Email security issues and solutions belong in one document rather than two, because the value is in the pairing: each failure mode has a specific closing move, and mismatched spending, buying a gateway to stop a fraud that only a procedure stops, is the commonest way small organisations stay exposed while feeling protected. The pairing is stable enough to write down. Reused passwords pair with multi-factor authentication. Payment fraud pairs with a voice confirmation procedure. Phishing volume pairs with filtering; phishing payoff pairs with a credential rule. Forgery of your domain pairs with published sender authentication. Misdirected data pairs with link-based sharing and a data handling rule. This page walks the pairs with enough mechanism to act on, and closes with the one meta-solution that keeps the pairs alive: writing them into a policy set someone reviews, which is the job the free sheet on this site sizes and prices.
Pairs one and two: identity failures
Issue: account takeover through passwords reused across services. Solution: multi-factor authentication on every mailbox, plus a rule-audit habit, checking for forwarding and auto-delete rules on any suspicion. Issue: payment redirection, the emailed bank change or urgent transfer. Solution: a finance procedure stating that no payment or detail change proceeds on message alone; confirmation is by voice to a number on file before the message existed. The first is configuration, the second is a sentence, and together they close the two failures that do the most financial damage.
Pairs three and four: message failures
Issue: phishing, credential harvesting and malware delivery at volume. Solution in two halves: filtering, the platform baseline or a dedicated product, removes the bulk, and the credential rule, passwords entered only from typed addresses or bookmarks, removes the payoff of what gets through. Issue: sender forgery, mail in your name you never sent. Solution: publish SPF and DKIM for every legitimate sender and take DMARC to an enforcing policy so receivers reject the forgeries; the standard's own overview documents the rollout order. Filtering you can buy; the other three halves are configuration and habit.
Pair five, and the meta-solution
Issue: misdirection, your own mail carrying restricted data to the wrong recipient, autocomplete's favourite failure. Solution: restricted files travel as access-controlled links rather than attachments, so a wrong send is revocable, paired with a data handling rule naming which tiers may travel at all. The meta-solution binds all five pairs: they only persist as written, reviewed policy. Solutions that live in one person's habits leave with that person. The free policy sheet counts the documents the pairs live in, acceptable use, access, data handling, finance procedure, incident procedure, and prices drafting at your own hourly figure; Hardenvo Pro generates them and keeps the review dates.
Questions people ask about email security issues and solutions
What are the main email security issues and their solutions?
Five pairs: reused passwords with multi-factor authentication; payment fraud with voice confirmation procedure; phishing with filtering plus a typed-credentials rule; domain forgery with SPF, DKIM and DMARC at enforcement; misdirection with link-based sharing under a data handling rule.
Which solutions are free?
Most of them: multi-factor authentication, sender authentication records, the payment and credential procedures, and link-based sharing are configuration and policy. Paid filtering adds margin on volume. The costly part is the drafting time, which the free sheet prices at your own rate.
Where do I write these solutions down?
In the policy set: access policy, finance procedure, data handling policy, incident procedure. A pairing that lives in habit leaves with the person. The free sheet counts the set your facts call for; the paid plan generates the documents and reminds you before reviews lapse.