Managed security

Email Security

A quieter, safer inbox.

Managed email security is the technical half of keeping unwanted mail out and stopping your own domain being used by other people, configured and then watched for you: filtering tuned rather than left at its defaults, authentication records published and enforced, and a security team who can remove a message from every mailbox it reached after it was delivered. happier IT runs it for Canadian organizations of roughly 15 to 200 people.

Who it's for

Four things that bring people to this page.

Three of them are about a message that got through. The fourth is about your domain being used somewhere you will never see, which has a known fix.

Filtering is running on the settings it shipped with. Microsoft 365 includes genuinely capable protection, and in most tenancies a good deal of it is switched off or left at defaults that do not know who your executives and finance staff are. This is the cheapest gap on the page to close.

A message reached forty people and there was no way to take it back. Once mail is delivered, getting it out of every mailbox needs tenancy-level tooling and someone with the access and the willingness to use it at 6pm.

Your domain is appearing as the sender on mail you did not send. Clients and suppliers receive it, and it damages a relationship you spent years building. The fix is a few days of work in your DNS records. DNS being the internet’s address book, where the public settings for your domain live.

The expensive message had no attachment and no link. BEC, business email compromise, is a plain request to change bank details or approve a payment, often from a supplier’s genuinely compromised mailbox. There is nothing technically wrong with the message, which is precisely why a filter is the wrong tool for it.

The half a filter cannot do

No filter reliably catches a well-written message from a real, compromised supplier account quoting a real invoice number. There is nothing about it to detect.

That is a process control: any change to bank details is confirmed by phoning a number you already held, never the number in the email, by someone other than the person who received it. Free, and it prevents more loss than anything else on this page. The human side lives on phishing prevention and training.

What's included

What we configure, and what we watch afterwards.

The setup is a project of days. The value after that is entirely in who is watching and what they are able to do quickly.

  • Filtering tuned to your organization

    Attachment and link handling, quarantine policy, and impersonation protection that knows the actual names most likely to be forged, your directors, your finance team, your largest suppliers. Defaults protect a generic company. Yours is not one.

  • SPF, DKIM and DMARC published and enforced

    Three records in your domain settings that let a receiving mail server check a message claiming to be from you. SPF lists who may send as you, DKIM signs each message, DMARC says what to do when a check fails and reports back. Reaching enforcement is the best day of work here.

  • Post-delivery search and removal

    When something gets through, we search every mailbox in your tenancy for the same message and remove it, rather than emailing everybody asking them not to click. This is the single capability most often missing when an organization runs email security alone.

  • Alerts routed to our SOC with a defined action

    A SOC is a security operations centre, the team that watches alerts and decides which matter. Ours is in Canada and staffed by happier IT employees. Each kind of email alert has an action written down in advance rather than invented at the time.

  • The credential check that follows a click

    When somebody enters a password somewhere they should not have, the important work is not the password reset. It is revoking active sessions, checking for new mailbox rules and forwarding, checking whether a second factor was added, and reviewing recent sign-ins. That sequence is ours to run.

  • External sender banners used sparingly

    A warning that appears on every message becomes wallpaper within a fortnight. We apply banners where they carry information, a first-time sender, a display name resembling an internal one, so that seeing one still means something.

  • Outbound protection and reputation monitoring

    Watching what leaves as well as what arrives: unusual sending volumes, forwarding rules created outside your policy, and whether your domain has ended up on a blocklist. The first sign of a compromised mailbox is often outbound, not inbound.

  • A monthly report that is short

    What was blocked, what was removed after delivery, what your authentication reports show about who is sending as your domain, and anything needing a decision. Written for a director rather than an administrator.

How it works

Audit, publish, then watch.

The domain records come first. They are the only part of this that protects your clients and suppliers as much as it protects you, which is why they get postponed.

  1. Audit what is already configured

    What your current licence entitles you to, what is switched on, what is at defaults, and what your domain records currently say. Most audits find capability already paid for and never enabled, which makes the next step cheaper than expected.

  2. Tune and publish

    Filtering configured to your organization, impersonation protection given real names, and SPF, DKIM and DMARC published, then moved to enforcement carefully with the reports watched for a few weeks so a legitimate newsletter, payroll system or booking platform does not silently stop being delivered.

