Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Review Microsoft 365 email security in a deliberate order: inventory your domains and mail flow, authenticate every sending domain, compare threat policies with Microsoft’s Standard or Strict baselines, then check forwarding, administrator access, reporting, and audit coverage. Use the recommendations as a review baseline—not a universal configuration recipe. The right settings depend on your licenses, senders, connectors, business workflows, and risk tolerance.
This checklist is for administrators managing Exchange Online. Microsoft’s guidance cited here was accessed October 7, 2026; exact controls and availability can change with tenant licensing and configuration.
1. Establish scope, licensing, and safe administrative access
Before changing a policy, map the mail environment it is meant to protect. Include cloud mailboxes, custom accepted and sending domains, third-party senders, inbound gateways, connectors, and business-required forwarding. Include parked domains and subdomains in the domain inventory: they can still be abused to impersonate your organization.
- Confirm the subscription. Microsoft’s built-in security features apply to organizations with cloud mailboxes. Defender for Office 365 adds controls such as Safe Links, Safe Attachments, impersonation protection, and phishing thresholds; availability and behavior depend on the subscription and policy assignment. Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, but check your tenant’s actual entitlements before planning around a control.
- Map legitimate mail paths. Identify services that send as your domains, any third-party service that processes inbound mail before Microsoft 365, and exceptions such as service or shared mailboxes.
- Use least privilege. Assign the role needed for each review or change. Microsoft recommends reserving Global Administrator for emergency situations where an existing lower-privilege role cannot perform the task.
Record the owner, purpose, affected users, and review date for exceptions. This makes it easier to distinguish a deliberate business requirement from an undocumented weakening of protection.
#1 Best Overall
2. Authenticate every custom sending domain and verify mail flow
Configure SPF, DKIM, and DMARC in that order for every custom Microsoft 365 domain, including parked domains and subdomains. Microsoft’s Microsoft 365 admin checklist explicitly recommends this sequence. First inventory every legitimate sender—including non-Microsoft services—so the records reflect real mail flow rather than Microsoft 365 alone.
- SPF: Check that the domain’s SPF record accounts for every authorized sending service. Confirm that a change will not omit a legitimate sender.
- DKIM: Enable signing for the relevant custom domains and verify that the expected mail is signed.
- DMARC: Publish a policy and monitor alignment and reports before deciding whether to strengthen enforcement. A policy that does not account for legitimate senders can disrupt their mail.
Authentication and routing defects can send legitimate messages to Junk or quarantine even when threat policies match Microsoft’s recommendations. Correct those defects before relaxing filtering. If inbound mail passes through a non-Microsoft service before Microsoft 365, review Enhanced Filtering for Connectors so Microsoft 365 can assess the original sender information appropriately.
Do not use broad anti-spam allowlists or allow your own domains to bypass filtering as a workaround for false positives. Microsoft warns that allowed domains can let messages through that would otherwise be filtered. Identify the sender, authentication, or routing problem and fix it at its source.
Rank #2
3. Compare threat protection with Microsoft’s baselines
Review anti-spam, anti-malware, anti-phishing, quarantine handling, and which recipients receive preset policies. Microsoft recommends using Standard and/or Strict preset security policies as baselines, then comparing custom policies against the recommended values. A baseline is a starting point for review, not proof that every setting fits every recipient or mail-flow design.
Recommended Free Tools
| What to compare | What to establish |
|---|---|
| Built-in cloud-mailbox protection | Which EOP or other built-in protections apply to your cloud mailboxes and how they are configured. |
| Defender for Office 365 controls | Whether your subscription includes the relevant controls, such as Safe Links, Safe Attachments, impersonation protection, or phishing thresholds, and whether the applicable preset or custom policy assigns them. |
| Standard and Strict presets | How the recommended settings and user impact differ for the relevant recipients; compare quarantine and business-critical mail handling rather than assuming one preset suits everyone. |
| Custom policies and exceptions | Which settings differ from the baseline, which users are affected, and the documented business reason and owner for each exception. |
Review quarantine permissions deliberately. Microsoft’s settings guidance says users cannot self-release certain malware and high-confidence phishing messages; depending on policy, they may be able to request release. Do not enable self-release for every quarantined threat simply to reduce administrator workload.
For education tenants, Microsoft’s education baseline also calls out common attachment filtering, malware scanning, zero-hour auto purge, phishing and impersonation protections, inbound spam filtering, link scanning, and audit logging. Treat that as education-specific guidance rather than a universal checklist of requirements for every organization.
