Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Cybersecurity

Email protection for small businesses: phishing, impersonation and filtering

Email is still the most common way attackers reach a small business, because it does not require a technical flaw: you just have to write to someone. This page explains what actually protects a business inbox, how you stop an outsider from writing on behalf of your domain, and what OKTO Solutions puts in place for Quebec organizations.

Employee of a small business looking at a hacking alert on her laptop after an email attack

Email protection comes down to three things done together: filtering that blocks what arrives, domain authentication with SPF, DKIM and DMARC that prevents impersonation, and employees who can spot an unusual request. Taken separately, none of the three is enough. Managed as one service, fraudulent messages that reach the inbox become rare.

In brief

Email protection in three points

Email protection comes down to three things done together: filtering that blocks what arrives, domain authentication that prevents impersonation, and employees who can spot an unusual request. Taken separately, none of the three is enough.

What it is

Filtering of inbound messages, domain authentication with SPF, DKIM and DMARC, and user awareness, all managed as one service rather than a setting at a time.

Who it is for

Any organization that uses Microsoft 365 or Google Workspace and receives invoices, payment requests, employee files or personal information by email.

What it changes

Fraudulent messages that reach the inbox become rare, no one can write in your domain’s name any more, and a change of banking information is verified before it is paid.

The context

Why email is the first target of a small business

A small business publishes its email addresses everywhere: on its site, in signatures, on LinkedIn, at the bottom of invoices. An attacker does not need to break anything to reach you. What is left is to impersonate someone you already know.

Three families of attack keep coming back. Classic phishing lures an employee into entering their password on a fake Microsoft 365 page. Vendor or executive fraud asks for a bank account number to be changed on an otherwise authentic invoice. Mailbox takeover lets the attacker reply inside a real email thread, which is nearly impossible to spot with the naked eye.

What ties the three together: they do not exploit a software flaw, they exploit a work habit. An antivirus does nothing against them. You have to work on filtering, on domain identity and on people’s reflexes at the same time.

Threat monitoring on three screens, detection of a compromised mailbox

What we put in place

What we set up to protect your email

Protection is built in layers, and each layer catches what the previous one lets through. Here is what we set up for a client, in this order.

Inbound message filtering

What it is. Messages are analyzed before they reach the mailbox: attachments, links, sender reputation, and how closely the sending domain resembles yours or a known supplier’s.

What it does. The vast majority of fraudulent messages never land in front of the employee, so they never have to decide whether to click.

Domain authentication: SPF, DKIM and DMARC

What it is. SPF publicly declares which servers are allowed to send email on your behalf. DKIM signs every outgoing message. DMARC tells receiving servers what to do when the signature does not match, and returns a report.

What it does. An outsider can no longer write to your clients using your address. It is the only measure that protects people outside your organization.

Multi-factor authentication on every mailbox

What it is. A second factor is required at sign-in, and the old protocols that let attackers bypass it are turned off.

What it does. A password stolen on a fake page is no longer enough to get into the mailbox.

Mailbox rule monitoring

What it is. Redirect and auto-delete rules are inventoried, and the creation of a new rule by an account is flagged.

What it does. The first move of an attacker inside a mailbox is to create a rule to hide their tracks. We catch it right away.

Tagging of external messages

What it is. A visible banner is added to messages coming from outside the organization.

What it does. An employee receiving an urgent request from the president can see at a glance that the message did not come from inside.

Awareness and phishing simulations

What it is. The OKTO vCIO module includes four phishing simulations per year, with follow-up on people who clicked and a reminder of the right reflexes.

What it does. The reflex holds over time instead of fading three weeks after a one-off training session.

Detection

How to tell if a mailbox has already been compromised

A compromised mailbox does not set off an alarm. It shows up as details that no one looks at. If you recognize one of the signs below, treat it as an incident, not as a curiosity.

  • Messages sent from your address that leave no trace in your Sent items
  • A mailbox rule no one created, that automatically moves or deletes certain replies
  • Successful sign-ins from a country where no one in the company works
  • A supplier confirming they received a new banking detail from you that you never sent
  • Colleagues receiving a reply from you that you never wrote
  • A password reset request no one asked for
  • A client replying inside a thread you do not recognize

How it unfolds

How the rollout works at your organization

The work happens in four steps, and nothing is tightened before it has been observed. A DMARC rule set too quickly breaks newsletters, appointment reminders and automated invoices.

  1. Assess the current stateWe read your DNS configuration, your transport rules, the state of multi-factor authentication and the sign-in history of the mailboxes. You get the list of what is already in place and what is missing, before we propose anything.
  2. Secure the domain’s identitySPF, DKIM and DMARC are put in place in order, DMARC first in observation mode. We identify every service that already sends email in your name, such as newsletters, accounting software or the site’s contact form, before tightening the rule.
  3. Close weak access pathsMulti-factor authentication on every mailbox, removal of legacy authentication protocols, review of existing forwarding rules, shared mailboxes and forgotten service accounts.
  4. Maintain and measureDMARC reports are reviewed every month, new sending sources are declared as they appear, and employees receive phishing simulations to keep the reflex sharp.

Email is the front door for ransomware: our ransomware protection and our cybersecurity services cover both fronts, and secure remote work closes the accesses that sit outside the office. This service is delivered across Quebec, from our office in Trois-Rivières, in the Mauricie, in Montreal and around Quebec City. Further reading: SPF, DKIM and DMARC explained, phishing simulations and QR code scams.

Questions and answers

Frequently asked questions about email protection

Doesn’t Microsoft 365 already protect my email?
Only in part. Microsoft 365 filters spam and some malicious messages, but it does not configure SPF, DKIM and DMARC for your domain, it does not enforce multi-factor authentication, it does not monitor suspicious mailbox rule creation, and it does not train anyone. These settings exist in the portal: they do not turn themselves on. Our work is precisely to set them, monitor them and keep them up to date.
What is DMARC, in plain terms?
DMARC is a public rule attached to your domain name that tells email servers around the world what to do with a message that claims to come from you but does not have the right signature: let it through, put it in quarantine, or reject it. Without DMARC, anyone can write to your clients displaying your address. With DMARC in reject mode, the attempt is blocked before it even arrives.
Does this replace training my employees?
No, and no training replaces filtering and authentication either. The three complement each other. A well-configured technical layer removes almost all the noise, so what still reaches employees is worth their attention. Training then teaches them to slow down at the right moments: a change of banking coordinates, an unusual payment request, an unforeseen shared document.
Do we still need this if we use Google Workspace instead of Microsoft 365?
Yes. The principles are the same: filter what comes in, prove that your outgoing messages are legitimate, protect the accounts. Only the console changes.
How long does the DMARC observation phase take?
Between four and six weeks in observation, then quarantine, then reject, once every legitimate sender has been identified. Rushing this step is what breaks appointment reminders and automated invoices for your clients. We watch the reports and turn each mode on only when it is safe.
Does this fit with Law 25?
Yes. Email protection is one of the reasonable security measures a Quebec organization can point to when it is asked how it handles personal information. It does not replace a legal review of your policies, but it addresses one of the most common entry points for a confidentiality incident. See our Law 25 compliance page.
Where do you start if we have nothing in place?
By an inventory. Our cybersecurity audit establishes what protects your email today, who has access to the mailboxes, and which vendors are used to send in your name. Email protection then becomes the first fix.

Take a serious look at your email

We look at your inbound filtering, the state of SPF, DKIM and DMARC, and the current settings of your accounts, and we give you a short list of what to fix, in order of priority.