Additional Spam and Phishing Protection — Exchange Online Email Security
Additional Spam and Phishing Protection is a service for organizations using Exchange Online that are experiencing spam, phishing, or email spoofing issues. IT Partner implements DKIM and DMARC, assigns Microsoft Defender for Office 365 (formerly Exchange Online Advanced Threat Protection) licenses to users, checks and corrects the SPF record if needed, and configures a country block list.
What this engagement is
Attackers continue to develop ways to bypass email protection, including targeted phishing methods that may exploit employee negligence or gaps in spam and phishing protection. This service helps organizations using Exchange Online start using modern protection solutions, such as Microsoft Defender for Office 365 (formerly Exchange Online Advanced Threat Protection), which helps protect employees from viruses and malware. DKIM and DMARC setup significantly reduces the ability to send phishing from your company’s domain, including messages sent to your own addresses on behalf of company employees. IT Partner will also check domain settings and make changes if necessary. Blocking mail receipt based on regional data can also be enhanced by eliminating the possibility of attacks from countries with increased viral activity. The plan may vary depending on your needs.
Success criteria
What you receive
How the work unfolds
Confirm project contacts, the in-scope domains, current mail protection settings, licensing readiness, and the delivery schedule.
Implement DKIM and DMARC, review and correct the SPF record if needed, assign Microsoft Defender for Office 365 licenses to users, and configure the country block list.
Verify mail flow and authentication results after the changes and fix any issues found within the project scope.
Review results with your team, confirm spam and phishing volumes are trending down, and close out the engagement.
Prerequisites
Who does what
IT Partner
- Implement DKIM
- Implement DMARC
- Assign Microsoft Defender for Office 365 licenses to users
- Check and correct SPF record, if needed
- Configure the country block list
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner
- Coordinate any outside vendor resources and schedules
- Perform changes to internal and external DNS, as required
- Configure all network equipment, such as load balancers, routers, firewalls, and switches
- Review and approve engagement deliverables in a timely manner
What's not included
Limitations & technical notes
Frequently asked questions
What is the Additional Spam and Phishing Protection service?
Additional Spam and Phishing Protection is a 5-day IT Partner service for organizations using Exchange Online that are experiencing spam, phishing, or email spoofing issues. IT Partner implements DKIM and DMARC, checks and corrects SPF if needed, assigns Microsoft Defender for Office 365 (formerly Exchange Online Advanced Threat Protection) licenses to users, and configures a country block list to strengthen email protection.
Who is this service designed for?
This service is designed for organizations that use Exchange Online and need additional protection against spam, phishing, malware-related email threats, or spoofing of their company domain. Exchange Online is a prerequisite, because the engagement is based on configuring protection features and licensing within that environment.
What is included in the service?
The service includes DKIM implementation, DMARC implementation, SPF record review and correction if needed, assignment of Microsoft Defender for Office 365 licenses to users, and configuration of a country block list. These deliverables are intended to reduce spam and phishing exposure while keeping mail flow working.
What is not included in the service?
Microsoft Defender for Office 365 licenses (formerly Exchange Online Advanced Threat Protection) are not included in the service price. IT Partner assigns the licenses to users as part of the engagement, but the customer must have or obtain the required licenses separately.
How long does the engagement take?
The stated duration for Additional Spam and Phishing Protection is 5 days. The plan may vary depending on the organization’s needs, so exact scheduling and sequencing should be confirmed with IT Partner during the kickoff.
How much does the service cost?
The service is $800 per project, quoted fixed-price in writing before work begins. The price covers the defined implementation scope; Microsoft Defender for Office 365 licenses are not included.
Will this service stop all spam and phishing emails?
No filtering service can guarantee that every unwanted or malicious email is blocked — attackers continuously change tactics. This engagement meaningfully decreases the volume of spam and phishing messages by implementing the planned protection features and reducing risk within the defined scope.
How do DKIM and DMARC help protect our domain?
DKIM and DMARC help reduce the ability of attackers to send phishing messages that appear to come from your company’s domain. This is especially valuable for limiting spoofed messages, including messages that may appear to be sent to your own users on behalf of company employees.
Does the service include SPF configuration?
Yes, IT Partner checks the SPF record and corrects it if needed. SPF is part of the domain email authentication review, while the client is responsible for performing required internal or external DNS changes.
Will the service disrupt mail flow or cause downtime?
The stated success criteria include that mail workflow is not broken. However, because DNS, authentication, and protection settings can affect mail behavior, IT Partner verifies the implementation and fixes issues as part of the engagement.
What does the country block list do?
The country block list is configured to enhance mail protection by blocking mail receipt based on regional data. This can help reduce exposure to attacks from countries identified as having increased viral activity, within the limits of the configured protection approach.
What does the client need to provide before or during the service?
The client must coordinate internal resources and staff schedules, provide a dedicated point of contact, coordinate any outside vendor resources, and review and approve deliverables in a timely manner. The client is also responsible for DNS changes and for configuring network equipment such as load balancers, routers, firewalls, and switches if required.