Setting Up Secure Email for a New Business

Setting Up Secure Email for a New Business

Why your email address should carry your company name

If you are still sending quotes from a free webmail address, you are quietly telling every customer that you are a one-person operation working from a kitchen table. That may even be true, but it is not the impression you want on an invoice for four thousand pounds of work.

A domain-based address — your name, then @ your company name — does three useful things at once. It looks established, it carries over if you ever change email providers, and it gives you control over the settings that decide whether your mail lands in an inbox or a spam folder. That last point matters more than most new businesses realise. A quote or invoice that never arrives is a lost job, and the customer will never tell you it went missing.

Buying the domain and getting the technical bits right

Start by registering your domain through a registrar you can actually log into, and keep those login details somewhere safe and shared with a trusted colleague. If the domain is registered in the personal name of whoever set it up and they leave, you have a genuine problem.

Once the domain is yours, three DNS records do the heavy lifting:

  • MX records tell the world where to deliver your mail. Your email provider will give you the exact values to paste in.
  • SPF and DKIM prove that messages claiming to be from you really were sent by your systems. Set both up before you send anything important.
  • DMARC tells receiving servers what to do with mail that fails those checks. Start with a monitoring policy, watch the reports for a few weeks, then tighten it. Jumping straight to a strict setting can wipe out legitimate mail from booking systems and newsletter tools.

If you only remember one thing from this section, make it this: do this work before you start quoting, not after a customer tells you your invoice ended up in their junk folder.

Mailboxes, aliases and shared inboxes

A mailbox costs money; an alias usually does not. Understanding the difference saves real cash.

Give every person their own mailbox with their own name on it, so there is a clear record of who sent what. Then use aliases or shared mailboxes for the generic addresses — info@, sales@, accounts@ — rather than paying for a separate full account for each one.

Two rules worth following. First, avoid a catch-all address that accepts anything aimed at your domain; it is a magnet for spam and it hides genuine misaddressed mail that you would rather bounce back to the sender. Second, never let two people share one login. If someone leaves under a cloud, you need to know exactly what was sent from that account and by whom.

Stop the junk before it reaches anyone's inbox

Your email provider's built-in filtering will catch the obvious rubbish but not all of it. Layer a second filter on top if you receive a high volume of spam, and set it to quarantine suspicious messages for the first month rather than deleting them outright — that way you can check nothing legitimate is being caught.

Block dangerous attachment types at the gateway: executable files, scripts, and macro-enabled documents. These are the usual delivery method for ransomware and banking trojans aimed at small firms.

Then deal with the human side. Turn on an external sender warning so staff can see at a glance when a message came from outside the company, and make sure everyone knows the golden rule: any request to change bank details must be verified by phone, using a number you already had. Not the number in the email.

Access rules that protect you when staff move on

Turn on multi-factor authentication for every mailbox without exception, using an authenticator app or a hardware key rather than text messages where you can. Text codes can be intercepted; apps are far harder to beat. Keep administrator accounts separate from day-to-day ones, so a compromised mailbox cannot be used to change the whole system.

For phones and laptops, insist on a screen lock and make sure you can remotely wipe the device if it is lost. Remove access the moment someone leaves — within the hour, not within the month. That means disabling the account, forwarding mail to a manager, setting an out-of-office reply, removing them from distribution lists, and changing any shared passwords they knew.

Finally, check for forwarding rules that a departing or compromised account may have quietly set up, and review your list of administrators every few months. It is a ten-minute job that prevents a very expensive afternoon.

A simple order of work

  • Register the domain in the company's name and store the credentials securely.
  • Choose an email provider and set up MX, SPF, DKIM and DMARC before going live.
  • Create one mailbox per person, plus aliases or shared mailboxes for generic addresses.
  • Switch on multi-factor authentication and block risky attachment types.
  • Write a one-page email policy covering passwords, bank detail changes and leavers.
  • Test by sending to a few external addresses and checking the spam folders.

None of this is glamorous, and most of it takes an afternoon. But a properly set up inbox quietly earns its keep every week — in enquiries that arrive, invoices that get paid, and the confidence that your business name is showing up where it should.

3 comments