Email Security Dojo

Tenant Defence Score
0 / 1000
Current Rank
No belt yet
0 done 0 in progress 0 in scope

Email is still how they get in. Microsoft ships sensible defaults and most tenants never touch them again. Answer four questions, then work the belts: three DNS records you can fix this afternoon, the protections you already own and haven't switched on, and the Defender controls you're paying for. Every control comes with the attack it stops, the MITRE ATT&CK techniques behind it, and the exact clicks. Walk out with a deployment plan.

Read this first — email breaks loudly and in public

Conditional Access locks you out of your own tenant. Email security is worse in one specific way: when you get it wrong, your customers find out before you do, because your invoices stop arriving. The order below isn't advice, it's the whole method.

Full guidance: Set up DMARC to validate the From address domain ↗

Size up your environment

Four quick questions. The dojo tailors the control set to what you actually run — and tells you honestly when something isn't for you. If you've been through another dojo, your licence mix is already filled in.

Which licences do you have in the tenant? Select all that apply.

Do you have Defender for Office 365?

Asked, not guessed: Microsoft's docs disagree on whether E3 includes Plan 1 (announced, not shipped). Business Premium and E5/A5/G5 do. Check yours ↗. Not sure counts as no.

How does mail reach Microsoft?

Own domains you never send mail from?

Walk out with a plan

Your deployment plan lists every in-scope control with its status, MITRE references and Microsoft Learn source. The PowerShell script contains the DNS records to publish and the Exchange Online checks for your in-scope controls, in belt order — with every Get- ready to run and every Set- left for you to run deliberately, because that's how professionals roll out something that can bounce their own invoices.