Skip to content

Services

Six services that cover the whole estate.

Engagements are scoped individually, but they overlap by design — a migration that ignores deliverability creates a reputation problem, and an archive that ignores retention creates a legal one. Most clients start with one service and add others as the estate is brought under control.

01 — Platform

Managed mail hosting

We operate the mail platform as a service: mailboxes, transport, routing policy and the DNS that holds it together. You keep ownership of the domains and the data; we keep the pager.

Monthly retainer Per mailbox 24/7 rota

Scope

Mailbox provisioning and lifecycle, inbound and outbound transport, MX and relay topology, TLS policy including MTA-STS and TLS-RPT, alias and distribution-group management, shared mailboxes and delegation, mobile and desktop client policy, and the DNS records that underpin all of it.

Included by default

  • Quarterly configuration review against a written baseline, with drift reported.
  • Change management with named approvers and a documented backout for every change.
  • Second-line escalation for your helpdesk, in English, Latvian or German.
  • Annual restore test with written evidence you can hand to an auditor.

Not included

End-user device support, licence resale, and marketing-campaign sending. We deliberately do not operate bulk-marketing platforms — see deliverability for how we treat that boundary.

02 — Project

Migration

Moving a mail estate from on-premises to cloud, or between cloud tenants, without asking the business for a service window. Pre-seed, verify, cut over, coexist, decommission.

Fixed project fee 6–14 weeks typical Backout plan

Scope

Estate discovery and mailbox sizing, target tenant design, identity and directory synchronisation, staged content pre-seeding with delta passes, calendar and free/busy coexistence, shared mailboxes, delegates, public folders and resource rooms, client reconfiguration, sending-source cutover, and decommissioning of the source platform.

Typical phases

PhaseDurationOutput
Discovery1–2 weeksInventory, risk register, sizing model
Design1–2 weeksTarget architecture, cutover runbook
Pre-seed2–6 weeksBulk sync complete, deltas running
Cutover1 weekendMX moved, coexistence live
Stabilise2–4 weeksHypercare, then decommission

For a fuller account of how the cutover itself is sequenced, see Planning a zero-downtime mailbox migration.

03 — Assessment

Deliverability audits

A fixed-fee, time-boxed assessment of why your mail is or is not arriving, ending in a prioritised remediation plan that your own team could execute if they wanted to.

Fixed fee 3–4 weeks Vendor-neutral

Scope

Full inventory of systems sending under your domains; SPF, DKIM and DMARC record review including alignment mode and DNS lookup budget; aggregate report analysis across a 30-day window; IP and domain reputation review at the major mailbox providers; blocklist position; bounce and complaint handling; feedback-loop enrolment; list acquisition and hygiene practice; and content and header construction where it is materially affecting placement.

Deliverables

  • Written findings report with severity, evidence and reproduction steps.
  • Sending-source register — usually the single most valuable artefact produced.
  • A sequenced remediation plan with an explicit path to DMARC enforcement.
  • Ninety-minute walkthrough with your infrastructure and marketing teams together.

We do not sell the remediation. Audit findings are yours to implement in-house, hand to your existing provider, or retain us for. The audit fee is not credited against a retainer, precisely so the findings stay honest.

04 — Platform

Anti-spam and filtering

Inbound protection tuned to your actual correspondence patterns, with a quarantine workflow your helpdesk can operate without escalating every release request.

Monthly retainer Policy tuning FP review SLA

Scope

Inbound policy design and threshold tuning, sender and recipient policy exceptions, attachment and URL handling, inbound authentication enforcement (rejecting mail that fails your correspondents' published DMARC policy), display-name and lookalike-domain detection for internal impersonation attempts, quarantine notification cadence, and end-user release workflow.

Operating commitments

ItemTarget
False-positive review, business hoursWithin 2 hours
Policy change request, non-urgentNext business day
Active phishing campaign responseWithin 30 minutes, 24/7
Quarantine retention30 days, configurable

We tune toward a low false-positive rate deliberately. A filter that quietly eats a purchase order costs more than one that lets through a nuisance newsletter, and users who stop trusting quarantine stop reporting real phishing.

05 — Governance

Archiving and retention

Journal-based capture into an EU-resident archive, governed by a retention schedule that reflects real obligations rather than the reflex to keep everything forever.

Monthly retainer EU residency Legal hold

Scope

Journal rule design and capture verification, archive ingestion and indexing, retention schedule development mapped to record classes, disposition and defensible deletion, legal hold placement and release, search and export for internal investigations or supervisory requests, and the audit evidence that proves the policy is actually being applied.

Design principles

  • Retention is set per record class, never per mailbox or per person.
  • Backups are not an archive, and an archive is not a backup. We keep them separate.
  • Deletion must be real and demonstrable, including through backup expiry.
  • Legal hold overrides disposition and is logged with who placed it and why.

Retention design under GDPR is covered in more depth on the compliance page, and practically in Retention policy design for email archives.

06 — Operations

Monitoring and alerting

Synthetic probes that test the path a real message takes, plus the reputation and authentication signals that predict a problem before your users report one.

Included with retainer Standalone available 24/7 rota

What we watch

Delivery path
Synthetic send-and-receive probes through each inbound and outbound route, measuring end-to-end latency rather than host reachability.
Queues
Depth, age and deferral reason codes, alerting on trend rather than a single threshold breach.
Authentication
Continuous DMARC aggregate ingestion with alerting on new sending sources and on alignment-rate regression.
Reputation
Domain and IP reputation at the major mailbox providers, plus position on the blocklists that actually influence delivery.
Certificates and DNS
TLS expiry, DNSSEC validity, MTA-STS policy reachability, and unexpected changes to MX, SPF, DKIM or DMARC records.
Capacity
Mailbox and archive growth against provisioned capacity, projected forward to a date rather than a percentage.

Alerts route to a staffed rota with a fifteen-minute P1 response target. Every page that fires is reviewed monthly, and any alert that has never once been actionable is deleted rather than tuned.

Not sure which of these you need?

That is a normal place to start. Most engagements begin with a scoping call and a short discovery, after which the right shape is usually obvious to both sides.