Email is still the easiest way into a business. A convincing message can steal a password, redirect a payment or plant malware, and a stolen mailbox can then be used to attack your own customers. This guide covers the practical defences a small business can put in place: protecting mailbox logins, authenticating your domain, encrypting mail, spotting fraud and handling a compromise.
Protect every mailbox with a long, unique password and two-factor authentication where your email service offers it. Publish SPF, DKIM and a DMARC policy so others cannot easily send mail as your domain. Always connect mail apps over SSL/TLS, keep spam filtering on, and verify every request to change bank details by phone on a number you already know. If a mailbox is compromised, change its password, check its forwarders and filters, and tell your email provider straight away.
1. The attacks that actually hit small businesses
| Attack | What it looks like | Main defence |
|---|---|---|
| Phishing | A "your mailbox is full" or "shared document" email linking to a fake login page | Check links before clicking; two-factor authentication |
| Invoice and payment fraud (BEC) | A supplier or director "changes bank details" or asks for an urgent transfer | Verify by phone on a known number; a two-person payment rule |
| Spoofing | Mail that shows your own domain in the From line but was sent by someone else | SPF, DKIM and DMARC on your domain |
| Account takeover | Someone logs in with a stolen or reused password and sends as you | Unique passwords, two-factor authentication, alerts on new devices |
| Malicious attachments | An "invoice" archive or an Office file asking you to enable macros | Never enable macros from email; keep your computer's security updates on |
Most of these attacks need no technical skill; they rely on a busy person clicking or paying without checking. So the defences are part technical, part habit.
2. Protect every mailbox login
A mailbox password protects more than the inbox. Whoever has it can reset your other accounts, read invoices and send mail your customers will trust.
- One password per mailbox, long and random, stored in a password manager. See the best password managers for personal and business use.
- Two-factor authentication wherever the service offers it: your email service, your hosting control panel and your Domain India client area. See how to enable two-factor authentication.
- App passwords for mail apps where your provider supports them, so a lost phone can be cut off without changing the main password.
- Change passwords immediately when a staff member leaves or a device is lost, and remove old devices from the account.
- Use IMAP over SSL/TLS. For email included with Domain India hosting, use port 993 for IMAP and port 465 (SSL/TLS) or 587 (STARTTLS) for sending. Ports 110 and 143 without encryption send the password in plain text; avoid them. The full settings are in email server details and SSL settings.
3. Authenticate your domain: SPF, DKIM and DMARC
These three DNS records let receiving servers check that mail claiming to come from your domain really does.
A typical DMARC record to start with:
v=DMARC1; p=none; rua=mailto:[email protected]Start with p=none to collect reports, fix any genuine sender that fails, then move to p=quarantine and finally p=reject. Jumping straight to reject can bounce your own invoices and password emails.
On Domain India hosting: in cPanel, Email › Email Deliverability checks SPF and DKIM for each domain and offers to install the suggested records. cPanel signs mail with the DKIM selector default, and most cPanel zones already carry a p=none DMARC record, so edit it rather than adding a second one. DirectAdmin uses the selector x; see how to check and manage DKIM in DirectAdmin. The step-by-step guide is setting up DMARC.
Your newsletter tool, billing system, CRM and website forms may all send mail from your domain. Each one must pass SPF or DKIM for your domain before you tighten DMARC, or its mail will start landing in spam or bouncing.
4. Encrypt mail in transit, and when it matters, end to end
In transit. TLS encrypts the connection between your mail app and the server, and between mail servers. Using the SSL/TLS ports above covers your side. Between servers, most large providers use TLS when the other side supports it; MTA-STS is an optional DNS and web policy that asks senders to insist on it.
End to end. TLS does not protect a message once it sits in a mailbox. For confidential documents, use S/MIME (certificates built into Outlook and Apple Mail) or OpenPGP (for example in Thunderbird), or share the document through a secure link with a separate password. Both people need to set it up, so most businesses keep it for sensitive exchanges.
5. Spot phishing and payment fraud
Report phishing in your mail app with its report or junk button. In India you can also report cyber fraud at the national cybercrime portal, cybercrime.gov.in, or the 1930 helpline.
