What's included
Auto-forwarding audit
Every mailbox's auto-forwarding state is read live across the fleet, and forwards to destinations outside the customer's domain are flagged per tenant. The classic quiet-compromise signal, checked everywhere at once.
Delegate audit
Mailbox delegates are enumerated per user, and delegates outside the organisation are flagged. External delegates can be removed in bulk — behind a dry-run preview and an explicit confirmation.
Send-as and aliases
Send-as identities and email aliases are audited per mailbox, so an identity a leaver left behind — or an attacker added — doesn't stay invisible. A dedicated alias audit covers every user across the fleet.
IMAP/POP posture
Per-mailbox IMAP and POP access is surfaced alongside the rest of the mail posture, so legacy-protocol exposure is visible before it becomes the way in.
Fleet-wide remediation
Disable external auto-forwarding across the fleet, remove external delegates, and push email signatures — each behind a dry-run preview, applied per tenant, and written to the audit log. Signature content is typed by the operator, never by the AI assistant.
Honest scan reporting
A mailbox whose reads failed counts as failed, and partial results are labelled partial. The scan is fail-closed by design — it never reports a false "all clear" over data it couldn't read.
Email authentication
SPF, DKIM, and DMARC checks live on the security page, alongside posture scoring — mail governance here is about mailbox behaviour, not DNS.
Deep mail governance — forwarding, delegate, and send-as remediation — is part of the Complete tier; see pricing.
Know what every mailbox is quietly doing
Forwarding, delegates, send-as, and legacy protocols — audited live across your whole book, with remediation one dry-run away.