Sign in or Register
Listing cover image

eMail Filter Pentest

80% of attacks start via E-Mail. Let us test your e-Mail filters.

  • Monitoring
    2800 € / semi-annually
  • Single Test
    3800 €
  • Activity
  • prev
  • next
  • Your effort: 6 h
  • Extensions possible
  • Request Quote & Start
  • prev
  • next
Steps

E-Mail is the most common attack path for hackers. It is of paramount importance to test & improve your filters. We test your security from an independent perspective and provide a roadmap of actionable recommendations to harden your defenses.

💡 How to give ACCESS

To perform our E-Mail pentests, clients typically provide us with two test users (e.g. Outlook Inbox) and access to the mailboxes via remote access (e.g. TeamViewer, WebMail) or POP3.

Step 1

Kick-Off (60 min)

We introduce you to our methodology and align on the project execution. This includes defining goals and scope, assessing environmental conditions, coordinating access, and finalizing the timeline. Unlike generic approaches, we adapt our tests to your specific environment. We identify relevant senders to imitate—such as regional banks, known business partners, or even your own internal domain—to ensure the highest practical relevance.

Result: Test cases tailored to your threat landscape.

Step 2

Pentest (including Inbound & Outbound)

We execute a comprehensive suite of approximately 150 test cases: Inbound (approx. 120 tests): We send various types of sophisticated, forged emails to a dedicated mailbox provided by you to check your defensive filters. Outbound (approx. 30 tests): We simulate data exfiltration to identify potential data leaks caused by employees or compromised systems. Infrastructure Check: We simultaneously audit your open ports and mail server configurations.

Regular Syncs: To keep you informed, we hold brief status meetings (e.g., twice a week) to discuss real-time findings and project progress.

Step 3

Syncs & Analysis

We analyze the path of every test mail and evaluate which messages were delivered, quarantined, or flagged. We dive deep into the "Why" by checking: SPF, DKIM, and DMARC configurations, Content scoring and filter logic, Gateway policies and mail routing. Usually, we have 2 or 3 Sync meetings with the administrator.

Step 4

Closing meeting

In our final session, we present the findings in detail. We walk you through the results and provide clear instructions on how to fine-tune your filters and protocols

Request Your Custom Assessment

    Sheet
    • Category
      Security Test
    • Your internal effort (~)
      6 h
    • Duration
      6 weeks
    • Compliance & Accountability relevant?
      ✅
    • Applicable to/at

      All public institutions & industries of any size

    • EUSEC®-Module

      EUSEC®-eMail-Filter-Pentest-26A

    Details
    • Key Outcomes & Deliverables
    • Scope / Out-Of-Scope

    Key Outcomes (What you achieve)

    • Independent Validation: Your eMail security is objectively assessed by top-tier experts.
    • Risk Reduction: Critical vulnerabilities are known and eliminated, significantly reducing your Cloud Security risks.
    • Improvement Started: Your company is empowered to implement effective M365 Cloud Security measures to detect, withstand, and recover from attacks.

    Deliverables (What you receive)

    • Traceable Evidence: Comprehensive documentation of your technical and organizational measures (TOMs) for eMail Security
      • Executive Management Summary (1-2 pages)
      • Report (approx 10-20 pages)
      • Attachments (e.g. eMail Protocols)

    In-Scope

    • Kick-off Meeting: 1-hour alignment and onboarding session.
    • Closing Meeting: 1-hour
    • 2 intermediate sync meetings before Closing (a 45-60min)
    • Assessment and Testing of your eMail Filter with 150 test cases (remote).
    • Tailoring test cases to your business environment (e.g. spoofing of specific senders)
    • Comprehensive Expert Report

    Out-of-Scope

    • Create Tickets in your ticket management system (e.g. JIRA), instead of list / report based documentation (optional)
    • Onsite or observed testing (e.g. via online conference tools and screen sharing) is costly and offered optional.
    • Additional effort if your company can not provide remote access to test inboxes (e.g. additional software required).
    • Group/Corporate Entities: Corporate groups or companies with multiple subsidiaries may require a separate package for each (legal) entity.
    • Implementation of corrective actions.
    • General exclusion: Everything else not explicitly mentioned as In-Scope is strictly Out-of-Scope.
    • Imprint
    • Data Privacy

    Basket