Corporate Mail & Cloud

Mail in the spam folder.
One DNS later, in the inbox.

Microsoft 365 or Google Workspace; correct DNS, correct SPF/DKIM/DMARC, MFA enforced, mailbox migration without loss. With phishing simulations, MDM and DLP we keep both your people and your data on the right side of the line. No migrations that bleed into the weekend, no certificates remembered on Thursday — we set it up once, set it up right.

In corporate mail success is measured by not landing in spam. When SPF, DKIM and DMARC are all set correctly, your proposal lands in the inbox and the impostor’s mail gets rejected at the door.

BLOCKED
Garanti BBVA
Monthly statement — May 2026
DMARC PASS
Tedarikçi A.Ş.
PO #44128 awaiting your approval
SPF + DKIM
paypa1-security@…
Your account suspended — click now
DMARC FAIL
HR — Partnerfy
Payroll — May
DKIM
Microsoft 365
Monthly security summary
VERIFIED
dig firma.com TXT
SPF v=spf1 include:spf.partnerfy.co ~all PASS
DKIM selector1._domainkey 2048-bit PASS
DMARC p=reject; rua=mailto:dmarc@… PASS
Sender Reputation
67 → 94
Mailbox migration
10 → 500
users in one weekend
DMARC
p=reject
enforced mode reached
MFA
100%
user coverage
Phishing click rate
-84%
in 6 months
The honest picture

Why DIY mail is a deliverability nightmare.

A mailbox on cPanel appears to work — you send, you receive. Until your proposal lands in Gmail’s spam folder, until your Outlook customer calls asking "I sent you a mail, didn’t it arrive?" The mail isn’t the problem; the problem is that the three DNS records that authenticate the sender (SPF, DKIM, DMARC) are written wrong, that there is no MFA on top, that ex-employee accounts are still active.

The spam folder black hole

A wrong SPF, missing DKIM or no DMARC pushes your proposal into Gmail’s Spam, Outlook’s Junk. Customers won’t complain — they simply won’t read.

A single password without MFA

When a mail password leaks once, the attacker reaches all past mail, customer threads, bank invoices. Without MFA nobody can prove "it wasn’t me".

The ex-employee still inside

When the ex-employee’s mail isn’t disabled, months later they still read proposals and price lists. One-click deactivation in the admin console is impossible without proper IT.

Phishing — who clicks what?

Which fake mail your team clicks, who needs training — without simulation and reporting you can’t see. After the incident, asking "who opened it" is too late.

No encryption — open traffic

On old IMAP/SMTP setups traffic flows in the clear. On café WiFi or a misconfigured corporate network your password and mail body become readable.

Backup? What backup?

When a user accidentally deletes a folder — or ransomware encrypts all messages — the cloud’s default retention often isn’t enough. A separate SaaS backup is essential.

Visual walk-through

Every mail you send passes five gates.

When you hit "Send" in Outlook or Gmail your mail in theory arrives instantly. In practice SPF, DKIM, DMARC, content scanning and finally delivery — five separate checks happen. If a single gate is closed, your mail either doesn’t arrive or lands in spam. Below you see the path, the admin console and the phishing report together.

Outgoing Mail Path
Compose
SPF
DKIM
DMARC
DELIVERED

At every stage Gmail / Outlook check your domain, signature and policy. All three green → inbox; one yellow → spam; one red → outright reject.

Microsoft 365 — Admin ● connected
Users
124
MFA enrolled
100%
Secure score
87 / 100
Risk level
Low
Legacy auth
3
Active DLP rules
14
Your admin sees users, MFA, secure score, DLP rules and risk level on one screen — three months in, the metrics already improve.
PHISHING SIMULATION

"DHL — Confirm your parcel"

Audience: 124 users

Opened
31
Clicked
4
Reported
68
Automatic action

A 12-minute micro-training was assigned to the 4 who clicked. Non-clickers earned +5, reporters +10 on the security score.

