Custom risk scores for inbound email

A custom risk score helps an organisation turn several email security signals into one practical decision. Rather than treating a sender reputation result, SPF failure or DMARC alignment issue as an isolated warning, you can combine them into a score that reflects your own exposure and tolerance for risk.

This approach is useful for Australian businesses dealing with invoice fraud, payroll impersonation and supplier scams. A small Melbourne retailer may need a simpler model than a large Sydney finance team, but both can use trust data and sender authentication results to decide whether a message should reach an inbox, be quarantined or receive urgent review.

Define what the score should decide

Start by choosing the action attached to each score range. A score is valuable only when it changes handling, such as allowing delivery, adding a warning banner, placing a message in quarantine or creating a security alert. Keep the first version easy for service desk staff to understand.

A practical scale runs from 0 to 100, where higher values indicate greater risk. For example, 0–24 could mean low risk, 25–59 could trigger monitoring, 60–79 could require quarantine and 80–100 could generate an incident response task. These bands should reflect your organisation’s workflow rather than generic security theory.

Gather reliable email signals

Use a domain trust score as the reputation component. It can indicate whether a sender domain has suspicious history, weak configuration or characteristics associated with spoofing and phishing. Consider the age and consistency of the domain, reputation trends and whether the sending identity matches the business relationship.

Authentication results provide a separate evidence stream. Capture SPF, DKIM and DMARC outcomes, including alignment, policy action and the visible From domain. A message that passes SPF but fails DMARC alignment should not receive the same treatment as one that passes both aligned DKIM and DMARC.

Build a weighted scoring model

Weights should reflect the signals that best predict harm in your environment. A sample model could assign 45 points to trust reputation, 25 to DMARC alignment, 15 to DKIM, 10 to SPF and 5 to message context. The numbers are a starting point, not a permanent rule.

Avoid allowing one passing check to erase multiple warning signs. A compromised legitimate domain may authenticate perfectly while still sending malicious mail. Similarly, a new Australian small business using a recently configured .au domain may have limited reputation history without being unsafe. Record the reason for each score so analysts can explain decisions.

Signal Example risk contribution Interpretation
Trust score 0–45 Reputation, history and suspicious indicators
DMARC alignment 0–25 Whether the visible From identity is authenticated
DKIM result 0–15 Integrity and signing validity
SPF result 0–10 Authorised sending infrastructure
Context adjustment -10 to +15 Business relationship, urgency and message behaviour

Treat authentication as evidence

Authentication should be interpreted in combination, not as a series of simple pass or fail labels. A DMARC pass with aligned DKIM is strong evidence that the visible domain authorised the message, while an SPF pass alone may be less useful when forwarding or third-party platforms are involved. Review anti-spoofing guidance when defining what conformance means for your scoring rules.

Use penalties for meaningful failures. A hard DMARC reject from a trusted domain may deserve more attention than a soft SPF failure from a low-volume sender. Also consider whether the sender’s policy is enforced. A domain with a monitoring-only DMARC policy can authenticate mail while providing weaker protection against impersonation.

Add business and regional context

Technical results should be adjusted by relationship and message behaviour. An unexpected request to change bank details, an urgent payroll instruction or a message using a new reply-to address should increase risk. A known supplier sending from its established domain may receive a modest reduction, but never an exemption from authentication checks.

Australian organisations can incorporate local operating patterns without relying on stereotypes. A message claiming to be from an Adelaide council, a Queensland construction supplier or an Australian Taxation Office service should be checked against the actual domain and relationship. Scam reports commonly arrive during busy periods such as end-of-financial-year processing, when rushed staff may overlook warning signs.

Set thresholds for human review

Create separate thresholds for delivery controls and analyst alerts. For example, a score of 70 may quarantine a message, while 55 may add a warning and 80 may open a high-priority incident. This prevents every medium-risk email from overwhelming a security queue.

Prioritise events that combine high trust risk with failed authentication. Sender reputation data can help teams prioritise incident response, especially when an Australian organisation receives a sudden wave of messages pretending to be a familiar bank, logistics company or government service.

Test, tune and govern the model

Run the scoring model in monitor-only mode before enforcing quarantine. Compare scores with confirmed phishing, legitimate newsletters, supplier invoices and internal test messages. Track false positives, missed threats, authentication failures and the time analysts spend investigating each category.

Review the model after domain changes, new mail providers and major incidents. Keep an audit record of weights, thresholds and overrides, and limit access to scoring data because sender information can form part of security records. Publish clear handling rules alongside the model, with relevant legal notices available to administrators and users who rely on the service.

A well-maintained custom risk score becomes a consistent decision layer between raw email telemetry and human action. It gives security teams a defensible way to combine sender reputation, domain authentication and business context while keeping controls understandable for staff across Australia.