Illustrated article hero image for Email security and recovery.

Reading path

Email security and recovery

A calm order to work through mailbox compromise, MFA recovery, and persistence checks (forwarding rules, delegates, and third-party app access). If a business mailbox was compromised, start here.

Start here

Contain the mailbox before you investigate

The fastest way to stop ongoing harm is to reset access and remove persistence. Then you can review sign-in history, inbox rules, and deliverability records without racing an attacker.

Contain access Remove persistence Build evidence packet Check business impact Harden calmly

Microsoft 365 support NZ

Use this when the recovery work involves admin access, MFA reset paths, shared mailboxes, device sign-in, or tenant settings.

First choice

If the mailbox may still be compromised, use the incident checklist first

The deeper business email compromise checklist is the best first stop when there may be active access, hidden forwarding, payment fraud, or provider escalation ahead. Use the other pages after access is contained and the evidence trail is clear.

Use it during the incident

It covers password reset, session revocation, forwarding/rule checks, app access, recovery methods, and what to preserve before deleting suspicious messages.

Use it before provider tickets

It helps gather timeline notes, mailbox-control evidence, message evidence, domain/DNS evidence, and the details a provider or bank may ask for later.

Use this hub after containment

Once the incident is stable, continue through Microsoft 365 setup, DNS/email authentication, deliverability, and safer AI/data-handling boundaries.

Decision path

Separate routine support from recovery work

Not every email problem is a security incident. Some are normal Microsoft 365 setup, some are DNS or deliverability problems, and some need a recovery-first response because there may still be active access or hidden persistence. Pick the path that matches the failure mode before changing settings.

Suspected compromise

Use the incident checklist when there are suspicious sign-ins, unexpected forwarding, missing messages, payment-detail changes, or signs that someone else may still have access.

Account or admin recovery

Use Microsoft 365 support when the issue is MFA recovery, tenant admin access, mailbox rules, shared mailbox access, or a provider escalation packet.

New or inherited setup

Use Microsoft 365 setup when the work is baseline setup: admin ownership, MFA methods, Teams/SharePoint/OneDrive, mailbox basics, and first-week verification.

Bounce, spam, or spoofing symptoms

Use deliverability support when the issue is SPF, DKIM, DMARC, sender inventory, suspicious sending, spam placement, or bounce evidence.

DNS and routing control points

Use DNS and routing support when nameservers, MX records, TXT records, TTL, propagation, provider routing, or different network results are involved.

Wider IT continuity

Use the IT support reading path when the mailbox issue sits beside device access, remote support, Wi-Fi, fibre, or handover documentation.

Recovery stages

Work in stages so the incident stays understandable

A mailbox incident becomes much easier to manage when the first response is staged. Contain access, remove persistence, check business impact, then harden the setup. That order avoids losing useful evidence while still stopping the immediate problem.

Stage 1: lock down access

Reset the password, review MFA methods, sign out active sessions, check admin roles, and confirm there is a safe recovery path that does not rely on the compromised account.

Stage 2: remove persistence

Look for forwarding rules, hidden inbox rules, suspicious delegates, app passwords, OAuth consents, shared-mailbox access, and unexpected transport behaviour.

Stage 3: check business impact

Review recent invoices, payment-detail changes, customer replies, deleted mail, sent items, and any accounts that use the mailbox for password resets.

Stage 4: harden and document

Write down what changed, update recovery details, add MFA coverage, improve admin separation, and keep short notes for staff or future support.

Evidence notes

Keep a simple recovery timeline

Even for an SME, a short timeline helps with provider tickets, insurance questions, customer follow-up, and future prevention. The timeline does not need to be dramatic; it needs to be clear enough that another person can understand what happened.

What to record

Capture the first noticed symptom, affected accounts, sign-in locations or timestamps, rules removed, password resets, MFA changes, and provider ticket numbers.

What not to lose

Preserve suspicious messages, headers, forwarding destinations, transaction details, screenshots, and customer reports before deleting or overwriting them.

What to review later

Check whether the same password was reused elsewhere, whether billing or payroll details changed, and whether any third-party app still has mailbox access.

Use the path

Recover first, then harden what let the incident happen

The useful order is containment, persistence checks, evidence notes, then prevention. Do not start by changing every setting at once; that makes it harder to know what fixed the problem and harder to explain the event to staff, customers, or providers.

Contain access

Reset passwords, review MFA methods, revoke risky sessions, and confirm there is more than one safe admin recovery path.

Remove persistence

Check inbox rules, forwarding, delegates, app passwords, OAuth app consent, shared mailboxes, and suspicious transport behavior.

Record what changed

Write a short timeline with sign-in times, affected accounts, settings changed, customer impact, and provider ticket numbers.

Harden calmly

Improve MFA coverage, admin separation, SPF/DKIM/DMARC records, backup access, and staff reporting habits after the mailbox is stable.

Hardening

Reduce repeat compromise and spoofing risk

Once the mailbox is stable again, the next goal is to reduce repeat incidents and reputational damage: correct recovery methods, predictable admin ownership, and basic email authentication records.

After recovery

Turn the incident into a cleaner operating baseline

Once urgent access is contained, the next value comes from reducing repeat incidents: record ownership, schedule recurring checks, and make support handover evidence easier to find.

SME maintenance calendar

Use the maintenance calendar to schedule password, MFA, backup, domain, renewal, and mailbox hygiene checks after the incident is stable.

Tools hub

Use the tools hub for practical launch, maintenance, and planning checklists that make follow-up work repeatable.

Services hub

Use the services hub when the recovery notes reveal a broader setup, support, deliverability, website, or DNS handover problem.

Remote IT support NZ

Use remote support when the next step is evidence gathering, account checks, reversible changes, or a provider-ready handover note.

Related support

When you need hands-on recovery and documentation

These pages are the next step when a checklist finds a real identity, deliverability, or admin-ownership problem.

Context

Professional and project evidence

If you need current professional context or software project notes, start with the About page and Projects hub.