Spam Filtering & Blacklists

Email Security Best Practices: Defending Against Modern Email-Based Attacks

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (9 sections)

Email is still the easiest way into a business. A convincing message can steal a password, redirect a payment or plant malware, and a stolen mailbox can then be used to attack your own customers. This guide covers the practical defences a small business can put in place: protecting mailbox logins, authenticating your domain, encrypting mail, spotting fraud and handling a compromise.

Key takeaways

Protect every mailbox with a long, unique password and two-factor authentication where your email service offers it. Publish SPF, DKIM and a DMARC policy so others cannot easily send mail as your domain. Always connect mail apps over SSL/TLS, keep spam filtering on, and verify every request to change bank details by phone on a number you already know. If a mailbox is compromised, change its password, check its forwarders and filters, and tell your email provider straight away.

1. The attacks that actually hit small businesses

AttackWhat it looks likeMain defence
PhishingA "your mailbox is full" or "shared document" email linking to a fake login pageCheck links before clicking; two-factor authentication
Invoice and payment fraud (BEC)A supplier or director "changes bank details" or asks for an urgent transferVerify by phone on a known number; a two-person payment rule
SpoofingMail that shows your own domain in the From line but was sent by someone elseSPF, DKIM and DMARC on your domain
Account takeoverSomeone logs in with a stolen or reused password and sends as youUnique passwords, two-factor authentication, alerts on new devices
Malicious attachmentsAn "invoice" archive or an Office file asking you to enable macrosNever enable macros from email; keep your computer's security updates on

Most of these attacks need no technical skill; they rely on a busy person clicking or paying without checking. So the defences are part technical, part habit.

2. Protect every mailbox login

A mailbox password protects more than the inbox. Whoever has it can reset your other accounts, read invoices and send mail your customers will trust.

  • One password per mailbox, long and random, stored in a password manager. See the best password managers for personal and business use.
  • Two-factor authentication wherever the service offers it: your email service, your hosting control panel and your Domain India client area. See how to enable two-factor authentication.
  • App passwords for mail apps where your provider supports them, so a lost phone can be cut off without changing the main password.
  • Change passwords immediately when a staff member leaves or a device is lost, and remove old devices from the account.
  • Use IMAP over SSL/TLS. For email included with Domain India hosting, use port 993 for IMAP and port 465 (SSL/TLS) or 587 (STARTTLS) for sending. Ports 110 and 143 without encryption send the password in plain text; avoid them. The full settings are in email server details and SSL settings.

3. Authenticate your domain: SPF, DKIM and DMARC

These three DNS records let receiving servers check that mail claiming to come from your domain really does.

SPF
A TXT record listing the servers allowed to send mail for your domain. A domain may have only one SPF record.
DKIM
A digital signature added to each message, checked against a public key in your DNS. It proves the message was not altered.
DMARC
A TXT record at _dmarc that tells receivers what to do when a message fails SPF and DKIM for your domain, and where to send reports.

A typical DMARC record to start with:

text
v=DMARC1; p=none; rua=mailto:[email protected]

Start with p=none to collect reports, fix any genuine sender that fails, then move to p=quarantine and finally p=reject. Jumping straight to reject can bounce your own invoices and password emails.

On Domain India hosting: in cPanel, Email › Email Deliverability checks SPF and DKIM for each domain and offers to install the suggested records. cPanel signs mail with the DKIM selector default, and most cPanel zones already carry a p=none DMARC record, so edit it rather than adding a second one. DirectAdmin uses the selector x; see how to check and manage DKIM in DirectAdmin. The step-by-step guide is setting up DMARC.

Add every service that sends as you

Your newsletter tool, billing system, CRM and website forms may all send mail from your domain. Each one must pass SPF or DKIM for your domain before you tighten DMARC, or its mail will start landing in spam or bouncing.

4. Encrypt mail in transit, and when it matters, end to end

In transit. TLS encrypts the connection between your mail app and the server, and between mail servers. Using the SSL/TLS ports above covers your side. Between servers, most large providers use TLS when the other side supports it; MTA-STS is an optional DNS and web policy that asks senders to insist on it.

End to end. TLS does not protect a message once it sits in a mailbox. For confidential documents, use S/MIME (certificates built into Outlook and Apple Mail) or OpenPGP (for example in Thunderbird), or share the document through a secure link with a separate password. Both people need to set it up, so most businesses keep it for sensitive exchanges.

5. Spot phishing and payment fraud

Check the real sender
Look at the full address, not just the display name. Watch for one-letter differences in the domain.
Hover before you click
The link text and the real destination often differ. Log in by typing the site's address yourself.
Distrust urgency
"Pay today", "account closes in 24 hours" and "keep this confidential" are pressure tactics.
Verify money requests
Any change of bank details or unusual payment gets a phone call to a number you already have, never one from the email.

