HLD Group
Email & messaging security policy
Anti-phishing, SPF/DKIM/DMARC, and acceptable email use.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy defines the controls that protect HLD Group email against compromise, spoofing, phishing, and data loss. Email remains a primary vector for attacks and for accidental disclosure, and warrants specific technical and behavioural controls.
2. Scope
This policy applies to all HLD Group email systems, domains, and accounts, and to all personnel who send or receive email for company business.
3. Email authentication and anti-spoofing
- SPF is published to declare authorised sending sources for our domains
- DKIM signs outbound mail so recipients can verify integrity and origin
- DMARC is enforced (with a reject or quarantine policy) to prevent spoofing of our domains, with reporting monitored
- MTA-STS and TLS reporting are used to protect mail in transit where supported
4. Threat protection
- Inbound filtering for spam, malware, and malicious links and attachments
- Protection against phishing and business email compromise, including impersonation detection
- Sandboxing or detonation of suspicious attachments and links where available
- Warning banners on external and high-risk messages
5. Account and access security
- Email access requires MFA under the Access Control Policy
- Mailbox auto-forwarding to external addresses is restricted and monitored to prevent silent exfiltration
- Anomalous access and mailbox rule changes are alerted and investigated
6. Acceptable use and data protection
Email is used in accordance with the Acceptable Use Policy. Confidential and Restricted information is sent only over appropriately protected channels and to authorised recipients, and sensitive data is encrypted where required. Data loss prevention controls detect and restrict inappropriate transmission of sensitive data.
7. Phishing awareness and reporting
Personnel receive phishing awareness training and simulations under the Awareness and Training Policy, and are provided a simple way to report suspicious email. Reported phishing feeds detection and response.
8. Framework alignment
- ISO/IEC 27001:2022 Annex A controls 5.14 (information transfer) and 8.23 (web filtering) as related controls
- NIST SP 800-53 Rev. 5 control SI-8 (spam protection) and SC-8 (transmission confidentiality and integrity)
- NIST SP 800-177 (Trustworthy Email) — SPF, DKIM, and DMARC
- SOC 2 Trust Services Criteria CC6.6 and CC6.7
9. Roles, exceptions, and review
IT and security own email security under the CISO. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].