Arizona Computer Guru LLC

Email Infrastructure Assessment
and Migration Recommendation

Confidential — Prepared for Quantum WMS
Prepared for
John & Sheila Velez, Quantum WMS
Date
May 26, 2026
Prepared by
Mike Swanson

Following our review of Quantum WMS's current email infrastructure, we have identified significant security deficiencies in your existing Intermedia hosted Exchange setup.

We are recommending a migration to Microsoft 365 Business Premium with Mailprotector as a managed email security frontend. This solution is technically superior, more cost-effective, and fully satisfies your regulatory compliance requirements under FINRA Rule 4511 and SEC Rule 17a-4.

Before we finalize the migration plan, we need one item from Sheila (detailed at the end of this document).

Current State: Intermedia Hosted Exchange

Your email is currently hosted by Intermedia on their Exchange Server cluster. This is an important distinction: Intermedia is not running Microsoft's cloud. They run Exchange Server software in their own data center, the same software that runs on an on-premises server. This has major security implications.

Your Domain Has No Email Security Records

Our DNS assessment revealed the following active security risks:

DMARC
Missing
Anyone can send email appearing to come from @quantumwms.com with zero enforcement. This is the primary mechanism used in CEO fraud and vendor impersonation attacks.
SPF
Misconfigured (2 records)
Internet standards allow only one SPF record per domain. Having two causes unpredictable authentication failures and can result in your legitimate email being rejected as spam.
DKIM
Not Configured
DKIM cryptographically signs outbound email, proving it originated from your server and was not tampered with in transit. Without it, recipients cannot fully authenticate your email.
DNSSEC
Not Signed
Your domain has no cryptographic protection against DNS hijacking or spoofing attacks at the infrastructure layer.
These issues exist today, regardless of which email platform you use. Correcting them is a required step and one we will handle as part of the migration.

Exchange Server CVE Exposure

Because Intermedia runs Exchange Server — not Exchange Online — your infrastructure is subject to the same critical vulnerabilities that have affected on-premises Exchange servers globally:

Vulnerability Disclosed Impact
ProxyLogon (CVE-2021-26855)March 2021Full server compromise, mass-exploited worldwide
ProxyShell (CVE-2021-34473)August 2021Remote code execution without authentication
ProxyNotShell (CVE-2022-41040)October 2022Actively exploited before patch availability
OWASSRF (CVE-2022-41080)December 2022Used in the Rackspace hosted Exchange breach

Microsoft patches Exchange Online the same day vulnerabilities are disclosed. Intermedia patches their hosted clusters on their own schedule. The gap between disclosure and deployment is precisely when attacks occur.

Recommended Solution: M365 Business Premium + Mailprotector

Microsoft 365 Business Premium — $22/user/month

A complete cloud-native productivity and security platform that replaces Intermedia entirely:

ServiceWhat It Provides
Exchange OnlineCloud email, Microsoft-managed, same-day security patching
Office Apps (Desktop)Word, Excel, Outlook, PowerPoint on up to 5 devices per user
Microsoft TeamsChat, video conferencing, file collaboration
OneDrive / SharePoint1 TB cloud file storage per user
Microsoft PurviewFINRA/SEC 17a-4 compliant email archiving (WORM storage) — included
Defender for Office 365Safe Links, Safe Attachments, advanced anti-phishing
Microsoft Entra ID P1Conditional Access, MFA enforcement, sign-in risk detection
Microsoft IntuneMobile device and PC management

Mailprotector — ACG-Managed Email Security Frontend

Mailprotector sits in front of Exchange Online as an additional filtering layer: inbound spam and malware are blocked before mail reaches your inbox. ACG configures and monitors it; you do not need to manage it.

Sender Mailprotector Exchange Online Your Inbox
Inbound: filtered for spam and malware before delivery  ·  Outbound: DKIM-signed, SPF-aligned, DMARC-enforced

Security Posture Comparison

Capability Intermedia (Current) M365 + Mailprotector
Exchange CVE Exposure Yes — Server CVEs No — Exchange Online
Same-Day Security Patching No Yes
Inbound Threat Filtering Basic Mailprotector + Defender
Safe Links / Safe Attachments No Yes
MFA Enforcement Policy Manual, per-user Conditional Access (Entra P1)
DMARC / DKIM / SPF Not managed ACG-configured
FINRA/SEC 17a-4 Archiving Extra-cost add-on Included (Purview)
Desktop Office Apps No Yes
Mobile Device Management No Yes (Intune)
Sign-In Risk Detection No Yes (Entra P1)

Regarding Your Broker/Dealer Compliance Requirement

You have indicated that your Broker/Dealer may require Intermedia for compliance purposes. We want to address this directly.

What FINRA Rule 4511 & SEC Rule 17a-4 Actually Require
  • Electronic communication retention in non-rewritable, non-erasable (WORM) storage
  • Minimum retention: 3 years readily accessible, 6 years total
  • Records indexed and available for regulatory inspection on demand
  • Supervisory review capability
Microsoft 365 is fully FINRA/SEC 17a-4 compliant. Microsoft Purview has received a formal compliance assessment from Cohasset Associates confirming that Exchange Online meets the requirements of SEC Rule 17a-4(f) and CFTC Rule 1.31. The majority of FINRA-registered broker/dealers run on Exchange Online today.
The regulations specify outcomes, not vendors. FINRA Rule 4511 and SEC Rule 17a-4 do not name Intermedia or any specific platform as a required provider. If your Broker/Dealer's written policy names Intermedia explicitly, we would consider that extraordinary and recommend reviewing it with your compliance attorney.
Action Required — Sheila

Please Provide the Written Policy Before Our Meeting

Please locate and provide the written policy from your Broker/Dealer that specifies your email and security compliance requirements.

We are looking for any document that defines which platforms are approved or required, specifies archiving or retention standards, or names Intermedia as a required provider.

Please have this document — or confirmation that no such document exists — ready for our meeting on Tuesday, May 27 at 2:00 PM.

Proposed Timeline

Now → May 27
Sheila obtains B/D compliance policy; confirm Intermedia is not mandated
May 27, 2:00 PM
Review policy; confirm migration go/no-go; finalize license counts
May 28 – 29
Purchase Business Premium licenses; configure tenant and mailboxes
May 30 – 31
Set up Mailprotector; configure DMARC, DKIM, SPF; test mail flow
June 1 – 2
Mail migration from Intermedia; DNS cutover to Exchange Online
June 3
Current GoDaddy O365 Essentials lapses. New Business Premium is live before this date.