Business email is the single most attacked entry point into a Nepali company's systems — more than the website, more than the network. A short annual audit catches most of the gaps that lead to account takeovers and fraud.

Authentication and Access

  • Is two-factor authentication (2FA) enabled on every account, especially finance and admin mailboxes?
  • Are shared logins (one password, several staff) eliminated in favor of individual accounts?
  • Are former employees' accounts disabled the same day they leave?

Domain Authentication

  • Are SPF, DKIM and DMARC records configured and passing? Missing records let attackers spoof your domain convincingly.
  • Is DMARC set to at least "quarantine," not just "none" (monitor-only)?

Data Protection

  • Are mailboxes backed up independently of the hosting provider's own infrastructure?
  • Is there an email retention policy for finance and legal correspondence?
  • Are attachments scanned for malware before delivery?

Human Factors

  • Have staff been trained to recognize phishing and invoice-fraud attempts in the last 12 months?
  • Is there a clear, known process for verifying payment-detail change requests by phone, not email reply?

Vendor Accountability

  • Does your email host provide an uptime SLA and documented incident response process?
  • Can you export your full mailbox data if you switch providers?

Running the Audit as a Structured 30-Minute Meeting

This checklist is deliberately short enough to work through in a single sitting with whoever manages IT and finance, rather than becoming an open-ended project that never gets scheduled. A practical approach: block 30 minutes once a year, print or share this list, mark each item pass/fail with a one-line note on the fix needed, and assign an owner and a date for anything marked fail. Businesses that treat this as an annual calendar event (tied to a fixed date like the start of the fiscal year) consistently keep pace with it; businesses that treat it as "something to get to eventually" mostly do not, until an incident forces the conversation anyway.

Frequently Asked Questions

How often should this audit run?

At minimum annually, and immediately after any staff departure involving privileged mailbox access.

What is the single highest-impact fix?

Two-factor authentication on every account. It stops the overwhelming majority of account-takeover attempts even when a password leaks.

Should this audit be documented for future reference?

Yes — keeping a simple record of each year's audit results and fixes creates a useful trail for tracking improvement over time and can matter for insurance or compliance purposes if ever asked to demonstrate security diligence.

Want a professional email security review? See our business email hosting or request a free audit.

Escalating Findings Appropriately

Not every gap found during an audit carries equal urgency. A missing DMARC record or an unremoved former-employee account represents active, exploitable risk and deserves same-week remediation; a documentation gap (no written retention policy yet) is real but rarely urgent enough to justify disrupting other work immediately. Triaging findings by actual risk, rather than treating the checklist as a uniform pass/fail list, keeps the audit's follow-up focused on what genuinely matters most first.