Family owned in Gilbert, AZ · Since 2015
Orca IT Solutions

Business Email

Email that lands, and cannot be faked

Most email problems come down to two things: authentication that was never configured, and mailboxes structured badly as the company grew. We fix both. Exchange Online, SPF, DKIM and DMARC done properly, shared mailboxes instead of shared passwords, and filtering that catches impersonation.

🛡 SPF, DKIM, DMARC Shared Mailboxes Done Right💰 Impersonation Protection Retention Policies

Overview

Email is your most attacked service, and usually the least configured

Every invoice fraud and business email compromise case starts in a mailbox. Either an attacker gets into yours, or they convince your customer that a message came from you. Both are addressable, and both are usually left open because the fixes are DNS records that nobody was assigned to write.

SPF, DKIM and DMARC are the three records that establish who is allowed to send email using your domain. SPF lists the servers permitted to send. DKIM adds a cryptographic signature that proves a message was not altered. DMARC tells receiving servers what to do when a message fails those checks, and gives you reports on who is sending as you. Without DMARC at enforcement, anyone can spoof your domain and your customers have no technical reason to doubt it.

Getting DMARC to enforcement without breaking things

The reason so many businesses sit at a permissive DMARC policy forever is that moving to enforcement can break legitimate mail from systems nobody remembered: the accounting package that sends statements, the marketing platform, the scheduling tool, the copier that emails scans. Rushing to a reject policy is how a company stops receiving its own invoices.

We run the process properly. Start in monitoring mode, collect reports for a few weeks, identify every legitimate sender, authorise each one correctly, then step through quarantine to reject. It takes weeks rather than an afternoon, and at the end your domain is genuinely difficult to impersonate. You can check where you stand today with emailcheck.orcait.io.

Mailbox structure, and the shared password problem

Almost every small business we assess has at least one generic mailbox, info, sales, billing, scheduling, with a password that four people know. It is a licensing cost you do not need to pay, an audit trail you do not have, and an offboarding problem waiting to happen.

Shared mailboxes solve this. They cost nothing extra in Microsoft 365, they are accessed through each person's own authenticated account, actions are attributable, and removing someone's access is one change rather than a password reset and a round of notifications. The same applies to distribution groups, resource mailboxes for rooms and equipment, and delegated calendar access.

Filtering does the rest. Microsoft's built-in protection is decent and gets considerably better once impersonation protection, safe links and safe attachments are configured, which frequently they are not. We tune policies for your business, add rules that flag lookalike domains, and make external sender warnings actually visible rather than a grey line people stop noticing after a week.

Retention and legal hold matter for regulated businesses and for anyone who has ever needed to produce an email thread from three years ago. We configure retention policies that match your obligations, and we back the tenant up with a third-party tool because Microsoft's native retention will not recover a mailbox a compromised account emptied. For migrations see Exchange and Exchange Online, and for the wider platform see Microsoft 365. More at email.orcait.io.

If your domain has no DMARC policy, anyone can send an invoice as you. Your customers will believe it.Orca IT, Gilbert AZ

What We Set Up

The full email build

Six components of a business email environment that behaves properly.

Platform

Exchange Online

Microsoft 365 mailboxes with the right licence tier per user, mobile access, and archiving where storage or retention demands it.

Auth

SPF, DKIM and DMARC

All three records built correctly, every legitimate sender authorised, and DMARC walked to enforcement without breaking mail flow.

Shared

Shared and resource mailboxes

Generic addresses accessed through individual logins, plus room and equipment mailboxes and delegated calendar permissions.

Filter

Advanced filtering

Impersonation protection, safe links and attachments, lookalike domain rules and visible external sender warnings.

Retention

Retention and hold

Policies matched to your regulatory and practical obligations, plus litigation hold where a business needs it.

Signature

Signatures and branding

Consistent company-wide signatures applied centrally, so every message looks the same regardless of device or client.

How It Works

From messy mail to a clean environment

01

Audit

We review DNS records, mailbox structure, licence assignment, filtering policy, mobile access and any shared credentials in use.

02

Authenticate

SPF and DKIM built correctly, DMARC deployed in monitoring mode, and every legitimate sending system identified from the reports.

03

Restructure

Shared mailboxes replace generic logins, groups and resource mailboxes created, retention policies applied, licences right-sized.

04

Enforce

DMARC stepped through quarantine to reject, filtering tuned against real traffic, and tenant backup put in place behind it.

Check your domain in a minute

Our free email authentication checker shows what your public records say about you right now.

Get a Free Assessment

Business email questions

What do SPF, DKIM and DMARC actually do?

SPF lists which servers may send email for your domain. DKIM cryptographically signs your messages so recipients can verify nothing was altered. DMARC tells receiving mail systems what to do when a message fails those checks and sends you reports about who is sending as you. Together they make spoofing your domain much harder.

Why does our email keep going to junk?

Most often because SPF or DKIM is missing, incomplete or lists a sender that no longer exists. Other causes include a shared IP with poor reputation, sending patterns that resemble bulk mail, or a domain with no sending history. We diagnose which applies rather than guessing.

Should generic addresses like info@ be user accounts?

No. Make them shared mailboxes, which cost nothing extra in Microsoft 365 and are accessed through each person's own authenticated login. You get attributable actions, no shared password, and instant removal of access when someone leaves.

Is Microsoft 365 filtering enough on its own?

The built-in protection is reasonable, and it gets considerably better once impersonation protection, safe links and safe attachments are properly configured, which we find disabled surprisingly often. For higher-risk businesses we add an additional filtering layer, but tuning what you already own comes first.

Do we need to back up our email if it is in the cloud?

Yes. Microsoft protects the platform and replicates data for their own resilience, but native retention will not save you from a compromised account emptying a mailbox, a departing employee deleting a folder, or ransomware encrypting synced files. Third-party tenant backup fills that gap.

How long does a mailbox migration take?

For a typical small business, a couple of weeks including preparation, with the actual cutover over a weekend. Mail is synchronised in the background beforehand, so the switchover is a DNS change and a final delta rather than a long outage. Our Exchange page covers migration in more detail.

Can you stop lookalike domain fraud?

We can make it much harder and much more visible. Impersonation protection flags messages claiming to be from your executives, mail rules catch domains that resemble yours or your key vendors, and external sender warnings alert staff. We also recommend an out-of-band verification rule for any change to payment details, because process catches what filtering misses.

What about email on phones?

Mobile access is standard, and it should be governed. We configure conditional access so mailboxes are only reachable from compliant devices where that suits you, enable remote wipe for lost phones, and enforce MFA on mobile sign-in. Basic Intune policies handle most small business requirements.

Make your domain hard to impersonate

Authentication records, filtering and mailbox structure, reviewed and fixed.

Talk to Your Pod

Talk to Your Pod

Check whether anyone can send email as you

We will review your domain records, filtering and mailbox structure and tell you exactly what is missing. Most businesses we check are one record away from being much harder to impersonate.

(602) 677-0779

Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced

Same-day response No long contracts Flat, honest pricing Five-star service

Get your free IT consultation

A few details and your pod gets right back to you, usually the same business day.

Spam-protected with a quick CAPTCHA. Your message goes straight to our team in Gilbert. We only use your details to help with your request. Never sold, never shared.