Email Server
Security Reviews
Configuration and architecture review of Microsoft Exchange, Exchange Online, Postfix, Exim and Zimbra — closing the relay, authentication and delegation weaknesses that make mail the most reliable route into an organisation.
Email remains the dominant initial access vector in real-world intrusions, and the mail platform itself is a high-value target long after that first foothold. It holds years of business correspondence, brokers password resets for every other system, and — in the case of on-premises Exchange — sits inside Active Directory with privileges that make it a direct path to domain compromise.
The severity of that exposure has been demonstrated repeatedly. ProxyLogon, ProxyShell and ProxyNotShell each turned an internet-facing Exchange server into unauthenticated remote code execution, and organisations were breached not because they lacked a patch policy but because they had no visibility into how their mail estate was configured, what was exposed, and who held delegated access to it.
Levantis Cyber reviews on-premises, hybrid and cloud-hosted mail platforms end to end — the server configuration, the authentication and delegation model, the transport and anti-spoofing controls, and the public DNS posture that determines whether anyone on the internet can convincingly send mail as your organisation.
Architecture Mapping & Exposure Assessment
We map the full mail flow — edge gateways, transport servers, mailbox servers, hybrid connectors and cloud tenancy — and establish exactly what is reachable from the internet. Exposed virtual directories (OWA, ECP, EWS, Autodiscover, MAPI, ActiveSync, PowerShell) are enumerated, version and cumulative update level are established, and exposure to the known Exchange RCE chains is assessed directly.
SMTP Transport & Relay Testing
Authenticated and unauthenticated relay testing against every listening connector, including internal-only listeners that are frequently reachable from the wider network. We assess receive connector permission groups and remote IP ranges, anonymous submission scope, sender address spoofing from inside the perimeter, VRFY and EXPN user enumeration, STARTTLS enforcement and certificate validity on the transport path.
Anti-Spoofing & Email Authentication Review
Full assessment of SPF, DKIM and DMARC across every sending domain and subdomain — including parked and legacy domains, which are routinely forgotten and routinely abused. We evaluate SPF record syntax, lookup count and terminating mechanism, DKIM key strength, rotation and selector coverage, and DMARC policy strength, alignment mode and reporting configuration. MTA-STS and TLS-RPT posture is reviewed alongside.
Authentication, Delegation & Permission Model
Review of mailbox permissions, Full Access and Send-As delegation, application impersonation rights, and Exchange RBAC role assignments — the mechanisms most commonly abused for persistence after account compromise. Legacy authentication protocol availability, MFA coverage and conditional access enforcement are assessed, and privileged Exchange groups are examined for their Active Directory blast radius.
Transport Rules, Forwarding & Data Egress
Enumeration and review of transport rules, journaling configuration, and every forwarding path out of the organisation — mailbox forwarding attributes, inbox rules, and connector-level redirection. These are the persistence and exfiltration mechanisms attackers reach for first following business email compromise, and they are frequently invisible to security teams that only monitor endpoint telemetry.
Content Filtering & Threat Protection Efficacy
Assessment of anti-malware, anti-phishing and attachment handling policy — including macro-enabled and archive attachment treatment, URL rewriting and detonation coverage, impersonation and lookalike domain protection, and quarantine handling. We test whether policy scope actually covers all recipients, a gap that is common in organisations with layered or partially migrated protection.
Logging, Auditing & Detection Coverage
Review of message tracking, mailbox audit and admin audit logging configuration, retention periods, and whether these feed a monitored SIEM. We assess detection coverage for the specific events that indicate compromise — new forwarding rules, permission grants, mass mailbox access, anomalous connector changes — and identify where an intrusion would currently pass unobserved.
Reporting & Remediation Guidance
A detailed technical report with findings risk-rated by exploitability, accompanied by platform-specific remediation — Exchange Management Shell and Graph PowerShell commands, corrected Postfix and Exim directives, and staged DMARC enforcement plans that move you to a reject policy without breaking legitimate mail flow. Debrief call with your messaging and security teams included as standard.
Mail platform reviews are commonly split between messaging administrators who understand the product and security testers who understand the attacker — with the gap between them being precisely where findings are lost. Our assessors work both sides. We know what an Exchange RBAC role assignment actually grants, and we know how an operator chains it into domain compromise.
We also treat the anti-spoofing work as an engineering deliverable rather than an advisory note. Moving a real organisation from p=none to p=reject without severing legitimate third-party senders takes a staged, evidenced plan — and we provide one, built from your actual DMARC aggregate data rather than a generic recommendation.