Before / after inbox

BEFORE — DIY mail
  • 18 Viagra ads
  • 2 fake bank / SMS phishing
  • Customer mail in spam
  • 47 new, 4 important
  • No MFA — old password
AFTER — corporate mail
  • Spam down 98%
  • Phishing blocked + reported
  • Customer mail in inbox
  • 9 new, 8 important
  • MFA + device compliance
Who it’s for

If mail is a critical channel — this is for you.

The eight profiles below should treat mail as critical infrastructure rather than a default. If you’re on the list, starting day one with the right licence, retention and DLP rules for your sector is far cheaper than migrating later.

Regulated finance

BDDK / SEC / MiFID-aligned retention + journaling.

Hospitals & clinics

PHI in mail with DLP and encrypted attachments.

Law firms

Attorney-client mail with e-discovery + journal.

Manufacturers

Supplier PO mail with DMARC enforced against BEC.

E-commerce

Order & invoice mail with a dedicated IP to avoid spam.

Professional services

Shared mailbox + archive for client communication.

Multi-branch retail

Branch manager groups & MDM-managed phones.

Schools & universities

Student / teacher mail with free EDU licences.

Capabilities

From licence choice to phishing training — ten capabilities.

In mail and cloud we don’t just resell M365 — we run an end-to-end operation covering licence advisory, DNS, migration, training, MDM, DLP and phishing simulations.

M365 / Workspace setup

Tenant creation, licence assignment, domain verification.

DNS configuration

MX, autodiscover, autoconfig — right the first time.

SPF / DKIM / DMARC

From zero to report-driven reject mode.

MFA enforcement

Conditional Access — risk-based sessions.

Mailbox migration

cPanel, Exchange, Zimbra → M365 / Workspace.

Shared mailbox & groups

info@, sales@ shared mailboxes & distribution lists.

DLP policies

Credit card, ID number, IBAN — no exfiltration.

Archive & e-discovery

10-year retention with legal-hold searchability.

Phishing sim & training

Monthly simulation + micro-learning via KnowBe4.

MDM

Corporate mail container on iOS / Android.

Process

Six steps — from discovery to user training.

01

Current-state discovery

User count, current server, DNS, licences, mailbox sizes, mobile inventory. 90-min call + 3-day report.

02

Licence & architecture

M365 Business Standard or Premium? Hybrid Exchange needed? Three-scenario recommendation.

03

Tenant + DNS prep

Tenant creation, user provisioning, SPF/DKIM/DMARC pre-publish (p=none), low TTL.

04

Mailbox migration

Incremental migration via IMAP/PST/EWS. Final delta on Friday night — Monday on the new system.

05

MX cutover + security

MX switch, MFA enforced, DLP rules, Conditional Access, anti-phishing policy.

06

Training + DMARC reject

1-hour user training, first phishing simulation, move to p=reject based on DMARC reports.

Platforms we work on

Before selling the right tool — picking the right tool.

No blind loyalty to any platform. M365 or Workspace; Mimecast, Proofpoint or Microsoft Defender — we recommend what fits your team, sector and regulation.

Microsoft 365 Google Workspace Mimecast Proofpoint Barracuda KnowBe4 Cisco Duo Okta Sophos Email MailRoute Bitdefender Coreview
Six from the field

Why they came in, what they left with.

M365

50-person engineering firm — to M365 in one weekend

Friday 6pm → Monday 9am. 8 years of Exchange data migrated in full, DMARC moved to p=quarantine in week one.

KnowBe4

Hospital — phishing click rate 19% → 3%

Six campaigns + micro-learning in 6 months. When a real phish landed, 2 of 312 clicked, 297 reported.

Compliance

Law firm — KVKK + Bar audit clean

Journaling, 10-year archive, e-discovery for client comms — auditor questions answered in 48 hours.

Deliverability

E-commerce — 92% of order mails reach inbox

Dedicated IP + SPF/DKIM/DMARC + warm-up. "Order confirmation never arrived" support tickets dropped 71%.

