SPF, DKIM and DMARC: The Three Records That Decide If Your Email Is Trusted
Three DNS records decide whether the world trusts mail from your domain. Most businesses have one of them and have never looked at the other two.
Removing someone’s account is not the same as removing their access. Where access survives, why it is hard to investigate later, and the sequence that works.

Removing someone’s account is not the same as removing their access. Those two things come apart more often than people expect, and the gap usually gets measured in weeks.
We were once asked to look into a case where a former worker still appeared to be reading company email. They were. The account had been dealt with. The access had not.
Mail clients keep their own credentials. Outlook, Apple Mail and anything speaking IMAP cache a token or a password on the device. Change the password in the admin console and that cached session can keep working until it happens to expire on its own. Until somebody explicitly revokes the tokens, the laptop on somebody’s kitchen table keeps syncing.
Sessions outlive password changes too. An active web session is not automatically killed by a reset on every platform. Signing the user out everywhere is a separate action, and it is the one that gets skipped.
Forwarding rules are invisible unless you go looking. A rule set months earlier keeps copying mail to a personal address and survives everything except somebody opening that specific settings page.
Then there are the leftovers. Personal phones that were configured with the mailbox. App passwords. API keys issued by some other system. Each was granted separately and each has to be revoked separately.
This is the part that surprises people, and it is worth understanding before you need it.
If somebody accesses a mailbox through a properly delegated permission, the audit log records it as delegated access. You can see who did what, and you can prove it.
If they access the same mailbox by signing in as the owner with cached credentials, the log records ordinary mailbox activity. It looks identical to the owner reading their own mail.
So the evidence that would separate “the owner read their mail” from “somebody else read the owner’s mail” often does not exist. What you are left with is IP addresses and timing, which is slow work and rarely conclusive.
State that plainly, because it drives a design decision. Your ability to investigate later depends on how access was granted in the first place. Delegation leaves a trail. A shared password does not.
Do these on the day, in this order, rather than across the following week.
Then record that you did it, with the date. When a question comes up in six months, that record is the thing that answers it.
The list above is a process, and processes decay. Two changes make it less load-bearing.
Use delegation instead of shared credentials. Anywhere one person needs another person’s mailbox, or an account that is not theirs, grant a permission rather than hand over a password. It is easier to remove and it leaves something behind in the log.
Then automate what you can. Connecting your HR system to your identity platform means offboarding starts when the termination is entered, not when somebody remembers to raise a ticket. It is a real project, and for any business with staff turnover it pays for itself quickly.
Pick somebody who left six months ago. Check whether the account is disabled, whether forwarding was ever removed, and whether any device is still enrolled against them.
That takes about 20 minutes and it is uncomfortable more often than not.
Element Digital does cyber security work in Hobart and across Tasmania. If you want your offboarding process reviewed, get in touch.
Let us talk about what you are trying to achieve, no obligation, just a conversation.