Setup checklist#
- ☐ Enforce phishing-resistant MFA (FIDO2 keys or passkeys) for admins and finance.
- ☐ Review third-party OAuth grants monthly and restrict user consent.
- ☐ Alert on impossible-travel logins and mass downloads.
- ☐ Have a documented response: revoke sessions, reset, audit rules and forwards, notify affected parties.
Audit checklist#
- ☐ Confirm you are not: sMS-based MFA for high-value accounts.
- ☐ Confirm you are not: not checking forwarding rules after remediation.
Ongoing monitoring#
- ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
- ☐ Monthly: re-run the setup verification after any vendor or DNS change
- ☐ Quarterly: full audit against this checklist
Frequently asked questions#
What are signs of a compromised email account?
Unknown sent items, new forwarding rules, missing mail, login alerts from unfamiliar locations, and contacts reporting odd messages.