Business email setup and problems
Email on your own domain is the cheapest credibility a small business can buy, and the first thing to break when the DNS behind it is wrong. Most email problems we see are records that were never set, or were set twice.
What we do
- Business email on your own domain, set up from scratch
- SPF, DKIM and DMARC records done correctly
- Moving mailboxes off shared web hosting
- Mail going to junk, or not arriving at all
- Spam filtering, quarantine and safe senders
- Mailbox compromise clean-up and lockdown
Email on your own domain
A business running on a free webmail address is telling every customer that it might not be here next year. Email on your own domain costs very little, keeps working when a staff member leaves, and means you own the address rather than borrowing it.
The important part is where the mailboxes live. Your domain name, your website hosting and your email can all sit with different providers, and for most small businesses they should. Mailboxes belong on a proper mail platform such as Microsoft 365, the website belongs with a web host, and the domain sits in your own account in the business name.
That last point causes more grief than anything else here. If the domain sits in a former web designer's account, you do not control your own email, and sorting it out later is slow. We can usually recover a domain, but it is cheaper to hold it properly from the start. Our websites and domains page covers that side.
SPF, DKIM and DMARC without the jargon
These three are records in your domain's DNS. They exist because the email system was built without any way to check that a sender is who they claim to be, and they are what stops somebody sending invoices as you.
SPF is a published list of the servers allowed to send mail using your domain. Receiving servers check the list. It breaks in two common ways: a business signs up to a new mail service and nobody adds it to the list, or somebody adds a second SPF record, which is not allowed and makes both fail. There is also a limit on how many lookups the record can chain through, and busy records quietly exceed it.
DKIM adds a signature to every message you send, which the receiving server checks against a key published in your DNS. It proves the message came from your mail system and was not altered on the way. DMARC then tells receiving servers what to do when a message fails those checks, and can send you reports about who is sending as your domain. The sensible path is to start DMARC in reporting mode, look at what turns up, then tighten it.
Why mail on shared web hosting is a risk
Cheap web hosting usually includes mailboxes, and for years that is how small businesses did email. The problem is that the mail server is shared with hundreds of other sites, and their behaviour becomes your reputation. One compromised site sending spam can get the whole server blacklisted, and your quotes stop arriving for reasons you cannot see or fix.
There are other limits. Mailbox quotas are usually small, so mail gets deleted to make room, and multi-factor sign-in is often unavailable. Phones and Outlook connect over protocols with no protection beyond a password.
The two services are also tied together in a way that does not help you. If the website is hacked, the mail sitting on the same hosting account is part of what has been exposed, and you are dealing with two problems instead of one.
Moving mailboxes to a proper platform is a job we do regularly, and mail history comes across with it. The website can stay exactly where it is.
Spam filtering that does not eat real mail
Good filtering is a balance. Filtering set too hard quietly swallows a customer's purchase order, which costs more than the spam does. Set too soft and staff stop reading their own inbox.
The workable arrangement is filtering that quarantines rather than deletes, a daily summary of what was held so anyone can release a message themselves, and a short list of approved senders for the suppliers and systems that keep getting caught. Anything sending from your own systems, such as a scanner or job management software, needs to be set up properly so it does not look like forged mail.
It is also worth knowing what filtering cannot do. A message from a real person at a real supplier whose mailbox has been taken over will pass every check, because technically it is legitimate. That is why the rule about confirming changed bank details by phone matters more than any filter.
Signatures, phones and the small stuff
Signatures are worth doing once, with the same layout across the business, a real phone number and no enormous image that arrives as an attachment. Set centrally, they stay consistent as people come and go.
Phones need thought rather than a rushed setup on someone's personal handset. The proper mail app with multi-factor sign-in is safer than a generic mail client using an old protocol, and it means access can be removed remotely when someone leaves rather than relying on them to delete the account.
Then there are the small things that cause real confusion: out-of-office messages still running in March, a shared mailbox nobody watches, rules filing a customer's mail into a folder nobody opens, and old aliases pointing at someone who left. We check those when we set an account up, because each one eventually costs a sale.
If a mailbox has been compromised
The signs are sent items you did not send, replies to conversations you were never part of, customers saying they received something odd, or a new rule moving mail into an obscure folder. That last one is a favourite, because it hides the replies while the attacker works.
The order matters. Change the password from a machine you trust, then sign out every active session, because changing a password alone leaves an attacker's session running. Turn on multi-factor. Then check for forwarding rules, mailbox rules and delegate access they may have added, and check that the recovery phone number and address are still yours.
After that comes the part people skip: work out what was sent and what was read while they were in. If any invoice went out during that window, ring the customers on a number you already had and confirm the bank details. Keep the evidence, and report it through ReportCyber at cyber.gov.au. We can do the clean-up remotely at $179 per hour, and it is worth doing properly rather than just changing a password and hoping.
Typical jobs
A typical job: a business whose quotes stopped arriving at customers after signing up to a new marketing service. The new service was never added to the SPF record, so half their mail was failing checks. We correct the record, add DKIM signing, and put DMARC into reporting mode to see what else is sending as the domain.
A typical job: five mailboxes on the same shared hosting account as the website, full to their quota, with no multi-factor available. We move the mailboxes to a proper platform with the history intact, leave the website where it is, and update only the mail records.
A typical job: an accounts mailbox taken over after a fake sign-in page, with a rule quietly moving supplier replies into the deleted items. We reset the password, revoke the sessions, remove the rules, turn on multi-factor, and work out which invoices went out while the attacker had access.
Questions
Why is our email going to everyone's junk folder?
Someone is sending emails that look like they are from us. Can you stop it?
Can we keep our website where it is and move only the email?
How long does an email migration take?
A staff member clicked a link and typed their password. What now?
Business email: work we have done

Serving Mount Druitt and 12km around
Ready to get it sorted?
Call for a chat about what you need. Onsite and business work is quoted per job or per visit.
