Steps
E-Mail is the most common attack path for hackers. It is of paramount importance to test & improve your filters. We test your security from an independent perspective and provide a roadmap of actionable recommendations to harden your defenses.
To perform our E-Mail pentests, clients typically provide us with two test users (e.g. Outlook Inbox) and access to the mailboxes via remote access (e.g. TeamViewer, WebMail) or POP3.
Step 1
Kick-Off (60 min)
We introduce you to our methodology and align on the project execution. This includes defining goals and scope, assessing environmental conditions, coordinating access, and finalizing the timeline. Unlike generic approaches, we adapt our tests to your specific environment. We identify relevant senders to imitate—such as regional banks, known business partners, or even your own internal domain—to ensure the highest practical relevance.
Step 2
Pentest (including Inbound & Outbound)
We execute a comprehensive suite of approximately 150 test cases: Inbound (approx. 120 tests): We send various types of sophisticated, forged emails to a dedicated mailbox provided by you to check your defensive filters. Outbound (approx. 30 tests): We simulate data exfiltration to identify potential data leaks caused by employees or compromised systems. Infrastructure Check: We simultaneously audit your open ports and mail server configurations.
Step 3
Syncs & Analysis
We analyze the path of every test mail and evaluate which messages were delivered, quarantined, or flagged. We dive deep into the "Why" by checking: SPF, DKIM, and DMARC configurations, Content scoring and filter logic, Gateway policies and mail routing. Usually, we have 2 or 3 Sync meetings with the administrator.
Step 4
Closing meeting
In our final session, we present the findings in detail. We walk you through the results and provide clear instructions on how to fine-tune your filters and protocols