  3. Monitor, remove, report

    Alerts route to our security operations centre with an agreed action for each type. Anything that got through is searched for and removed across the tenancy, the credential sequence runs where it applies, and you get a short monthly summary.

What it costs

Per mailbox, per month, with the domain work priced separately.

The authentication project is quoted on its own because it is worth buying even if you never take the monitoring.

For happier IT managed IT

We are happy to do only that, and it remains useful long after any relationship with us.

Before quoting a third-party product to sit in front of Microsoft 365, we check what your existing licence already includes. That check often removes a line from the proposal, which is an odd thing to advertise and the right way round.

What DMARC is really worth

Enforced DMARC mostly stops other people sending mail that appears to come from your domain. It protects your clients and your suppliers more than it protects your own inbox, which is exactly why it keeps getting postponed.

It is also a decent measure of a provider. Whether they have done it tells you whether they think past the boundary of your own tenancy.

Why us for this

The difference is what happens in the ten minutes after.

Every provider in Canada can turn on filtering, and the filtering products are broadly comparable. The honest position is that a well-written message from a compromised supplier account, quoting the right invoice number, will land in somebody’s inbox. There is nothing technically wrong with it to detect.

So the thing worth buying is what happens next. When a message is reported, happier IT’s security operations centre in Canada can search every mailbox in your tenancy for it and remove it, then check whether anyone who clicked had already signed in somewhere they should not have: sessions, mailbox rules, added second factors, sign-in locations. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific. Time from a reported message to that search running: minutes, not hours.

What we will not publish is a click-rate improvement figure or a percentage of threats blocked. We do not have a sourced one, and the numbers in this category are mostly vendor marketing. The measure we do watch with clients is how often people report something, because a reported message is a twenty-minute job and an unreported one is a quiet fortnight.

Go deeper

Questions

What people ask before they sign anything.

What is managed email security?

It is email filtering and authentication set up properly and then watched by somebody. The setup part covers your filtering policy, impersonation protection, and the SPF, DKIM and DMARC records that prove a message really came from you. The managed part is a security team monitoring what those produce, removing messages from mailboxes after delivery when something gets through, and running the account checks that follow a click. Software alone gets you the first half.

Is Microsoft 365 filtering enough on its own?

It is genuinely good, and in most tenancies it is under-configured. Impersonation protection, Safe Links and Safe Attachments are frequently off or left at defaults that do not know who your executives and finance staff are. Before buying a third-party filter to sit in front of it, have someone configure what you already pay for, that is often the whole improvement. See Microsoft 365 security for what that involves.

What is business email compromise?

BEC is a plain, well-written request, usually to change bank details, approve a payment, or send payroll information, that appears to come from a colleague, an executive or a supplier. Often it genuinely does come from a supplier, whose mailbox has been compromised. There is no attachment and no link, so there is nothing for a filter to catch. The control that works is a process one: confirm any change to payment details by phoning a number you already held.

Can you remove an email after it has been delivered?

Yes, across the whole tenancy, provided you have given us the necessary administrative access. We search every mailbox for the same message and remove it, which is considerably more reliable than sending an all-staff email asking people not to click something. It is also the capability most often missing when an organization runs its own email security, because it needs both the tooling and somebody available to use it promptly.

Does this include phishing training?

No, deliberately. This page is the technical half. The training, the one-click report button, the simulations and the payment-verification rule live on phishing prevention and training, and the broader curriculum is on security awareness training. Most organizations want both, and they are separate pieces of work with separate prices so you can see what each is worth.

How long does DMARC take to enforce?

A few days of configuration, then a monitoring period of several weeks before switching to enforcement. The monitoring period is not padding: it is how you discover that your payroll platform, your booking system or a marketing tool sends mail as your domain and would break the moment you enforce. Rushing that step is the way this project causes an outage nobody connects back to it.

What does email security cost?

Inside happier IT’s managed IT agreement it is not a separate line. Ask any provider whether their price includes removing a message from mailboxes after delivery, that is where the quotes actually differ.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.