Exchange Online
Microsoft 365 mailboxes with the right licence tier per user, mobile access, and archiving where storage or retention demands it.
Business Email
Most email problems come down to two things: authentication that was never configured, and mailboxes structured badly as the company grew. We fix both. Exchange Online, SPF, DKIM and DMARC done properly, shared mailboxes instead of shared passwords, and filtering that catches impersonation.
Overview
Every invoice fraud and business email compromise case starts in a mailbox. Either an attacker gets into yours, or they convince your customer that a message came from you. Both are addressable, and both are usually left open because the fixes are DNS records that nobody was assigned to write.
SPF, DKIM and DMARC are the three records that establish who is allowed to send email using your domain. SPF lists the servers permitted to send. DKIM adds a cryptographic signature that proves a message was not altered. DMARC tells receiving servers what to do when a message fails those checks, and gives you reports on who is sending as you. Without DMARC at enforcement, anyone can spoof your domain and your customers have no technical reason to doubt it.
The reason so many businesses sit at a permissive DMARC policy forever is that moving to enforcement can break legitimate mail from systems nobody remembered: the accounting package that sends statements, the marketing platform, the scheduling tool, the copier that emails scans. Rushing to a reject policy is how a company stops receiving its own invoices.
We run the process properly. Start in monitoring mode, collect reports for a few weeks, identify every legitimate sender, authorise each one correctly, then step through quarantine to reject. It takes weeks rather than an afternoon, and at the end your domain is genuinely difficult to impersonate. You can check where you stand today with emailcheck.orcait.io.
Almost every small business we assess has at least one generic mailbox, info, sales, billing, scheduling, with a password that four people know. It is a licensing cost you do not need to pay, an audit trail you do not have, and an offboarding problem waiting to happen.
Shared mailboxes solve this. They cost nothing extra in Microsoft 365, they are accessed through each person's own authenticated account, actions are attributable, and removing someone's access is one change rather than a password reset and a round of notifications. The same applies to distribution groups, resource mailboxes for rooms and equipment, and delegated calendar access.
Filtering does the rest. Microsoft's built-in protection is decent and gets considerably better once impersonation protection, safe links and safe attachments are configured, which frequently they are not. We tune policies for your business, add rules that flag lookalike domains, and make external sender warnings actually visible rather than a grey line people stop noticing after a week.
Retention and legal hold matter for regulated businesses and for anyone who has ever needed to produce an email thread from three years ago. We configure retention policies that match your obligations, and we back the tenant up with a third-party tool because Microsoft's native retention will not recover a mailbox a compromised account emptied. For migrations see Exchange and Exchange Online, and for the wider platform see Microsoft 365. More at email.orcait.io.
If your domain has no DMARC policy, anyone can send an invoice as you. Your customers will believe it.Orca IT, Gilbert AZ
What We Set Up
Six components of a business email environment that behaves properly.
Microsoft 365 mailboxes with the right licence tier per user, mobile access, and archiving where storage or retention demands it.
All three records built correctly, every legitimate sender authorised, and DMARC walked to enforcement without breaking mail flow.
Generic addresses accessed through individual logins, plus room and equipment mailboxes and delegated calendar permissions.
Impersonation protection, safe links and attachments, lookalike domain rules and visible external sender warnings.
Policies matched to your regulatory and practical obligations, plus litigation hold where a business needs it.
Consistent company-wide signatures applied centrally, so every message looks the same regardless of device or client.
How It Works
We review DNS records, mailbox structure, licence assignment, filtering policy, mobile access and any shared credentials in use.
SPF and DKIM built correctly, DMARC deployed in monitoring mode, and every legitimate sending system identified from the reports.
Shared mailboxes replace generic logins, groups and resource mailboxes created, retention policies applied, licences right-sized.
DMARC stepped through quarantine to reject, filtering tuned against real traffic, and tenant backup put in place behind it.
Our free email authentication checker shows what your public records say about you right now.
SPF lists which servers may send email for your domain. DKIM cryptographically signs your messages so recipients can verify nothing was altered. DMARC tells receiving mail systems what to do when a message fails those checks and sends you reports about who is sending as you. Together they make spoofing your domain much harder.
Most often because SPF or DKIM is missing, incomplete or lists a sender that no longer exists. Other causes include a shared IP with poor reputation, sending patterns that resemble bulk mail, or a domain with no sending history. We diagnose which applies rather than guessing.
No. Make them shared mailboxes, which cost nothing extra in Microsoft 365 and are accessed through each person's own authenticated login. You get attributable actions, no shared password, and instant removal of access when someone leaves.
The built-in protection is reasonable, and it gets considerably better once impersonation protection, safe links and safe attachments are properly configured, which we find disabled surprisingly often. For higher-risk businesses we add an additional filtering layer, but tuning what you already own comes first.
Yes. Microsoft protects the platform and replicates data for their own resilience, but native retention will not save you from a compromised account emptying a mailbox, a departing employee deleting a folder, or ransomware encrypting synced files. Third-party tenant backup fills that gap.
For a typical small business, a couple of weeks including preparation, with the actual cutover over a weekend. Mail is synchronised in the background beforehand, so the switchover is a DNS change and a final delta rather than a long outage. Our Exchange page covers migration in more detail.
We can make it much harder and much more visible. Impersonation protection flags messages claiming to be from your executives, mail rules catch domains that resemble yours or your key vendors, and external sender warnings alert staff. We also recommend an out-of-band verification rule for any change to payment details, because process catches what filtering misses.
Mobile access is standard, and it should be governed. We configure conditional access so mailboxes are only reachable from compliant devices where that suits you, enable remote wipe for lost phones, and enforce MFA on mobile sign-in. Basic Intune policies handle most small business requirements.
Authentication records, filtering and mailbox structure, reviewed and fixed.
Talk to Your Pod
We will review your domain records, filtering and mailbox structure and tell you exactly what is missing. Most businesses we check are one record away from being much harder to impersonate.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.