Skip to content

Home Topics Email Security Management Mailbox account takeover

Email Security Management · Mailbox account takeover

Email account takeover and CASL compliance in the Canada

Short answer

CASL requires express or implied consent before sending and identification of the sender in every message. Email account takeover supports compliance by making sender identity verifiable and recipient choices enforceable.

What CASL requires#

CASL requires express or implied consent before sending and identification of the sender in every message.

What email account takeover is#

Account takeover (ATO) is unauthorized access to a legitimate mailbox, typically via phished credentials, password reuse, or OAuth consent phishing.

Why it matters#

A taken-over mailbox bypasses every authentication control and becomes a launchpad for BEC and internal phishing.

How email account takeover supports CASL compliance#

Regulators and recipients need to identify who sent a message and trust that opt-out mechanisms work. Email account takeover contributes by a taken-over mailbox bypasses every authentication control and becomes a launchpad for BEC and internal phishing.

Implementation steps#

  1. Enforce phishing-resistant MFA (FIDO2 keys or passkeys) for admins and finance.
  2. Review third-party OAuth grants monthly and restrict user consent.
  3. Alert on impossible-travel logins and mass downloads.
  4. Have a documented response: revoke sessions, reset, audit rules and forwards, notify affected parties.

Frequently asked questions#

What are signs of a compromised email account?

Unknown sent items, new forwarding rules, missing mail, login alerts from unfamiliar locations, and contacts reporting odd messages.

Keep reading on Mailbox account takeover