Setting Up Business Email Properly

Email is the most critical system in most businesses and the one most often set up casually and never revisited.
Use your own domain
Free consumer email addresses for business correspondence look unprofessional and, more importantly, mean the address is not yours to control.
A domain-based address moves with you between providers and can be reassigned when staff change.
Role addresses — sales, accounts, support — should be aliases or shared mailboxes rather than tied to an individual, so that correspondence survives that person leaving.
Authentication is now essential
SPF, DKIM and DMARC records establish that mail claiming to come from your domain is legitimate.
Major providers tightened enforcement in 2024, and mail without proper authentication is now routinely filtered or rejected rather than merely scored down.
Without them, your invoices and quotes may silently not arrive, and your domain can be spoofed by anyone.
DMARC reporting also reveals who is sending mail using your domain, which frequently uncovers legitimate systems nobody documented as well as abuse.
Access control and departures
Every person should have their own account. Shared mailboxes accessed with a single password make activity unattributable and access impossible to revoke individually.
Multi-factor authentication on every account, without exception. Email is the reset mechanism for every other system, so compromise of email is compromise of everything.
Have a documented offboarding process: change the password, convert the mailbox to a shared one or set forwarding, revoke device access, and remove the person from distribution lists.
Retaining a departed employee's mailbox in some form matters, because correspondence and contractual history live there.
Retention and backup
Providers ensure the service is available; they are not a backup of your data. Deleted items have limited retention windows, and an account compromise or accidental deletion can lose correspondence permanently.
Third-party backup for business email exists for exactly this reason and is inexpensive.
Set retention policies deliberately rather than accepting defaults, taking account of any regulatory obligation to retain records.
Practical hygiene
Configure external sender warnings, which help staff spot impersonation attempts.
Establish a written rule that bank details are never changed on the basis of an email alone, verified only by phoning a number you already held. This single policy prevents the most costly form of business email fraud.
Review who has administrative access to the email system periodically, and ensure more than one person does, so a single absence does not lock the business out.
Article Was Generated By AI.