Cloud
Email that arrives where it should
Migration off legacy Exchange, mail flow that stops landing in spam folders, and the authentication records that determine whether anyone can impersonate your domain.
Deliverability
The three records almost nobody has set correctly
SPF, DKIM and DMARC determine whether your mail is trusted, and whether a stranger can send invoices that appear to be yours.
Email is the system a business notices fastest when it breaks and thinks about least when it works. It is also where the largest number of avoidable security exposures sit, because mail authentication is invisible until someone uses it against you.
Legacy Exchange
On-premise Exchange servers are increasingly difficult to justify. They require patching against a steady stream of serious vulnerabilities, they need hardware that eventually fails, and the versions still running in many small businesses are past or approaching end of support. There are legitimate reasons to keep mail on-premise, mostly regulatory, but for the majority of businesses running Exchange 2016 or older, the honest recommendation is a migration path rather than another hardware refresh.
We handle those migrations to Microsoft 365 or Exchange Online: mail, calendars, contacts, shared mailboxes, distribution groups, public folders where they exist, and mobile device reconfiguration. Scheduled over a weekend with a rollback plan written before anything moves.
Deliverability, which is usually authentication
When a business tells us their email lands in customers' spam folders, the cause is almost always incorrect or missing authentication records rather than anything about the message content. SPF that does not include every legitimate sender. DKIM never configured. DMARC absent entirely, or set to a policy that does nothing.
These three records determine whether receiving mail servers trust your domain, and equally whether somebody else can trivially send mail that appears to come from it. Business email compromise, where an invoice arrives that looks exactly like yours, depends heavily on domains that have not configured this properly. It is an afternoon of work and it is missing in a remarkable proportion of the environments we assess.
Shared mailboxes and structure
Most businesses need shared addresses such as info, billing or support, and most set them up as full user accounts because that is the obvious route. That is a licensing cost and a security exposure. Shared mailboxes do the same job without a license and without a password anyone can phish. We restructure this, along with distribution groups and the aliases that accumulate over the years.
Scope
What is included
Everything below is part of the service rather than an upsell discovered later.
Migration from on-premise Exchange
Mail, calendars, contacts, shared mailboxes and distribution groups moved intact, on a weekend, with a documented rollback plan.
SPF, DKIM and DMARC configuration
The three records that decide whether your mail is trusted and whether your domain can be impersonated. Frequently missing entirely.
Deliverability investigation
When your mail lands in spam, we trace the actual cause rather than guessing at content, which is rarely the problem.
Shared mailbox restructuring
Role addresses converted from licensed user accounts to proper shared mailboxes. Cheaper and materially safer.
Mail security and filtering
Filtering tuned to your business, plus rules that catch the impersonation patterns behind business email compromise.
Mobile and client configuration
Phones, tablets and desktop clients configured correctly, including the conditional access rules that govern them.
Common questions
Our email keeps going to spam. Can you fix it?
Usually, and the cause is typically authentication rather than content. We audit your SPF, DKIM and DMARC records, check whether your domain or sending IP appears on blocklists, and correct the configuration. Most cases resolve within a day or two of the records propagating.
Should we keep our on-premise Exchange server?
For most small businesses, no. The patching burden, the hardware replacement cycle and the security exposure rarely justify it now. There are legitimate regulatory exceptions and we will tell you if you are one rather than pushing a migration by default.
Can you stop invoice fraud emails?
We can substantially reduce the risk. Correct DMARC prevents direct impersonation of your domain, filtering catches lookalike domains, and rules can flag external mail claiming to be internal. Combined with staff who have been trained on it, this addresses most of the attack. No control is absolute.
Related services
Talk to Us
Talk to a technician, not a salesperson
Describe what is happening. We will tell you whether it is a quick fix, a project, or a sign of something larger.
(858) 429-1311Family owned in San Diego, California since 2004 · remote support in all 50 states · US-based technicians · never outsourced