, the licences are held, and nothing has been reviewed since the person who did it moved on.
All sending domains authenticated
Audited and maintainedYes
Configured once, never reviewedPartly
Defaults onlyNo
Impersonation protection populated
Audited and maintainedYes
Configured once, never reviewedEmpty or stale
Defaults onlyNot licensed or not set
Internal mail link scanning on
Audited and maintainedYes
Configured once, never reviewedOften not
Defaults onlyNo
Allow lists reviewed
Audited and maintainedYes
Configured once, never reviewedNever
Defaults onlyNot applicable
Bypass transport rules known
Audited and maintainedYes
Configured once, never reviewedNo
Defaults onlyUnknown
Routing understood end to end
Audited and maintainedYes
Configured once, never reviewedPartly
Defaults onlyNo
External forwarding controlled
Audited and maintainedYes
Configured once, never reviewedSometimes
Defaults onlyNo
Inbox rules reviewed for compromise traces
Audited and maintainedYes
Configured once, never reviewedNo
Defaults onlyNo
Findings need purchase
Audited and maintainedRarely
Configured once, never reviewedNot applicable
Defaults onlySometimes
Position against targeted fraud
Audited and maintainedDefended
Configured once, never reviewedExposed
Defaults onlyExposed
Feature
Audited and maintained
Configured once, never reviewed
Defaults only
All sending domains authenticated
YesPartlyNo
Impersonation protection populated
YesEmpty or staleNot licensed or not set
Internal mail link scanning on
YesOften notNo
Allow lists reviewed
YesNeverNot applicable
Bypass transport rules known
YesNoUnknown
Routing understood end to end
YesPartlyNo
External forwarding controlled
YesSometimesNo
Inbox rules reviewed for compromise traces
YesNoNo
Findings need purchase
RarelyNot applicableSometimes
Position against targeted fraud
DefendedExposedExposed
The audit scope

Five layers, and what the audit establishes at each.

Attention in most organisations concentrates on the first two layers, because they are what projects deliver. The findings concentrate in the last three, because they are what accumulates between projects.
LayerWhat we establishTypical finding
Authentication recordsSPF, DKIM and DMARC for every sending domain and subdomainA domain used by a marketing platform with no alignment, and a DMARC policy at none
Policy configurationAnti-phishing, spoof handling, link protection and attachment handlingImpersonation protection licensed and the protected sender list empty
Exception listsTenant allow and block entries, do not rewrite lists, and bypass transport rulesEntries nobody can explain, from incidents that closed years ago
Mail routingConnectors, third-party gateways, hybrid paths and anything that bypasses filteringTwo products wrapping links, one of which is doing nothing
Mailbox configurationExternal forwarding, inbox rules, delegates and send-as permissionsForwarding rules from a compromise nobody detected at the time
How an engagement runs

Five steps, and it is shorter than most audits.

Typically one to three weeks. Most of the evidence is available from the tenant with read access, and the majority of findings are configuration changes rather than projects.
  1. 1

    Inventory the sending domains and check authentication

    Every domain and subdomain that sends as your organisation, including marketing platforms, invoicing systems, ticketing tools and anything else that sends on your behalf. Then sender policy framework, domain keys identified mail and domain-based authentication for each, including whether the record does what its author intended.

  2. 2

    Review the policy configuration across every surface

    Anti-phishing including the impersonation protected sender and domain lists, mailbox intelligence and phishing thresholds. Spoof intelligence settings and the decision on honouring other senders published policies. Link protection across email, internal mail, collaboration and documents. Attachment handling and quarantine behaviour.

  3. 3

    Read every exception list

    Tenant allow and block entries including the spoofed senders tab, do not rewrite entries in each Safe Links policy noting that only one list applies per user, and transport rules that bypass filtering. Each entry gets a question: who added it, why, and does the reason still exist.

  4. 4

    Trace the mail routing end to end

    Inbound and outbound connectors, third-party gateways in front of or behind Microsoft, hybrid arrangements, and any path that delivers mail while bypassing part of the stack. Where two products process mail, we establish which is doing what rather than assuming the arrangement works as designed.

  5. 5

    Review mailbox configuration and report with priorities

    External forwarding, inbox rules, delegate and send-as permissions across user, shared and functional mailboxes. Then a report ordered by what reduces fraud exposure fastest, which for most organisations is the impersonation list, the exception cleanup and internal mail scanning, none of which requires a purchase.

Straight answers

What organisations ask about email security audits.

Five layers. Authentication records for every sending domain. Policy configuration including anti-phishing, spoof handling, link and attachment protection. Exception lists including tenant allow and block entries, do not rewrite lists and bypass transport rules. Mail routing including connectors and any third-party gateway. And mailbox configuration including forwarding, inbox rules, delegates and send-as permissions.

Usually not, and that is one of the better features of this particular audit. In a Microsoft 365 tenant most of the capability is already licensed and partially configured, so the majority of findings are settings that were never turned on, lists that were never populated, and exceptions that were never removed. Occasionally a licensing gap emerges, and we state it plainly when it does.

Because they never expire and nobody reviews them. Each entry was added for a real reason under time pressure, usually to unblock a supplier or a customer during an urgent situation. The situation ends and the entry remains. Across several years and several administrators, the accumulated exceptions can materially undermine an otherwise well-configured tenant.

A mail flow rule that exempts messages from some or all filtering based on sender, domain, IP address or header. It is the most powerful exception available because it operates before the security stack rather than within it, and it is the least visible because it lives in mail flow configuration rather than in the security portal where somebody reviewing security would look.

