Email Security For Both Directions

Right now, a supplier could be reading an email that looks like it came from your business, one you never sent and had no way to stop. Most cyber security watches what lands in your inbox, never what leaves under your name. IronInbox covers both directions, built on Mimecast and Sendmarc, run by our Johannesburg team.

Inbound Filtering Guards Your Inbox, Not Your Name

A gateway filter, whether that is Mimecast or the protection built into Microsoft 365, only ever looks one way: at what is arriving in your inbox.

Nobody Is Watching Outbound

Your domain can be used to send a convincing fake invoice to a supplier, and your own inbox never sees it happen because the message never touches your mail server at all.

Spoofing Needs No Breach

An attacker does not need to touch your systems or steal a password. They only need to forge your domain in the From field of a message you never sent.

The Damage Lands Elsewhere

The business that pays the fake invoice is not you, it is your client or supplier, and closing that gap is exactly what our 24/7 cyber security reviews are built to catch before it becomes a real loss.

Reply Chains Get Hijacked

An attacker who compromises one mailbox in a thread can reply convincingly using real context, and outbound authentication does nothing to stop a hijacked reply from a genuine account.

Executives Are Impersonated By Name

A lookalike domain one character different from yours, sent to a bookkeeper who is not checking headers closely, is often all it takes to get a payment authorised.

It catches the obvious phishing attempt, the malware attachment, the message impersonating your MD in your finance team's inbox. That part is real, working email security, and most Johannesburg businesses already have some version of it running.

What almost nobody has in place is anything watching the other direction: the mail going out under your domain name to somebody else's inbox.

Everything IronInbox Covers For Inbound And Outbound Mail From Day One

IronInbox pairs Mimecast for everything arriving in your inbox with Sendmarc for everything leaving under your domain, covered together from day one, not added later as extras.

Threat Filtering Before It Lands

Malware sandboxing, URL rewriting that re-checks a link at the moment it is clicked, and display name checks that catch impersonation.

Outbound Data Loss Prevention

Outbound mail is scanned for sensitive data and blocked, encrypted or held for review before it ever leaves the business.

Mail Server Continuity

If your mail server goes down, staff switch to a web portal or Outlook add-in, then everything syncs back once it is restored.

A Complete Domain Audit

Sendmarc finds every server currently sending mail as your domain, including the old marketing tool or abandoned integration nobody remembers signing up for.

A Staged DMARC Rollout

Your policy starts at monitor only, so nothing is blocked while we confirm who legitimately sends as your domain, then it tightens toward full rejection.

Ongoing Authentication

SPF and DKIM records are kept current as your senders change, with anomalies escalated through our 24/7 managed cyber security monitoring.

How Inbound Filtering And Outbound Domain Authentication Work As One System

Mimecast and Sendmarc are not two separate purchases, they are two engines pointed at the same domain from opposite directions, and each one only works properly once the other is in place.

The Gateway Sits In Front Of Your Inbox

Inbound mail routes through Mimecast’s cloud gateway before it reaches Microsoft 365 or Google Workspace, so filtering happens before a message ever lands in a real inbox.

Outbound Mail Is Checked On Its Way Out Too

The same gateway watches what leaves: content is scanned against DLP rules, and anything matching a sensitive pattern is blocked, encrypted or held back for review before it sends.

Continuity Keeps Mail Moving Through An Outage

If the primary mail server fails, staff switch to a web portal or Outlook add-in without losing mail flow, and everything reconciles automatically once the server is back.

DMARC Goes Live In Stages, Never Switched On Cold

We move your Sendmarc DMARC policy from monitor only, through quarantine, to full rejection, because switching straight to reject can block legitimate senders by accident.

No Flat Rate, Because No Two Inbox Setups Look The Same

We can’t publish a single number here, because the honest quote depends on your setup. Three things move the price: how many mailboxes need Mimecast filtering, how many domains, including old or dormant brand names, need DMARC configured, and how far through the monitor to reject rollout you already are. A ten mailbox business on one domain is a different job to a fifty mailbox business running three domains, and the quote reflects that, not a flat per seat rate. IronInbox can also sit inside our broader 24/7 IT support package.

01 Mailbox Count Across Microsoft 365 Or Workspace

02 Every Domain That Needs DMARC Authentication Configured

03 How Far Along Your DMARC Rollout Sits

Who This Is For

IronInbox is for businesses running their own domain and mailboxes on Microsoft 365, Google Workspace or similar, not personal Gmail or Yahoo accounts used for company mail. You need to be willing to grant DNS access, since DMARC cannot be configured without it. It doesn't replace your mailbox platform or cover a straight hosting swap, and if the gap is your network rather than your inbox, network security is the place to start.

How it works

1
Domain Audit
We audit every domain and current mail flow.
2
Mimecast Deployment
Mimecast filtering goes live across your mailboxes immediately.
3
DMARC Enforcement
DMARC moves from monitor only to full reject.
4
SOC Management
Ongoing management is handed to our managed SOC.

frequently asked questions

Does IronInbox replace our Microsoft 365 or Google Workspace mailbox?

No. Mimecast sits in front of your existing mailbox and rescans every link and attachment before it lands, on top of whatever Microsoft Defender is already doing. If you also need the Microsoft 365 environment itself managed, our Reputable M365 support covers that side.

Fully exposed. Monitor mode watches who is sending as your domain but blocks nothing. Once SPF and DKIM are authenticated, policy moves to reject and spoofed mail stops before it reaches anyone.

It holds rather than disappears. Our team checks flagged messages and releases false positives, so a real invoice is delayed briefly, not lost.

Whoever controls your domain’s DNS, since Mimecast routing and Sendmarc’s SPF, DKIM and DMARC checks depend on it. If a lapsed developer or agency still holds that access, recovering it is usually the first step.

Your existing mailbox data stays exactly where it is, since IronInbox sits in front of your current platform rather than replacing it, so nothing in your archive or compliance history needs to move for the security layer to go live.

Not if they are authenticated first. Before any policy moves to reject, every legitimate sender using your domain, including an accounting system or a marketing platform, is added to SPF and DKIM so it keeps sending normally while anything unauthorised gets blocked.

Everyone Secures Their Inbox. Almost Nobody Watches What Leaves It.

Talk to us about what leaves your domain unmonitored, and close that gap with a Mimecast and Sendmarc review.