Information Security

Email Security Policy

An email security policy template defining acceptable use of corporate email, phishing defence, authentication standards including SPF, DKIM and DMARC, encryption of sensitive content and retention, aligned to ISO 27001, NIST SP 800-53 and GDPR.

14-18 pages|Updated 2026-09-11|4 frameworks

What's Included

1. Purpose & Scope

Defines the objective and the accounts and systems covered.

Policy ObjectiveCovered AccountsRoles and Responsibilities

2. Acceptable Use

Sets what corporate email may and may not be used for.

Business UseLimited Personal UseProhibited ContentAuto-Forwarding Restrictions

3. Phishing & Social Engineering

Defines detection, reporting and user obligations.

User Reporting ObligationReporting MechanismSimulation ProgrammeResponse Procedure

4. Email Authentication

Establishes the sender authentication records that prevent domain spoofing.

SPFDKIMDMARC Policy and EnforcementMonitoring of Reports

5. Content Protection

Governs encryption and handling of sensitive information in email.

Transport EncryptionMessage EncryptionAttachment HandlingData Loss Prevention

6. Retention & Legal Hold

Defines how long email is kept and how holds are applied.

Retention PeriodsArchivingLegal HoldDeletion

7. Monitoring & Review

Sets the monitoring an employer performs and the review cadence.

Monitoring Scope and NoticeLoggingMetricsAnnual Policy Review

Frequently Asked Questions

What should a email security policy include?

A comprehensive email security policy should include purpose & scope, acceptable use, phishing & social engineering, email authentication, and more. This template covers 7 key sections aligned to ISO 27001, NIST SP 800-53, GDPR, NIST CSF requirements.

Which frameworks require a information security policy?

Major frameworks requiring information security policies include ISO 27001, NIST SP 800-53, GDPR, NIST CSF. This template maps directly to their control requirements, making it easier to demonstrate compliance across multiple standards.

How often should a email security policy be reviewed?

Best practice is to review your email security policy at least annually, or whenever significant changes occur in your organisation, technology environment, or regulatory landscape. Most frameworks including ISO 27001 and NIST CSF require documented policy review cycles.

Build Your Compliance Programme

Pair this policy template with our compliance platform to map controls across 686+ frameworks, run self-assessments, and get AI-powered compliance advisory.

Get Started Free →

Free forever — no credit card required