Decide how you will run your email system
-
Personal email accounts (no way to enforce policies and no control of data)
-
Running own mail server (control over all accounts but requires 24/7 monitoring)
-
Third-party provider (strongly recommended for security and legal protection)
Track malicious emails
-
Examine header metadata (subject, name, email address)
-
Identify types of malicious emails
-
Malicious attachments (view attachments via web)
-
Links to malicious websites (use 2FA)
-
Fraud/harassment
-
Spoofing (pretending to be someone else)
Use passwords and 2FA
Set a data retention policy
-
Set a data retention policy
-
Comply with your local data regulations (e.g. EU's GDPR)
-
Communicate policies clearly
-
Confirm your legal requirements to store data
When needed, use encryption
-
PGP: Pretty Good Privacy
-
Third-party extensions
-
Mailvelope
-
Virtru
-
FlowCrypt
-
Secure email providers