Email Security Checklist for SMEs
Protect your email from phishing, spam, and data leaks with this comprehensive checklist.
Purpose
Email is the #1 attack vector for cyberattacks. 90% of data breaches start with a phishing email. This checklist hardens your email security posture.
Technical Controls
- SPF record configured and published
- DKIM signing enabled
- DMARC policy set to reject or quarantine
- External email warning banner enabled
- Attachment blocking for dangerous file types (.exe, .js, .vbs)
- Auto-forwarding to external addresses disabled
User Controls
- Phishing awareness training completed by all users
- Report phishing button enabled in email client
- Regular phishing simulation exercises
- Clear process for reporting suspicious emails
Related reading
Clean Desk Policy Template
Protect sensitive information with a clean desk policy. Simple rules that prevent data leaks.
Read moreResourceSecurity Incident Report Template
A standardised template for documenting and reporting security incidents — from phishing attempts to data breaches.
Read moreResourceConfidentiality Agreement Template
Protect company secrets with a clear confidentiality agreement covering trade secrets, client data, and IP.
Read moreArticleData Security Policy Template for Indian SMEs
A practical data security policy template that addresses DPDP Act compliance, access control, and incident response for small businesses.
Read moreArticleNetwork Security Checklist for SMEs
Essential network security checklist covering firewall, WiFi, VPN, and access controls.
Read morePut this into practice with workro desk.