AegentraNew Zealand

Harden / New Zealand

Email security

Aegentra helps New Zealand organisations strengthen email-domain authentication and Microsoft 365 mailbox protection. We review the legitimate sending services, existing controls and evidence before recommending or implementing a scoped change.

On this page

Start with the boundary

Define the work that is needed.

For organisations addressing spoofing exposure, inconsistent email controls or uncertainty about third-party senders.

  • Legitimate sending domains and services
  • SPF, DKIM and DMARC configuration and alignment
  • Mailbox and anti-phishing protection within agreed licences
  • Monitoring and controlled rollout of policy changes

Keep the responsibilities distinct

Domain authentication reduces particular spoofing risks; it does not prevent every phishing message or account compromise. Mail-flow changes must be tested and monitored.

What the engagement can produce

Useful outputs, agreed in advance.

  • An inventory of agreed sending services and dependencies
  • Authentication and mailbox-control findings
  • A staged change and verification plan
  • Handover guidance for ongoing monitoring

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How we work

From evidence to a practical next step.

Agree

Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.

Examine

Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.

Act or report

Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.

Verify and hand over

Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

An illustrative starting point

What a useful first decision looks like.

Fictional example to explain the service, not a New Zealand client case study or a promised outcome.

A domain uses Microsoft 365 plus a marketing platform and a ticketing service. Enforcing a restrictive policy before identifying every legitimate sender can disrupt business messages.

Questions for the first discussion

  • Which systems send email using your domain?
  • Who controls DNS and each sending platform?
  • What delivery problems or spoofing reports have you observed?

Before you begin

Your questions, answered.

Should we immediately set DMARC to reject?

Not without understanding legitimate sending sources and alignment. A staged review can identify unauthenticated services and delivery risks before a stricter policy is enforced. The right rollout depends on your domain, providers and monitoring evidence.

What can be included in email security?

The agreed scope can include legitimate sending domains and services; sPF, DKIM and DMARC configuration and alignment; mailbox and anti-phishing protection within agreed licences; monitoring and controlled rollout of policy changes. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.

How much does this service cost?

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How do you deliver the work in New Zealand?

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

What should we provide before a proposal?

Bring answers to these starting questions: Which systems send email using your domain? Who controls DNS and each sending platform? What delivery problems or spoofing reports have you observed? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.

Reference points

Check the underlying guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss your requirement

Start with your business.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.