CrossTenant
Home / Use cases / Auditing mailbox exposure

Auditing mailbox exposure

The quiet-compromise signals (an external auto-forward, an unexpected delegate, a stale send-as), audited across every mailbox in every tenant at once.

Prefer email? Get in touch and we run onboarding with you.

What's included

Auto-forwarding sweep

One pass reads the live auto-forwarding state of every mailbox in every tenant you manage, and flags destinations outside the customer's own domain, per tenant. A rule added quietly during a compromise surfaces in the same sweep as everything else.

auto-forwarding external destination per tenant

External delegate cleanup

Delegates are enumerated per mailbox, and anyone outside the organisation is flagged. When the list is wrong, external delegates can be removed in bulk: a dry-run preview shows exactly what would change, and nothing executes without an explicit confirmation.

external delegates dry-run bulk removal

Send-as and alias review

Send-as identities and aliases are reviewed per mailbox, because the address a leaver kept sending from, or an attacker added, rarely shows up in day-to-day admin. Stale entries become visible in one place, across the fleet.

send-as stale identities

Legacy protocol exposure

Per-mailbox IMAP and POP access sits alongside the forwarding and delegate findings, so a legacy protocol enabled years ago is part of the same audit, not a separate job that never gets scheduled.

imap pop

Honest scan results

A mailbox the scan could not read counts as failed, and partial coverage is labelled partial. An audit that skipped what it couldn't reach would report a false all-clear, so this one refuses to.

fail-closed partial labelled

Remediation on the record

Every fix (a forward disabled, an external delegate removed) is written to the customer's own tamper-evident audit trail, so the audit ends with evidence rather than a tidy tenant and no record. How the trail works lives on approvals & audit.

audit trail tamper-evident

The audit half of this runs on every tier; the remediation half (forwarding, delegates, send-as) sits in the Complete tier, so you can prove a problem before paying to fix it fleet-wide. See pricing. Gmail settings ride domain-wide delegation, a separate grant the customer approves in their own Admin console.

Mailbox exposure

Run this audit across your whole book

Every mailbox's exposure settings in every tenant you manage: one pass, honest results, and every fix behind a preview and a confirmation.