Rank #3
4. Use the configuration analyzer to find drift
In the Microsoft Defender portal, open the configuration analyzer and compare policy settings with the Standard or Strict baseline. The analyzer covers built-in anti-spam, anti-malware, and anti-phishing policies. When Defender for Office 365 is in scope, it also covers impersonation and phishing-threshold settings, Safe Links, and Safe Attachments. It checks certain non-policy settings too, including whether SPF and DKIM are detected and whether Outlook external-sender identifiers are enabled.
For each finding, review the affected policy, current configuration, recommendation, and last-modified date. A difference from baseline is a reason to investigate—not an instruction to apply a change without considering mail flow, recipient impact, and documented exceptions.
Where drift history is available, use it to see who changed a setting, its old and new values, and whether it moved security up or down relative to the selected baseline. Microsoft documents review of up to 90 days of history in the interface and requires Unified Auditing to be enabled for this drift-analysis view. Keep a record of accepted deviations and revisit them when their owner, workflow, or risk changes.
Rank #4
5. Check external forwarding, inbox rules, and device access
External automatic forwarding
For each outbound spam policy, inspect Automatic forwarding rules. Microsoft’s Zero Trust guidance identifies Automatic – System-controlled (the default) and Off – Forwarding is disabled as values that block automatic forwarding to external recipients for affected users. Choose the setting that fits the organization’s requirements and scope exceptions narrowly.
Policy-level controls do not tell the whole story. Review mailbox-level forwarding and inbox rules as well, and investigate unexpected rules. Attackers can use external forwarding to extract data. Microsoft points administrators to Secure Score and the Autoforwarded messages report as additional review sources.
Mobile and unmanaged-device access
Check whether legacy or basic-authentication ActiveSync is blocked and whether mobile access requires the intended app protection. For unmanaged devices, Exchange Online mailbox policies and Conditional Access can prevent users from downloading attachments—or from viewing them at all—in Outlook on the web and new Outlook for Windows. Apply restrictions to the intended groups and test legitimate access workflows before rollout.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
6. Protect privileged accounts and improve message reporting
Administrator sign-in
Require phishing-resistant multifactor authentication for Exchange Administrator accounts and other privileged roles. Microsoft explicitly names Exchange Administrator among the roles for which it recommends phishing-resistant MFA. FIDO2 security keys are one supported method; available methods and policy scope are managed through Microsoft Entra authentication methods and Conditional Access.
Before enforcing a policy, make sure administrators have registered working methods and a recovery path. Microsoft’s Entra guidance specifically advises registering the appropriate methods before creating a policy that requires phishing-resistant MFA. Check that the chosen method works for the administrator’s devices and tenant policy, and plan how authorized administrators can recover access without weakening the policy for everyone.
User reports, alerts, and review cadence
Configure Outlook’s Report button and route user-reported messages to a designated mailbox, Microsoft, or both. Review the submission queue and relevant threat reports; investigate suspected phishing as well as false positives and false negatives. Submissions can help identify missed threats and messages incorrectly classified as malicious.
Maintain alert policies for relevant user and administrator activity and for potential malware or data-loss incidents. Microsoft recommends reviewing Secure Score monthly in its anti-phishing best practices. Use that review to track meaningful changes and unresolved risks, rather than treating a score alone as proof that mail is secure.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitches7. Preserve audit evidence
Do not disable the default audit policy. Microsoft’s Exchange Online education baseline says it logs certain administrator actions and recommends enabling Microsoft 365 user activity logging for incident response and threat detection. Check audit coverage and retention in your tenant’s current Purview configuration, taking licensing into account; Microsoft’s cited guidance does not establish one universal retention duration for every tenant.
Quick Recap
Turn the review into a repeatable checklist
- Inventory cloud mailboxes, domains, senders, connectors, gateways, and required forwarding; confirm relevant licenses and review roles.
- Verify SPF, DKIM, and DMARC for each custom domain, then validate legitimate inbound and outbound mail paths.
- Compare anti-spam, anti-malware, anti-phishing, quarantine, and applicable Defender controls with Standard or Strict recommendations.
- Review analyzer findings and drift history; investigate each difference before changing it.
- Check outbound forwarding policy, mailbox forwarding, inbox rules, legacy authentication, and unmanaged-device access.
- Verify privileged users’ phishing-resistant sign-in methods and recovery readiness; test reporting, alerts, and audit coverage.
- Document changes and exceptions with an owner, scope, reason, and review date.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

