Email Security & Phishing Protection for NZ Business
Stop dodgy emails before they reach your team — that's where nearly every attack starts.
Email is the number one way businesses get hit. Most incidents — phishing, invoice fraud, a staff member clicking a bad link — begin with a single message that should never have landed. We put a New Zealand email security layer in front of your inbox so the bad stuff gets caught first.
Why email is the front door for attackers
Think about how much runs through your inbox — invoices, approvals, password resets, quotes. Attackers know this, so email is where they knock first. One convincing message to the right person can move money or hand over a login.
Microsoft 365 has built-in filtering, and it does catch a lot. But the clever, targeted stuff — the fake invoice, the email that looks like it’s from the boss — often slips through. A dedicated layer closes that gap.
What we stop
Phishing & scam emails
These are messages built to trick a person into clicking a link or handing over a login. We scan and scrub inbound email so the obvious and the not-so-obvious ones never reach your team.
Invoice fraud & business email compromise
This is when a scammer changes the bank details on a real-looking invoice, and the money goes to them. We flag the impersonation and lookalike tricks these attacks rely on — before someone pays the wrong account.
Domain spoofing
Spoofing is when a scammer sends email that looks like it came from your domain. We set up the records that stop them — so your name can’t be used to con your clients.
How the protection works
A New Zealand filter in front of your inbox
We run your email through SMX, a New Zealand email security gateway, before it reaches Microsoft 365. It filters spam, scans every attachment & link, and holds anything suspect in quarantine — a holding pen for messages we’re not sure about. You get a simple summary, and a real email is one click to release.
Locking down your domain
We set up SPF, DKIM & DMARC for you — the email authentication records that prove a message really came from you. In plain terms, DMARC is a setting that stops scammers sending email that looks like it’s from your domain. Together they make it far harder for anyone to impersonate your business.
What you get
Inbound filtering
Spam, phishing & scam email caught before it reaches your team.
Attachment & link scanning
Every attachment & link checked, so a bad file or dodgy URL doesn’t get through.
Quarantine you control
Suspect email held safely, with a simple summary — release a genuine message in one click.
Anti-spoofing records
SPF, DKIM & DMARC set up so no one can send email pretending to be you.
Data-loss rules
DLP (data-loss prevention) rules that stop sensitive information leaving by email by mistake.
Part of a bigger picture
Email security is one layer of your wider cyber security — it works best alongside the rest.
How we set it up
1. Quick look at your setup
We check how your email runs today and where the gaps are. No jargon — just a plain read on your risk.
2. Switch on the protection
We put the filtering in front of your inbox and set up your authentication records. It happens in the background, so your team keeps working.
3. Tune & hand over
We adjust the rules to fit how you work, then show you the quarantine summary. From there we keep an eye on it as part of your managed IT support.
What it costs
Pricing depends on your team size and what’s already in place, so we quote rather than guess. It’s a small monthly cost per mailbox — far less than one paid-out fake invoice. Get in touch and we’ll give you a straight number for your business.
Frequently asked questions
Doesn’t Microsoft 365 already protect my email?
It does a fair bit, and it’s a good base. But the targeted attacks — the fake invoice, the email that looks like it’s from your boss — are exactly the ones that slip past the standard filter. A dedicated layer catches what gets through, and locks down your domain so no one can impersonate you.
What is business email compromise, in plain terms?
It’s when a scammer changes the bank details on a real-looking invoice, so your payment goes to them instead of your supplier. It’s common, it’s expensive, and it works because the invoice looks completely normal. We flag the impersonation tricks these scams rely on before anyone pays.
What happens when a real email gets caught by mistake?
It sits safely in quarantine — a holding pen — and you get a simple summary of what’s waiting. If it’s genuine, you release it in one click. Nothing important is lost; it’s just held until you say so.
What are SPF, DKIM & DMARC, and do I need them?
They’re email authentication records that prove a message really came from you. In plain terms, they stop scammers sending email that looks like it’s from your domain. We set them up for you — most NZ businesses don’t have them configured properly, and they matter.
Do we still need staff training if we have this?
Yes — the two work together. The filter stops the bulk of it, but the occasional clever email will always test the human. Email security is the technical layer; security awareness training is the human one. We pair them, along with backup, so a mistake doesn’t turn into a disaster.
We’re only a small team — are we really a target?
Small businesses get hit the most, because attackers assume the defences are lighter. The scams are automated and sent by the thousand — they don’t check your headcount first. Good protection is well within reach for a small team, and cheaper than the clean-up.
Let's shut the front door
Book a quick, no-pressure chat and we’ll show you where your email is exposed. It’s a small first step — with a big payoff if it stops one scam.
Phone: +64 9 280 1780
Email: sales@itlive.co.nz