The best email security expert to improve your email protection.

Rob Walton is an experienced freelance email security consultant with 30+ years working with email system technologies.

Rob has acted as Technical Lead on many email security projects across multiple industry sectors. Clients are across USA, Canada, and APAC.

Rob has maximised the email security controls for over 50 companies.

Originally from the United Kingdom, Rob worked in the finance sector, and moved to New Zealand in 2002 to continue his freelance email security consulting work. By leading multiple projects, and working with most of the email messaging platforms, Rob has gained deep experience in the area of email security.

“Email remains one of the most frequently targeted routes into an organisation. I provide independent email security consulting for businesses that need specialist help protecting Microsoft 365, Exchange Online and internet email services against phishing, business email compromise, impersonation, account takeover and data loss.”

Rob Walton, emailsecurityexpert.com

Contact Rob Walton today to discuss how to improve your email security.

Experienced Expert

My work combines more than 30 years of enterprise email-system experience with current Microsoft 365 cyber-security expertise.

I can review Exchange Online Protection and Defender for Office 365, anti-phishing controls, Safe Links and Safe Attachments, Entra ID authentication and Conditional Access, Microsoft Purview DLP, mailbox and mail-flow configuration, and the security posture of your email domains.

BEC Email Attacks

Business Email Compromise (BEC) is one of the most serious email security threats facing organisations. Attackers may use phishing, stolen credentials or Adversary-in-the-Middle (AiTM) techniques to compromise Microsoft 365 accounts and impersonate trusted employees, executives or suppliers. Once access is obtained, attackers can monitor email conversations, create hidden inbox rules, redirect messages and manipulate payment or banking instructions.

Effective BEC protection requires more than traditional spam filtering. I help organisations strengthen Microsoft 365 and Exchange Online using Microsoft Defender for Office 365, Entra ID, MFA and Conditional Access, together with secure mailbox configuration and monitoring for suspicious sign-ins, forwarding rules and other indicators of compromise.

Email Authentication Controls

Email authentication remains a critical part of that defence. I assess and harden SPF, DKIM and DMARC, including progression to DMARC p=reject, and can review newer transport and domain-security controls such as DANE, DNSSEC and MTA-STS.

The objective is not simply to pass an online DNS test, but to reduce practical opportunities for domain spoofing, impersonation and fraudulent email delivery.

M365 Exchange Online Protection

Microsoft Exchange Online Protection (EOP) provides the core email security layer for Microsoft 365 and Exchange Online. It analyses inbound and outbound email to identify and block spam, phishing, malware and other unwanted or malicious messages before they reach users.

EOP protection includes anti-malware scanning, anti-spam and anti-phishing policies, spoof intelligence, connection and content filtering, bulk email controls and outbound spam protection. It also evaluates email authentication technologies such as SPF, DKIM and DMARC to help identify spoofed or impersonated senders.

Email Security Assessment Report

For organisations that want a clear starting point, I provide an Email Security Assessment Report identifying weaknesses, risks and prioritised improvements.

I can then assist with implementation or work alongside your internal IT and security teams. I also undertake deeper Microsoft 365 cyber-security reviews and can assist with BEC and compromised-account investigations where forensic analysis is required.

New Email Security Measures

Modern email security increasingly extends beyond SPF, DKIM and DMARC. Technologies such as ARC (Authenticated Received Chain) help preserve email authentication results when messages pass through intermediaries such as mailing lists and forwarding services, reducing authentication problems caused by legitimate message modification.

MTA-STS helps protect SMTP connections by requiring supporting mail servers to use trusted TLS encryption, reducing the risk of downgrade and interception attacks. CAA (Certification Authority Authorization) provides additional DNS-based control over which certificate authorities may issue certificates for a domain, supporting the wider security of an organisation’s internet services.

BIMI (Brand Indicators for Message Identification) builds on strong DMARC enforcement by allowing qualifying organisations to display verified brand logos with supported email providers. Although primarily a trust and brand-identification technology rather than an anti-phishing control by itself, BIMI can complement a mature email authentication and domain-security strategy.

Email Security Expert Blog Articles

  • What is DMARC and why do I need it?

    DMARC is a custom DNS record in your public DNS zone file that tells receiving email systems how to treat an incoming email. If the sending email system is evaluated as being trusted – which can be attained by that system being included in your SPF record, or having a DKIM key, then that email…

  • Request an Email Security Assessment Report

    Hire an email security expert to review your email security posture. Rob Walton is a qualified, experienced, email security expert – and can review your email security measures. Rob Walton can provide an Email Security Assessment Report for $1,000 USD. You will need to provide details on all your registered public domain names, and details…

  • Encrypt Exchange Online Mailboxes with BYOK

    Encryption for Exchange Online Mailboxes Exchange Online mailbox data encryption can be increased beyond the default Microsoft provided level. When you first use Exchange Online for your mailboxes, the data is encrypted with a Microsoft encryption key that protects your data. This is similar to having your laptop protected by Bitlocker. However, the master key…

  • Capture DMARC Reject Email Copies

    Use DMARC to Protect your Email System It is recommended to ensure you have the highest SPF, DKIM, and DMARC email protection for all your email domains. This includes setting the DMARC email protection level to the highest “reject” mode. DMARC “reject” mode will result in rejection for any email sent from your domain name…

  • Email Impersonation Protection for Unused Email Domains

    Protect Unused Email Domains Against Cyber Attack Organizations usually own a large number of email domains, for brand protection reasons. But only use a subset of those email domains for their mailboxes. It is recommended to protect unused email domains as part of your overall cyber security. Typically any email security measures are only applied…

  • Review Older TLS Versions and Cipher Suites

    Prepare for TLS 1.3 Support for Mail Transport TLS 1.3 support is becoming prevalent across messaging platforms as we enter 2025. Exchange Online support for TLS 1.3 is due soon – see this TLS 1.3 Blog Post from office365migrate.com . TLS 1.2 is used as the default message transfer protocol, and this has superseded the…

Email Security Expert FAQs

Why do I need to hire an email security expert for my business?

Emails are a common attack surface to gain user credentials, resulting in invoice fraud and reputation damage. An email security expert can assess your current environment and make recommendations to maxmise your email security baseline. Many of the email security controls are free, and only required access to free tools, and your DNS zone file.

Where are you based, and which regions do you work in?

I am based in New Zealand, and work with clients in US, Canada, and APAC regions.

Can you prevent any email security breach?

No, this cannot be done. However, you can maximise the protection on all available email security controls. Other security policies, related to device & identity, can be leveraged to complement any email security controls.

Do you do any email forensic, or email expert witness work?

Yes, I do both email forensic work, and email expert witness work. Please see my other website that covers that topic.