Report phishing in your mail app with its report or junk button. In India you can also report cyber fraud at the national cybercrime portal, cybercrime.gov.in, or the 1930 helpline.

6. Keep spam and malware out

Email included with Domain India cPanel hosting runs SpamAssassin, and spam filtering with a Spam folder is already on for almost every account. Check the Spam folder now and then, and tune the threshold if genuine mail is caught; see SpamAssassin and the Spam Box.

On every computer that reads mail:

  • keep the operating system, browser and Office updated;
  • never enable macros in a document that arrived by email;
  • treat unexpected archives (.zip, .rar, .iso) and "invoice" links with suspicion, even from a known contact, whose mailbox may have been hijacked.

7. Stop your website becoming a spam source

A contact form without spam protection, or a hacked WordPress site, can send thousands of messages from your hosting account and get your domain blocklisted. Protect every form with a CAPTCHA or honeypot field, never let a visitor choose the recipient or edit the headers, and keep WordPress plugins updated. Domain India cPanel hosting limits each account to 200 outgoing messages per hour (DirectAdmin: 1,000 per day), which caps the damage but does not prevent it.

8. If a mailbox is compromised

  1. Change the password
    from a clean device, and sign out other sessions if your service allows it.
  2. Check forwarders, filters and autoresponders.
    Attackers add a forwarder to copy your mail, or a filter to hide replies from you.
  3. Warn your contacts
    if messages were sent in your name, especially customers who pay you.
  4. Check the devices
    that used the mailbox for malware.
  5. Ask your provider
    to check what was sent and lift any sending block once you are clean.

The full walkthrough for Domain India hosting accounts is how to investigate email spam and abuse problems.

9. Email security with Domain India

The email included with cPanel, DirectAdmin and Webuzo hosting gives you SSL/TLS connections, SPF and DKIM through your control panel, spam filtering on cPanel and per-account sending limits. It runs on the same server as your website.

Business Email runs on a separate platform. It signs every message with DKIM, provides SPF and DMARC records for your domain, supports two-factor authentication and mail filters, and serves webmail over HTTPS at https://mail.yourdomain.com:8443/:

Business Email
₹60/mo + GST
  • Priced per mailbox - start with one
  • Email at your own domain ([email protected])
  • Add and remove mailboxes yourself
  • Webmail with calendar, contacts and tasks
See plan details

The price on the card is a live Domain India list price and excludes 18% GST. To choose between them, read Business Email vs the email included with your hosting.

What is the most important email security step for a small business?

Give every mailbox a long, unique password and turn on two-factor authentication wherever your email service offers it. Most email attacks start with a stolen or guessed password.

What are SPF, DKIM and DMARC?

SPF lists the servers allowed to send mail for your domain, DKIM signs each message so receivers can check it was not altered, and DMARC tells receivers what to do with mail that fails those checks for your domain. Together they make it much harder for others to send mail as your domain.

Should I set DMARC to p=reject straight away?

No. Start with p=none and read the reports for a few weeks, fix any genuine service that fails, then move to p=quarantine and finally p=reject. Rejecting too early can bounce your own legitimate mail.

Which ports should my mail app use for secure email on Domain India hosting?

Use IMAP on port 993 with SSL/TLS, and SMTP on port 465 with SSL/TLS or 587 with STARTTLS, with mail.yourdomain.com as the server. Avoid unencrypted ports 110 and 143. On Windows (Plesk) hosting, port 587 is closed, so use 465.

How can I tell if a payment request email is fraud?

Treat any change of bank details or urgent payment request as suspect until you have confirmed it by phone on a number you already have, not one in the email. Check the full sender address for small spelling changes in the domain.

Does Domain India hosting email include spam filtering?

Yes, on cPanel hosting. SpamAssassin runs on our cPanel servers, and spam filtering with a Spam folder is switched on for almost every account. You can adjust the threshold in cPanel under Email › Spam Filters.

What should I do if my email account has been hacked?

Change the password from a clean device, remove any forwarders, filters or autoresponders you did not create, warn contacts who may have received fraudulent mail, scan your devices, and open a support ticket so the provider can check what was sent.

Ready to secure your email? Start with passwords and two-factor authentication today, then set up DMARC for your domain. If you are unsure what your records should be, open a support ticket with your domain name.

Email kept separate from your website

Mailboxes at your own domain with DKIM signing, SPF and DMARC records, two-factor authentication and webmail, priced per mailbox.

See Business Email

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app