Secure email infrastructure

for councils and public bodies

epost.plus is professional email for the public sector, built on the enterprise-grade Axigen server. It provides the sender authentication that public bodies are expected to have in place — SPF, DKIM and DMARC — together with multi-factor authentication (2FA). We work under ISO 9001 and ISO 27001 certification, and our servers sit in UK or EU data centres, so you can give a documented answer to where your correspondence is held.

Email in the public sector — a standard to meet, not a preference

What public sector email is expected to prove

Public bodies are held to a higher bar than ordinary business email. A public sector mailbox has to prove that messages genuinely come from the organisation that claims to have sent them, which in practice means SPF, DKIM and DMARC on every domain. On top of that, sign-in has to be protected by more than a password, so multi-factor authentication (2FA) is part of the baseline.

Risk management, monitoring and incident reporting

Public sector organisations are expected to manage cyber risk actively rather than react to it: to monitor their systems, evidence how they are configured, report incidents, and be able to show all of this at audit. Email is usually the first area examined, because it is the channel through which most attacks arrive.

What public sector email has to provide

In summary, email for public bodies needs to provide:

  • SPF (Sender Policy Framework) — a mechanism that verifies whether the sending server is authorised to send mail on behalf of a given domain;
  • DKIM (DomainKeys Identified Mail) — a digital signature confirming that the content of a message has not been altered in transit;
  • DMARC (Domain-based Message Authentication, Reporting and Conformance) — a protocol defining what to do with messages that fail SPF or DKIM checks, together with a reporting mechanism;
  • Multi-factor authentication (2FA) — an additional layer of verification at sign-in, beyond the password alone;
  • Transport encryption (SSL/TLS) — protection of connections across every mail protocol;
  • Data protection — processing on servers in UK or EU data centres, supporting compliance with UK GDPR and the Data Protection Act 2018.

epost.plus provides all of this as standard, with no additional configuration needed at your end.

Councils under pressure — rising threats and limited IT resources

Local councils and public bodies are an increasingly common target for cyber attacks. Many public sector organisations still do not have SPF, DKIM and DMARC configured correctly, which leaves them exposed to spoofing — someone impersonating a trusted council address to extract information from residents.
At the same time most councils, particularly smaller district and parish authorities, work with a limited IT budget and employ no cyber security specialists. Configuring and maintaining secure email infrastructure in-house is a challenge many simply cannot afford.
epost.plus solves that problem. We provide ready-made, fully configured email for the public sector — with every required safeguard in place, a daily backup and someone to contact when you need help. There is no need to hire additional IT staff or invest in server infrastructure. We move mailboxes across from your current provider without interrupting your work and configure the security for you.

Public sector email from epost.plus — the features that matter

Authentication as standard

SPF, DKIM and DMARC are active on every domain as standard, so the mail your residents receive can be verified as genuinely yours. Multi-factor authentication (2FA) is available on every account.

S/MIME and PGP encryption

Every message sent from an official domain can be encrypted with S/MIME or PGP. A digital signature proves the content has not been altered. Strong protection for correspondence that carries personal data.

Bitdefender antivirus protection

Advanced anti-spam and antivirus systems integrated with Bitdefender technology. Signature databases update automatically. Protection against phishing, ransomware and malware.

Official email on your own domain

As many accounts as you need on the institution’s domain — for example enquiries@yourcouncil.gov.uk. Unlimited storage on every account. Aliases, forwarding and auto-replies.

The full WebMail client

Full access to mail, calendar, contacts and tasks through the browser. Multiple languages and themes. Integration with the eM Client app.

Shared mailboxes

Mail folders shared across the organisation. Joint handling of shared mailboxes such as enquiries@, committees@ and foi@. The full correspondence history available to every authorised member of staff.

Migration without disruption

Mailboxes moved across from your current provider without interrupting your work. SPF, DKIM and DMARC configured. The whole environment checked. Correspondence carries on throughout.

Calendar and tasks

Built-in calendar with CalDAV support. Task management with reminders. Synchronisation across devices — computer, tablet, phone.

Two-factor authentication

Two-step sign-in with SMS or Cisco Duo. Application passwords for email programs. Losing one device does not mean losing access.

Email for the public sector — frequently asked questions

Yes. SPF, DKIM and DMARC are active as standard on every domain we host, so mail sent from your addresses can be verified as genuinely yours. Multi-factor authentication (2FA) is available on every account. You do not have to take our word for it — the configuration of any domain is publicly checkable with a standard DMARC or SPF lookup tool.
SPF (Sender Policy Framework) verifies that a message was sent from an authorised server. DKIM (DomainKeys Identified Mail) digitally signs every message, confirming its integrity. DMARC (Domain-based Message Authentication, Reporting and Conformance) sets out what to do with messages that fail those checks, and produces reporting. Without them in place, criminals can impersonate official addresses and send fraudulent messages to residents in your name.
Without sender authentication, anyone can send email that appears to come from your address. For a public body that usually means residents being targeted with convincing fraud in the organisation’s name — and the organisation carrying the reputational damage. If personal data is compromised as a result, a breach is reportable to the ICO within 72 hours under UK GDPR.
We work under ISO 9001 and ISO 27001 certification — quality management and information security respectively — which means our security management is audited against international standards rather than self-declared. On top of that we provide layered protection, a daily backup, security monitoring and message encryption.
We support the whole migration. We move the contents of your mailboxes from your current provider, set up the accounts on your official domain, activate SPF, DKIM and DMARC, and verify the whole environment. Email keeps running throughout, so correspondence carries on without a gap. The process passes unnoticed by staff and residents alike.
Our servers are located in UK or EU data centres. You get a clear, documented answer to where your correspondence is held, which is what you need for your own records and data protection impact assessments under UK GDPR and the Data Protection Act 2018.
Yes. The email works on every device. Use WebMail in a browser, set up an email app (Outlook, Thunderbird, Apple Mail, eM Client) over IMAP or POP3, or use Exchange ActiveSync, which is included and gives instant synchronisation of mail, calendar and contacts on mobile devices.

A dedicated mail server for large public bodies

For county councils, unitary and combined authorities, large city councils and central government bodies that need full control over their mail infrastructure, we offer a dedicated mail server built on Axigen technology. It suits organisations that require data isolation, their own security policies, non-standard configurations and the greatest possible independence — with the same sender authentication, monitoring and daily backup applied across every domain on the server.