
Ask FirstNet about Security
Managed Email Security & Advanced Threat Protection for South African Enterprise
Hosted email security to stop phishing, spam, and malware while maintaining continuity and compliance.
The Challenge
Email: The most common attack vector
Email remains the most common initial access vector for attackers. Phishing, business email compromise, and malware campaigns continue to evolve.
Security controls must filter threats effectively, maintain continuity during outages, and provide audit‑ready archives.
Quick answers
Do you support multiple mail platforms?
Yes. We integrate with Microsoft 365, Exchange, and other mail systems.
How are archives protected?
Archives are encrypted and access is controlled by roles and audit trails.
How are archives protected?
Archives are encrypted and access is controlled by roles and audit trails.
Can we run phishing awareness?
Yes. We can provide or integrate awareness training and simulations.
Our Expertise
Advance Protection
We deliver hosted email security (e.g., Mimecast or your chosen platform) with advanced filtering, URL and attachment protection, and continuity features that keep mail flowing even during provider issues.
Retention and e‑discovery features support investigations, compliance, and legal hold requirements.
- Advanced Filtering: block phishing, spoofing, and malicious attachments.
- Continuity: keep email available during provider or connectivity incidents.
- Archiving & e‑Discovery: ensure strict POPIA compliance with secure, audit-ready, localized email archiving and legal hold capabilities.
- User Protection: awareness features and safe link inspection.
How We Deliver
Keep defences current
At FirstNet, our team configures policies, integrates with your directory, and monitors threat
trends to keep defences current.
Assessment
Review current controls and recent incidents.
Implementation
DNS, routing, and policy setup with staged rollout.
Awareness
Optional user training and phishing simulations.
Operations
Monitoring, tuning, and regular reporting.
Explore the details
Case studies: Legal and retailReduced spam by over 99% and improved response to targeted phishing. · Continuity service ensured email…

Legal
Reduced spam by over 99% and improved response to targeted phishing.

Retail
Continuity service ensured email access during a provider outage.
Mimecast, run by FirstNetFirstNet deploys Mimecast in front of Microsoft 365, Google Workspace, hybrid Exchange or standalone SMTP…
Inbound protection
Mimecast, run by FirstNet
FirstNet deploys Mimecast in front of Microsoft 365, Google Workspace, hybrid Exchange or standalone SMTP and operates it as your managed service provider. As a Mimecast Elite Managed Services Partner, we handle onboarding, policy tuning, threat triage and escalation into Mimecast.
- Archiving with 30-day, 1-year, 7-year or 99-year retention
- Continuity via Outlook, web and mobile apps during Microsoft 365 outages
- Integrates with Entra ID, Google identity and SAML or OIDC providers
- API integrations with SIEM, SOAR, EDR and ticketing platforms
- Mimecast supports South African data residency preferences
Essentials
Anti-spam, anti-malware and anti-phishing with URL and attachment sandboxing, plus basic awareness nudges. A stronger front door than native filtering.
Resilience (recommended)
Essentials plus impersonation and BEC protection, internal email protection after account compromise, managed DMARC, email continuity and a full awareness training programme.
Complete
Resilience plus Brand Exploit Protect, Sync & Recover, web security, Large File Send, Secure Messaging, a 99-year archive option and executive human-risk reporting.
Stop attackers spoofing your domainMimecast protects your users from incoming threats. SendMarc protects everyone else from emails pretending…
Outbound protection
Stop attackers spoofing your domain
Mimecast protects your users from incoming threats. SendMarc protects everyone else from emails pretending to be you. FirstNet runs a managed DMARC journey that authenticates every legitimate sender, then enforces p=reject so criminals cannot put your domain in the From line.
See who sends as you
We publish a monitoring-only DMARC record and gather reports from every mailbox provider. Most organisations discover 15 to 40 sending sources, some unrecognised.
Authenticate every sender
FirstNet engineers align SPF and DKIM across Microsoft 365, Google Workspace, marketing platforms, ERP, transactional and bespoke applications. Your admins execute changes under our guidance.
Enforce safely
Policy moves from p=none to p=quarantine to p=reject in phases, with go or no-go reviews and rollback guardrails, so legitimate marketing and transactional email keeps flowing.
Show your logo with BIMI
Once DMARC reaches quarantine or reject, BIMI can display your verified logo in Gmail, Apple Mail and Yahoo. Most providers require a Verified Mark Certificate.
How we switch you overMimecast onboarding follows five steps, with a hyper-care tuning window after cutover. Complex…
Onboarding
How we switch you over
Mimecast onboarding follows five steps, with a hyper-care tuning window after cutover. Complex environments, such as multiple domains, multi-tenant Microsoft 365 or legacy archive ingest, get a dedicated technical workshop before dates are committed.
- Confirm scope, mailboxes, domains, platform and technical contacts
- Technical workshop: MX, connectors, DMARC posture, identity, retention and continuity
- Document the cutover plan, baseline policies and DMARC roadmap
- Provision the Mimecast tenant, apply policies and set up integrations
- Phased MX cutover, mail-flow validation, hyper-care tuning, then live support
We’ve got your security covered. Choose us as your long-term partner.
Why Choose FirstNet
Benchmark risk & plan improvements
We already have Microsoft Defender for Office 365. Why add Mimecast?
Mimecast adds an independent, specialist email layer in front of Microsoft 365, with separate threat intelligence, sandboxing and URL rewriting, plus continuity if Microsoft 365 itself is down. FirstNet also runs the tuning, threat workflows and DMARC programme for you.
What is the difference between Mimecast and SendMarc?
