Service Mail, identity & resilience
Business email on your domain, the certificates that protect it, and backups that restore
Email is the one service nobody notices until it fails once. We run it as a permanent responsibility: mailboxes and groups on your own domain, authentication that stops impersonation, certificates that do not expire on a Friday evening, and backups that have actually been restored — with a record of it.
1 · Business email on your domain
An address on your own domain is the first thing a new supplier judges you on. Mailboxes are provisioned on a managed platform with webmail, standard protocols, aliases, distribution groups, shared mailboxes, automatic replies and quota reporting — issued the same working day when the domain and requester are confirmed.
- Named mailboxes, functional addresses and group distribution that survives staff changes.
- Shared calendars and contacts where the organisation needs a desk, not an individual.
- Spam and virus filtering with quarantine reporting, so a blocked invoice is visible rather than lost.
- Archive and retention settings chosen deliberately, not left to a platform default.
- Mailbox, alias and licence inventory kept current — the register, not a spreadsheet someone remembers.
2 · Microsoft 365 administration
For organisations standardised on Microsoft, we take the tenant: domain verification and DNS, licence assignment and reduction, users and groups, role-based administration, Exchange Online, SharePoint and OneDrive structure, Teams policy, mailbox migration from IMAP or another tenant, shared-device and mobile enrolment where required, and monthly housekeeping that removes licences nobody uses.
Tenants inherited from a previous supplier are usually the harder job — orphaned global administrators, forwarding rules pointing at unfamiliar domains, and third-party apps granted consent years ago. We baseline all of it and hand back a documented state.
3 · SPF, DKIM, DMARC and deliverability
Sending as your domain should be provable. We configure and then monitor the three records that decide whether your mail is trusted:
| Control | What it does | How we run it |
|---|---|---|
| SPF | Lists the hosts permitted to send for the domain | Built from an inventory of real senders, kept inside the DNS lookup limit |
| DKIM | Signs outbound mail so receivers can verify it was not altered | Keys issued per sending service and rotated with the certificate cycle |
| DMARC | Tells receivers what to do with failures, and reports what is happening | Staged p=none → quarantine → reject once sources are clean |
| MTA-STS & TLS reporting | Enforces and reports opportunistic TLS between mail servers | Published where the platform supports it, monitored for failures |
| Blocklist and reputation checks | Detects when your domain has quietly started landing in spam | Reviewed as part of the managed service, not after a client complains |
The commercial benefit is concrete: fewer lost invoices, fewer "did you send that?" calls, and a documented position when a customer's security team asks why their vendor's domain is now protected.
4 · SSL and TLS certificates
Certificates are supplied, installed, monitored and renewed — including the awkward ones on mail gateways, legacy appliances and internal portals.
- Domain-validated and organisation-validated certificates; wildcard and multi-domain (SAN) profiles.
- Automated issuance and renewal where the platform allows, and a central expiry register where it does not.
- Installation on web servers, load balancers, mail servers, FTP and API endpoints, with chain and cipher configuration checked rather than assumed.
- Monitoring for expiry, revocation, mismatched chains, mixed content and certificate-transparency entries for hosts you did not know existed.
- Advice on lifetimes and on which validation level the estate actually needs — shorter lived, automatically renewed certificates usually beat a manual three-year plan.
5 · Domains, DNS and DNSSEC
Domain registration and transfer, registrar lock and auth-code handling, record management, forwarding, subdomain hygiene and DNSSEC where the registry supports it. Portfolios are reviewed annually: unused registrations released, defensive registrations kept, expiries tracked centrally so nothing lapses while somebody is on leave.
6 · Account and platform hardening
- Multi-factor authentication enforced for administrative and remote access, with app-based methods rather than SMS where the choice exists.
- Separation of administrative accounts from day-to-day mailboxes, and named accounts instead of shared logins.
- Mail-forwarding and inbox-rule review — the two places attacker persistence hides.
- Baseline configurations for servers and mail platforms, documented and re-checked periodically.
- A patch cadence that is published to the client, so nobody has to ask whether anything is being done.
- Phishing simulation follow-through: when a test message is opened, the fix is a control, not a memo.
7 · Backup, restore and disaster recovery
A backup nobody has restored is a hope, not a control. Backup arrangements are written against two numbers agreed with you: how much loss is acceptable, and how long recovery may take.
- Scheduled snapshots and off-platform copies for mailboxes, files, databases and servers.
- Retention stated per system, with longer archives where records must be kept.
- Isolated or immutable copies where the platform supports them, so a compromise cannot delete the escape route.
- Restore tests on a schedule, with the result recorded — a one-line note per test, filed where an auditor will look.
- A written recovery procedure naming who decides, who executes and what is recovered first.
8 · Mailbox migration projects
Migrations are run in waves with a rehearsal, a control total and a rollback that has been tested once. Mail, contacts and calendars move together; permissions and shared resources are rebuilt rather than assumed; client devices are re-pointed on a schedule; and the old platform is decommissioned only after delivery is confirmed on the new one.
9 · Compliance, retention and reporting
Where personal data is processed, the group acts under the UK GDPR and the Data Protection Act 2018, either as controller for its own records or as processor on a client's documented instructions — see the privacy notice. Reporting covers mailbox changes, authentication results, certificate renewals, backup and restore evidence, and incidents, in a format that can be filed without rewriting.
10 · How the service is bought
| Shape | Suited to | What it covers |
|---|---|---|
| Per mailbox or per service | Sole traders and small teams | Standard plans operated by the relevant entity, self-service with support |
| Managed monthly service | Medium-sized businesses without an internal IT function | Mail, DNS, certificates, authentication, backups and monitoring under one scope schedule |
| Project | Migrations, tenant clean-ups, DMARC enforcement | Fixed scope, written plan, defined acceptance and a hand-over pack |
| Master agreement | Multi-brand or multi-entity organisations | One register of domains, mailboxes and certificates; one escalation route; annual review |
11 · Questions teams ask first
- Can you migrate our mail without an outage?
- Mail is migrated with a planned overlap rather than a switch. Records are prepared in advance, the lowest practical TTLs are set, mailboxes and calendars are moved in waves, and both systems run side by side until delivery is confirmed. The cutover window and the rollback position are agreed in writing before anything changes.
- Do we need a Microsoft 365 tenant, or can you host our email directly?
- Both are available. Microsoft 365 suits organisations that want mail with Teams, SharePoint, OneDrive and device management. Direct hosted mailboxes suit teams that want a professional address on their own domain without a full suite. We recommend against a licence nobody will use.
- What does DMARC reporting actually get us?
- Visibility of who is sending as your domain, which of your real sources fail authentication, and where spoofing attempts are landing. We publish the policy in stages — monitor, then quarantine, then reject — so legitimate mail is never caught by a rule applied too quickly.
- How quickly can a certificate or a new mailbox be issued?
- Domain-validated certificates and standard mailboxes are usually issued the same working day once the domain and the requester are confirmed. Organisation-validated certificates depend on the issuing authority's verification process, which we manage on your behalf and track centrally so it never becomes your problem at renewal time.
12 · Related services
Correspondence
Tell us where the mail, the certificates or the backups are today.
A domain name, a count of mailboxes and what worries you is enough to start. You will get a written assessment of the current position and a costed plan to put it right — including the answer, when the answer is that nothing needs changing.