Intune

12-branch retailer — phone fleet via MDM

180 phones with corporate mail container; stolen devices wiped remotely, no customer data leaked.

DMARC

Manufacturer — supplier BEC blocked

Thanks to DMARC reject + impersonation protection, a 240k EUR fake-wire mail never reached the inbox.

Most asked

M365 or Workspace, where does KVKK stand?

There are two questions: what is your team already used to, and how deep do you go into each app. Finance, legal and engineering shops dependent on Excel formulas, long Word docs and Outlook rules usually find M365 the right answer. Conversely, agencies, education and distributed teams that live in real-time collaboration usually flow better in Workspace. Licence cost, device fleet, OneDrive vs Drive quotas and third-party integrations also play in — in a 30-minute discovery call we lay out three side-by-side scenarios with price and capacity.
No — and the reason we say so is technical, not promotional. A typical migration goes: a full inventory of the existing server (mail count, folder tree, attachments, calendar, contacts). Then via IMAP, EWS or PST we pull a baseline into the new tenant; each night during the window we take an incremental delta. On Friday before MX is switched we take one last delta — so Monday morning every mail the user had on the old system is also on the new. The old server stays read-only for 14-30 days more; if anything looks missing we can re-import.
With correct prep, practically no. MX has a 24-48h propagation window, but seven days before cutover we lower TTL to 300 seconds so resolvers worldwide refresh in five minutes. On cutover night we keep the old server alive and forward whatever still arrives there to the new tenant. The user never experiences "no mail since 3am" — at most some mail takes a slightly longer path through the old server for a few hours and then arrives.
A correctly tuned MFA means one approval per day, not one per session. With Conditional Access, staff on the corporate network, on a known device, from a low-risk IP skip the prompt entirely. Only on signals like new device, new city, long idle does the phone ring. Net effect: most users approve once in the morning and the rest of the day is transparent. An attacker who steals a password and tries to log in always gets prompted — without the phone, they don’t get in.
Monthly in the first year, every two months thereafter — that’s the sweet spot. Each campaign tests about one-third of the audience with a different lure (parcel, bank, internal impersonation, invoice, shared file). Anyone who clicks gets a 12-minute micro-training on the spot; they’re included again next round. Reporters earn score, reported mails reach SOC. After 6 months average click rate drops from 18% to under 4%. You won’t get there with "watching a training video" — live simulation is required.
Within minutes of HR notifying us. The process: one-click disable (signs out from every device), mailbox archived for 30 days, manager gets access to files, then deletion. Delegation, auto-reply, mail forwarding and licence reclamation happen in parallel. Crucially: before closure we export the mailbox as PST/JSON into the company archive — so months later when "find that customer thread from six months ago" comes up, we still can.
Yes — but compliance starts with "the platform itself is compliant" and only completes once you configure it correctly. Microsoft and Google offer EU data centres and KVKK-equivalent DPAs. Our contribution: one, EU residency choice and data-residency policy; two, DLP across user, mailbox, OneDrive/Drive logging movement of ID numbers, IBAN, card data; three, a document set for consent, retention, deletion requests and breach notification. When the auditor arrives we can answer "which policy applied to which user when" in seconds.
Think of three layers. One, platform licence: M365 Business Standard or Workspace Business Standard ~12-14 USD / user / month. Two, an extra security layer (Defender for Office, Mimecast, KnowBe4) 3-7 USD / user / month depending on needs. Three, our managed service: a flat fee up to 50 users, marginal per-user beyond. For a typical 30-person team the total monthly bill stays below a senior engineer’s daily salary — in exchange for MFA management, DMARC monitoring, phishing simulation, MDM and 24/7 support.
30 minutes — free mail audit

From spam folder to inbox,
one DMARC report away.

Let’s look at your current DNS, mailbox sizes, MFA status and last three months of DMARC reports together. By the end of the call — before any decision — you’ll have a clear picture: where you’re strong, where the risk is, how fast it’s fixable.

results