Yes, for every domain and subdomain that sends as your organisation, which is usually more than the list somebody supplies. Marketing platforms, invoicing systems, ticketing tools and helpdesk software all send on your behalf, and each needs to be authorised correctly. Separately, we check whether you honour the published policies of other senders, which is a distinct decision most tenants have never made.

Microsoft enhances the standard checks for inbound email, meaning sender policy framework, domain keys identified mail and domain-based authentication, with sender reputation, sender history, recipient history, behavioural analysis and other advanced techniques to help identify forged senders. It means your own records matter and the platform is not relying on them alone.

No, and the published exclusions are worth knowing. Safe Links does not work on mail-enabled public folders, supports only HTTP, HTTPS and FTP link formats, provides no protection for URLs in rich text format messages, and ignores messages signed with S and MIME. There is also no default policy, though a built-in protection preset covers all recipients where at least one Defender for Office 365 licence exists.

Because business email compromise operates through them. An attacker with mailbox access typically creates a rule that moves or deletes mail from a finance address, or sets forwarding to an external address, so the legitimate user does not see the conversation. Reviewing these proactively regularly finds artefacts from compromises that were never detected at the time.

Frequently more so. Where two products both filter mail, the interaction is rarely as designed. One may be wrapping links the other then cannot process. One may be trusted by connector configuration in a way that bypasses filtering. Establishing what each is actually doing is a short exercise with a substantial answer, and it sometimes changes a renewal decision.

One to three weeks for most organisations. Most evidence is available with read access to the tenant, and the analysis is straightforward. The variable is how many sending domains exist and how many exception entries have to be traced back to a reason, since that requires people rather than queries.

Three, and they recur almost universally. An impersonation protected sender list that is empty or lists people who have left. Internal to internal mail not being scanned, despite that being the route most lateral phishing takes. And a set of allow entries nobody can explain, from incidents that closed years ago.

No, they measure different things and both are useful. A simulation measures whether your people click. This audit measures whether your technology would have stopped the message reaching them, and whether the exceptions in place would have let it through. Running simulations while the technical configuration is incomplete tests people against attacks the platform was never told to stop.

Yes, and most clients want that. Because the majority are configuration rather than purchase, remediation is usually days rather than a project. The sequence we recommend is the impersonation list first, then the exception cleanup, then internal mail scanning and the click-through setting, because those four have the largest effect on fraud exposure for the least disruption.

Annually as a baseline, and after any change to mail routing, a platform migration, or a significant change to the leadership or finance teams, since the impersonation list depends on both. The exception lists in particular need a review cadence, because they grow continuously and nothing in the platform prompts anybody to look at them.

Yes, and it answers a different question. Inbound controls determine what reaches your people. Outbound controls determine what leaves in your name, which matters for both data loss and for the reputation of your sending domains. The audit covers outbound connectors, whether sensitive content is inspected on the way out, and whether a compromised mailbox could send at volume before anybody noticed.

It is in scope and it is more consequential than it sounds. Where users can release anything from quarantine without review, a detection that worked is being overridden by the person the message was aimed at, which is the least reliable possible reviewer. The audit establishes what users can release, what requires administrator approval, whether anybody reviews release patterns, and how long quarantined items are retained before they disappear.

We scope per organisation, driven by the number of sending domains, whether a third-party gateway is in the path and how many mailboxes are in scope for the configuration review. It is one of the shorter audits we run and one of the more consistently productive, because the findings are usually free to fix.
Questions the audit answers

Fifteen things you should be able to answer about your email security.

These are the questions we work through. Most organisations can answer the first group, some of the second, and almost none of the third without looking.

Authentication

  • Do you know every domain that sends as you?
    Including marketing and invoicing platforms.
  • Is DMARC published, and at what policy?
    None, quarantine or reject.
  • Is DKIM signing every sending source?
    Third-party senders are the usual gap.
  • Is SPF within its lookup limit?
    Adding senders breaks it silently.
  • Do you honour other senders DMARC policies?
    A separate setting, rarely decided.

Policy

  • Is the impersonation protected sender list current?
    Leadership and finance change.
  • Are counterparty domains protected?
    The ones on payment instructions.
  • Is internal to internal mail scanned for links?
    A separate setting.
  • Can users click through a malicious link warning?
    Recommended off.
  • Are phishing thresholds set deliberately?
    They are adjustable.

Exceptions and routing

  • How many allow entries exist?
    And can anybody explain them.
  • Are there bypass transport rules?
    The most powerful exception.
  • Is another product also processing mail?
    One of them may be doing nothing.
  • Is external forwarding permitted anywhere?
    Check per mailbox, not per policy.
  • When did anyone last review inbox rules?
    Compromise leaves traces here.
Related reading

The pages around this one.

DMARC audit

The authentication record layer in depth, including alignment and reporting.

Learn more

Anti-phishing policies

The policy configuration layer, including impersonation protection.

Learn more

Safe Links

Link protection specifically, including what it does not cover.

Learn more
Next step

Open your tenant allow list and count the entries you can explain.

It is a five minute check and it is the most reliable indicator of whether your email security reflects a current decision or an accumulated history. Every audit we have run has found at least one entry nobody could account for.

Book an email security auditCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

DMARC Audit UAE

Stop exact-domain spoofing, and keep your mail delivering

Learn more

Anti-Phishing Policies

Impersonation protection, spoof handling and thresholds

Learn more

Safe Links

Time-of-click URL checks in mail, Teams and Office

Learn more

Defender for Office 365

Plan 1 versus Plan 2, and the ten second way to tell which you have

Learn more

Phishing Protection

Defender for Office 365, DMARC, simulation campaigns

Learn more

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more

Attack Simulation Training

Phishing simulation you probably already own, including QR codes

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy