Skip to content

Home Topics Email Security Management Phishing defense

Email Security Management · Phishing defense

Phishing protection checklist for 2026

Short answer

A complete phishing protection checklist has 5 setup items and 2 things to audit against. Work through setup in order, then schedule a quarterly review.

Setup checklist#

  • ☐ Enforce DMARC p=reject so exact-domain spoofing fails.
  • ☐ Register lookalike domains or monitor them for registration.
  • ☐ Enable link rewriting and attachment sandboxing at the gateway.
  • ☐ Run quarterly simulations and make reporting a one-click action.
  • ☐ Apply BIMI so users learn what authentic mail looks like.

Audit checklist#

  • ☐ Confirm you are not: blaming users while leaving the domain unprotected.
  • ☐ Confirm you are not: allow-listing vendors broadly, which bypasses filtering.

Ongoing monitoring#

  • ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
  • ☐ Monthly: re-run the setup verification after any vendor or DNS change
  • ☐ Quarterly: full audit against this checklist

Frequently asked questions#

Does DMARC stop all phishing?

It stops exact-domain spoofing. Lookalike domains and display-name spoofing require additional controls.

Keep reading on Phishing defense