Skip to content

Email security & Defender Sécurité courriel et Defender

The "security baseline" in Plus has a name. Here’s what it is.

Plans names a security baseline and a regular review inside Plus without ever spelling out the tools behind it. This page does: mailbox-level threat protection (Microsoft Defender for Office 365 where a client’s licence already includes it, or the equivalent filtering controls in whatever email platform they run), sender-authentication records that stop spoofed mail, and short awareness nudges when a real attempt gets through — named as their own resellable line, not a vague review bullet.

Your side

Your practice

You set the baseline you’re targeting, decide who signs off on a quarantine release or a blocked-sender override, and tell your client what "security basics" means before they buy it.

Our side

Delivery team

We check the agreed email-security settings against that baseline, triage what the filtering layer flags, and send a short nudge to a user only when a real attempt got through — not a running compliance score.

Baseline check and awareness nudges

For a client whose email already runs through Microsoft 365 or another hosted platform, but whose spam/phishing filtering, sender-authentication records, and end-user awareness have never been checked against an agreed baseline.

What we need first

The baseline you want enforced (what Defender or the platform’s native filtering should already catch), who approves releasing a quarantined message or adding a sender override, and whether awareness nudges should go to the user directly or through your practice first.

What’s included

  • Checking mailbox-level filtering and threat-protection settings against the agreed baseline
  • Reviewing sender-authentication records (SPF, DKIM, DMARC) tied to the domains in scope
  • A short, plain-language nudge to a user after a real phishing or spoofing attempt reaches them

Handled separately

  • Choosing or licensing the email platform, or paying for a Defender tier the client doesn’t already hold
  • Releasing a quarantined message or approving a sender override without the named approver’s sign-off
  • Formal security-awareness training with completion tracking or a compliance certificate

What you get: A baseline that’s actually been checked instead of assumed, and a small number of real attempts turned into short user-facing nudges — not a bigger alert feed nobody reads.

What we hand back: A baseline review note naming what was checked, what drifted, and a requested decision — the same format as every other review on this site.

What "security basics" has to define before it’s priced

Which tier is actually licensed

Defender for Office 365 exists at more than one licence level, and some tenants have none of it — only the mailbox platform’s native filtering. What we can check depends on what’s actually turned on, not on what the plan name implies.

Who approves a quarantine release

Releasing a held message can also release whatever made it suspicious. Name one approver for that call before the first quarantine ticket arrives, not while a user is waiting.

What counts as a nudge-worthy event

Sending a note to a user after every filtered spam message would train them to ignore it. Agree on the threshold — a real click, a reported attempt, a targeted spoof — before the first nudge goes out.

Domains actually in scope

Sender-authentication records apply per domain. A client with a second brand domain or a legacy domain still receiving mail needs that named explicitly, or it sits outside the baseline by default.

What this line doesn’t include

  • 24/7 SOC-style monitoring or a guaranteed detection/response time
  • A security certification, audit opinion, or cyber-insurance attestation
  • Incident response for a confirmed compromise — that’s an escalation, not a baseline review
Discuss email security scope

Straight answers on email security

Does this mean we can call ourselves a security company now?

No. This is a baseline check and awareness nudges inside the Plus review line, not a security practice or SOC. Describe it to your client as what it actually is: checked settings and short nudges, not continuous monitoring.

What happens if a client gets phished anyway?

It’s reported through the same escalation path as any other request. A confirmed compromise is treated as an incident with a named approver deciding next steps — not folded quietly into the next baseline review.