A structured, 40-point checklist to evaluate your enterprise email security posture across seven domains — from authentication foundations through compliance and governance. This checklist is designed as a gap analysis tool, not an audit instrument. Its purpose is to surface specific areas where your enterprise email security program may have unaddressed risks.
Foundation: Authentication
- SPF records configured and enforced for all sending domains
- DKIM signing enabled for all outbound email
- DMARC policy configured at p=quarantine or p=reject
- DMARC reports being monitored and acted upon
- All subdomain email sending reviewed and secured
Inbound Threat Detection
- Secure Email Gateway (SEG) or equivalent inbound filtering deployed
- URL scanning active for all inbound links
- Attachment sandboxing enabled for all file types
- Anti-spoofing controls for executive names and domains
- External email warning banners enabled
- Newly registered domain blocking or elevated scrutiny configured
Advanced AI & Behavioral Detection
- Behavioral baselining active for all employees (not just executives)
- NLP-based BEC detection deployed (evaluates content intent, not just links)
- Zero-day phishing detection capability verified with test scenarios
- Internal east-west email scanning enabled
- Account takeover detection active for unusual login patterns
- Supply chain / vendor communication baselining configured
- Explainable AI verdicts available in the security console
Mobile & Cross-Channel Coverage
- Mobile device policy enforced for all users accessing corporate resources
- SMS/smishing protection evaluated for high-risk users
- QR code scanning protection deployed (or evaluated)
- Browser extension or on-device AI active for high-risk user populations
- Collaboration tool (Teams/Slack) link scanning evaluated
Response & Remediation
- Automated inbox remediation capability deployed (retrospective sweep)
- Incident response playbook documented and tested
- Phishing reporting button deployed in email client
- Phishing reports triaged within SLA (target: <4 hours)
- Compromised account response procedure documented
- Post-incident communication templates prepared
Governance & Measurement
- Phishing simulation program running quarterly
- Simulation click rate tracked and trending downward
- Monthly security metrics reported to leadership
- Threat blocked count tracked by channel and threat type
- False positive rate monitored and within acceptable threshold (<2%)
- Vendor security assessment process documented
Compliance & Sovereignty
- Data residency requirements documented and vendor compliance verified
- On-premises or air-gapped deployment evaluated for regulated data
- Email retention and archiving compliant with applicable regulations
- Breach notification process documented per regulatory requirements
Interpreting Your Score
35–40 checks completed indicates a Mature Posture. 20–34 indicates a Developing Posture. 0–19 indicates an At-Risk Posture. The goal is not a perfect score — it is honest visibility into where investment and attention are most needed.
If your organization scores below 20, prioritize the Authentication and Inbound Detection sections before investing in advanced AI capabilities — without DMARC enforcement and basic inbound filtering, sophisticated behavioral AI is working against a structural weakness. If you score 20–34, your biggest gains are likely in Advanced AI Detection and Mobile Coverage. If you score 35+, focus on Response and Governance — a mature detection posture is diminished by slow response or inadequate measurement.
Top Gaps Most Enterprises Miss
Based on DefenceNet's enterprise security assessment process, these checklist items represent the most common gaps in organizations that believe they have mature email security postures:
- Internal east-west email scanning: almost universally absent until explicitly deployed. Most SEGs only scan inbound traffic.
- Behavioral baselining for non-executive users: many programs apply VIP protection only to the C-suite, leaving finance teams, IT admins, and operations staff — frequent targets — unmonitored.
- Zero-day verification: organizations assume their tools can detect zero-day threats without validating this claim with actual test scenarios against newly registered, untagged domains.
- Mobile channel coverage: virtually no enterprise email security program extends systematically to the SMS channel accessed by employees on personal devices.