Mimecast is inbound protection: it stops phishing and malware reaching your users. SendMarc is outbound brand protection: it stops anyone spoofing your domain to attack your customers and suppliers. Most organisations need both.
Will enforcing DMARC break our marketing email?
Not with a phased approach. Every legitimate sending source is identified and authenticated before enforcement, policy moves through quarantine with rollback guardrails, and only then reaches reject.
How long does it take to reach p=reject?
It depends on how many sending sources you have and how quickly your platform owners can make authentication changes. We scope the journey during discovery rather than committing to a date upfront.
Is email archiving the same as backup?
No. An archive captures every inbound and outbound message under enforced retention, indexed for eDiscovery and legal hold. A backup is a point-in-time copy for restoring lost mailboxes. Most regulated organisations need both.
Who do we call when something goes wrong?
FirstNet's Rapid Response desk, 24/7, by email, phone or portal. Platform issues are escalated to Mimecast or SendMarc by FirstNet, so you never deal with the vendor directly.
What is DMARC and why does it matter?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is the email standard that lets you tell receiving mail servers what to do with messages that falsely claim to come from your domain. It works with SPF and DKIM. Without DMARC enforcement, anyone can put your domain in the From line of an email, which is how most business email compromise, invoice fraud and executive-impersonation attacks work. Only an enforced policy of p=reject actually blocks this spoofing.
Is an SPF record enough to stop email spoofing?
No. SPF only declares which mail servers are allowed to send for your domain, and attackers can still spoof the address your recipients actually see. DMARC is needed to enforce the check: it requires the visible From domain to align with an authenticated SPF or DKIM domain, and tells receiving mail providers to quarantine or reject mail that fails. Many organisations have an SPF record but no alignment and no enforced DMARC policy, which leaves their domain open to impersonation.
What is BIMI, and how do we get our logo shown in email inboxes?
BIMI (Brand Indicators for Message Identification) displays your verified brand logo next to your emails in supporting mailbox clients such as Gmail, Apple Mail and Yahoo. It only works once your DMARC policy is enforced at p=quarantine or p=reject. Most mailbox providers also require a Verified Mark Certificate, which is backed by a registered trade mark. FirstNet's optional BIMI add-on covers the BIMI record, logo hosting and help procuring the certificate.
How can we find out who is sending email using our domain?
A baseline DMARC report shows every system sending email as your domain. FirstNet publishes a monitoring-only DMARC record (or uses your existing one) and collects the reports that receiving mail providers send back, usually over two reporting cycles. Each source is then classified as legitimate, a forwarder or unauthorised. Most organisations discover far more senders than expected, often 15 to 40 sources including marketing platforms, ERP and finance systems, and some they do not recognise.
Does DMARC protect us against look-alike domains?
No. DMARC protects only your real domain, stopping attackers from sending email that uses your exact address. It does not stop criminals registering look-alike or typo-squat domains that resemble yours. FirstNet offers an optional brand-impersonation takedown add-on to SendMarc that detects look-alike domains and phishing infrastructure and runs a takedown workflow. Inbound protection such as Mimecast also helps detect look-alike domains in email reaching your staff.
How much work does our IT team need to do for a DMARC project?
Less than a do-it-yourself project, but some. FirstNet engineers identify every sending source and specify the SPF and DKIM changes needed across Microsoft 365, Google Workspace, marketing platforms, ERP and bespoke applications. Your administrators then make those DNS and platform changes under FirstNet's guidance, and FirstNet validates them. Progress through each enforcement step depends on how quickly your platform owners complete these changes, so having them engaged early keeps the project moving.
Can we keep sending and receiving email if Microsoft 365 is down?
Yes, if Mimecast email continuity is included in your contracted service. Continuity gives users a failover email experience so they can keep sending and receiving during a Microsoft 365 outage, through Outlook for Windows and Mac, a web interface or mobile apps. FirstNet designs a continuity runbook during onboarding and supports activation and communication during an outage. Continuity is an optional capability, so confirm it is in scope if this matters to your business.
Is Mimecast email data kept in South Africa?
FirstNet delivers the Mimecast managed service from South Africa, and the Mimecast platform supports South African data residency preferences. If your organisation needs specific contractual residency wording or mapping to regulatory controls, these requests are reviewed by FirstNet's product and legal teams before any commitment is made. Compliance remains a shared responsibility, depending on both the platform and your own configuration and governance.
What Mimecast service tiers does FirstNet offer?
FirstNet offers Mimecast email security in three tiers: Essentials, Resilience and Complete. Essentials is a stronger front-door filter for spam, phishing and malware with safer links and attachments. Resilience, the usual starting point, adds impersonation and business email compromise protection, managed DMARC and, where contracted, continuity and awareness training. Complete adds advanced brand protection and long-term archiving and eDiscovery for regulated or high-risk organisations.
Will a new email security layer block legitimate email?
FirstNet reduces this risk by starting with a safe baseline policy, monitoring results and continuously tuning allow and block rules to cut false positives. Clear quarantine and release workflows are set up so users and administrators can recover legitimate messages quickly. Ongoing tuning is part of the managed service rather than a one-off setup task, so the policies keep adjusting as your mail flow and threat patterns change.
Book an email security review to benchmark current risk and plan improvements.
From the Knowledge Hub
In-depth answers about Email Security & Threat Protection
- Which email platforms does FirstNet's managed Mimecast email security support?
- How can FirstNet show us every system that is sending email using our domain?
- Who do we call when FirstNet's Mimecast or SendMarc email security has a problem?
Your place in the stack
Security is layer 3 of 5.
Enriched by Sovereign AI Keep AI POPIA-aligned: prompts, documents and data are processed on South African infrastructure instead of foreign APIs. Explore the AI Factory →