6. Keep spam and malware out
Email included with Domain India cPanel hosting runs SpamAssassin, and spam filtering with a Spam folder is already on for almost every account. Check the Spam folder now and then, and tune the threshold if genuine mail is caught; see SpamAssassin and the Spam Box.
On every computer that reads mail:
- keep the operating system, browser and Office updated;
- never enable macros in a document that arrived by email;
- treat unexpected archives (
.zip,.rar,.iso) and "invoice" links with suspicion, even from a known contact, whose mailbox may have been hijacked.
7. Stop your website becoming a spam source
A contact form without spam protection, or a hacked WordPress site, can send thousands of messages from your hosting account and get your domain blocklisted. Protect every form with a CAPTCHA or honeypot field, never let a visitor choose the recipient or edit the headers, and keep WordPress plugins updated. Domain India cPanel hosting limits each account to 200 outgoing messages per hour (DirectAdmin: 1,000 per day), which caps the damage but does not prevent it.
8. If a mailbox is compromised
- Change the passwordfrom a clean device, and sign out other sessions if your service allows it.
- Check forwarders, filters and autoresponders.Attackers add a forwarder to copy your mail, or a filter to hide replies from you.
- Warn your contactsif messages were sent in your name, especially customers who pay you.
- Check the devicesthat used the mailbox for malware.
- Ask your providerto check what was sent and lift any sending block once you are clean.
The full walkthrough for Domain India hosting accounts is how to investigate email spam and abuse problems.
9. Email security with Domain India
The email included with cPanel, DirectAdmin and Webuzo hosting gives you SSL/TLS connections, SPF and DKIM through your control panel, spam filtering on cPanel and per-account sending limits. It runs on the same server as your website.
Business Email runs on a separate platform. It signs every message with DKIM, provides SPF and DMARC records for your domain, supports two-factor authentication and mail filters, and serves webmail over HTTPS at https://mail.yourdomain.com:8443/:
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
The price on the card is a live Domain India list price and excludes 18% GST. To choose between them, read Business Email vs the email included with your hosting.
What is the most important email security step for a small business?
Give every mailbox a long, unique password and turn on two-factor authentication wherever your email service offers it. Most email attacks start with a stolen or guessed password.
What are SPF, DKIM and DMARC?
SPF lists the servers allowed to send mail for your domain, DKIM signs each message so receivers can check it was not altered, and DMARC tells receivers what to do with mail that fails those checks for your domain. Together they make it much harder for others to send mail as your domain.
Should I set DMARC to p=reject straight away?
No. Start with p=none and read the reports for a few weeks, fix any genuine service that fails, then move to p=quarantine and finally p=reject. Rejecting too early can bounce your own legitimate mail.
Which ports should my mail app use for secure email on Domain India hosting?
Use IMAP on port 993 with SSL/TLS, and SMTP on port 465 with SSL/TLS or 587 with STARTTLS, with mail.yourdomain.com as the server. Avoid unencrypted ports 110 and 143. On Windows (Plesk) hosting, port 587 is closed, so use 465.
How can I tell if a payment request email is fraud?
Treat any change of bank details or urgent payment request as suspect until you have confirmed it by phone on a number you already have, not one in the email. Check the full sender address for small spelling changes in the domain.
Does Domain India hosting email include spam filtering?
Yes, on cPanel hosting. SpamAssassin runs on our cPanel servers, and spam filtering with a Spam folder is switched on for almost every account. You can adjust the threshold in cPanel under Email › Spam Filters.
What should I do if my email account has been hacked?
Change the password from a clean device, remove any forwarders, filters or autoresponders you did not create, warn contacts who may have received fraudulent mail, scan your devices, and open a support ticket so the provider can check what was sent.
Ready to secure your email? Start with passwords and two-factor authentication today, then set up DMARC for your domain. If you are unsure what your records should be, open a support ticket with your domain name.
Mailboxes at your own domain with DKIM signing, SPF and DMARC records, two-factor authentication and webmail, priced per mailbox.
See Business Email