Services Methodology Why Us About Us Blog Get in Touch
← Back to Services
// 14 — EMAIL SERVER SECURITY

Email Server
Security Reviews

Configuration and architecture review of Microsoft Exchange, Exchange Online, Postfix, Exim and Zimbra — closing the relay, authentication and delegation weaknesses that make mail the most reliable route into an organisation.

Microsoft Exchange Exchange Online Postfix Exim Zimbra SPF / DKIM / DMARC Open Relay Transport Rules
Overview

Email remains the dominant initial access vector in real-world intrusions, and the mail platform itself is a high-value target long after that first foothold. It holds years of business correspondence, brokers password resets for every other system, and — in the case of on-premises Exchange — sits inside Active Directory with privileges that make it a direct path to domain compromise.

The severity of that exposure has been demonstrated repeatedly. ProxyLogon, ProxyShell and ProxyNotShell each turned an internet-facing Exchange server into unauthenticated remote code execution, and organisations were breached not because they lacked a patch policy but because they had no visibility into how their mail estate was configured, what was exposed, and who held delegated access to it.

Levantis Cyber reviews on-premises, hybrid and cloud-hosted mail platforms end to end — the server configuration, the authentication and delegation model, the transport and anti-spoofing controls, and the public DNS posture that determines whether anyone on the internet can convincingly send mail as your organisation.

Review Methodology
01

Architecture Mapping & Exposure Assessment

We map the full mail flow — edge gateways, transport servers, mailbox servers, hybrid connectors and cloud tenancy — and establish exactly what is reachable from the internet. Exposed virtual directories (OWA, ECP, EWS, Autodiscover, MAPI, ActiveSync, PowerShell) are enumerated, version and cumulative update level are established, and exposure to the known Exchange RCE chains is assessed directly.

02

SMTP Transport & Relay Testing

Authenticated and unauthenticated relay testing against every listening connector, including internal-only listeners that are frequently reachable from the wider network. We assess receive connector permission groups and remote IP ranges, anonymous submission scope, sender address spoofing from inside the perimeter, VRFY and EXPN user enumeration, STARTTLS enforcement and certificate validity on the transport path.

03

Anti-Spoofing & Email Authentication Review

Full assessment of SPF, DKIM and DMARC across every sending domain and subdomain — including parked and legacy domains, which are routinely forgotten and routinely abused. We evaluate SPF record syntax, lookup count and terminating mechanism, DKIM key strength, rotation and selector coverage, and DMARC policy strength, alignment mode and reporting configuration. MTA-STS and TLS-RPT posture is reviewed alongside.

04

Authentication, Delegation & Permission Model

Review of mailbox permissions, Full Access and Send-As delegation, application impersonation rights, and Exchange RBAC role assignments — the mechanisms most commonly abused for persistence after account compromise. Legacy authentication protocol availability, MFA coverage and conditional access enforcement are assessed, and privileged Exchange groups are examined for their Active Directory blast radius.

05

Transport Rules, Forwarding & Data Egress

Enumeration and review of transport rules, journaling configuration, and every forwarding path out of the organisation — mailbox forwarding attributes, inbox rules, and connector-level redirection. These are the persistence and exfiltration mechanisms attackers reach for first following business email compromise, and they are frequently invisible to security teams that only monitor endpoint telemetry.

06

Content Filtering & Threat Protection Efficacy

Assessment of anti-malware, anti-phishing and attachment handling policy — including macro-enabled and archive attachment treatment, URL rewriting and detonation coverage, impersonation and lookalike domain protection, and quarantine handling. We test whether policy scope actually covers all recipients, a gap that is common in organisations with layered or partially migrated protection.

07

Logging, Auditing & Detection Coverage

Review of message tracking, mailbox audit and admin audit logging configuration, retention periods, and whether these feed a monitored SIEM. We assess detection coverage for the specific events that indicate compromise — new forwarding rules, permission grants, mass mailbox access, anomalous connector changes — and identify where an intrusion would currently pass unobserved.

08

Reporting & Remediation Guidance

A detailed technical report with findings risk-rated by exploitability, accompanied by platform-specific remediation — Exchange Management Shell and Graph PowerShell commands, corrected Postfix and Exim directives, and staged DMARC enforcement plans that move you to a reject policy without breaking legitimate mail flow. Debrief call with your messaging and security teams included as standard.

What Makes Levantis Different

Mail platform reviews are commonly split between messaging administrators who understand the product and security testers who understand the attacker — with the gap between them being precisely where findings are lost. Our assessors work both sides. We know what an Exchange RBAC role assignment actually grants, and we know how an operator chains it into domain compromise.

We also treat the anti-spoofing work as an engineering deliverable rather than an advisory note. Moving a real organisation from p=none to p=reject without severing legitimate third-party senders takes a staged, evidenced plan — and we provide one, built from your actual DMARC aggregate data rather than a generic recommendation.

// Platforms Assessed

  • Microsoft Exchange Server
  • Exchange Online (Microsoft 365)
  • Exchange Hybrid deployments
  • Postfix
  • Exim
  • Sendmail
  • Zimbra Collaboration Suite
  • Google Workspace Gmail
  • Proofpoint / Mimecast gateways
  • Amazon SES / SendGrid

// Common Findings

  • Permissive internal SMTP relay
  • DMARC absent or at p=none
  • SPF exceeding 10 DNS lookups
  • Unprotected parked domains
  • Legacy authentication enabled
  • Excessive mailbox delegation
  • Undetected forwarding rules
  • Exposed ECP / OWA admin surface
  • Unpatched Exchange CU level
  • Mailbox auditing disabled

// Standards & Frameworks

  • CIS Microsoft 365 benchmark
  • CIS Exchange Server benchmark
  • NCSC Email Security & Anti-Spoofing
  • RFC 7208 / 6376 / 7489 (SPF, DKIM, DMARC)
  • MITRE ATT&CK — Email Collection & Persistence
  • ISO 27001 Annex A.8

// Typical Duration

  • Cloud tenancy review: 2–3 days
  • On-premises / hybrid: 4–6 days
  • Multi-domain enterprise estate: 8–12 days

// Engage Us

Ready to assess your mail platform and anti-spoofing posture? Get in touch for a scoping call — no obligation.

Get in Touch

Email is how they get in. And how they stay.

Close the relay, delegation and spoofing gaps in your mail estate before someone else finds them.

Get in Touch