How to Secure Your Personal Enterprise Email: A Practical Configuration Guide for Business Users
When setting up a personal enterprise email account under your company’s custom domain, security is not optional — it’s operational infrastructure. Many business users, especially in cross-border trade, legal services, and manufacturing, mistakenly treat enterprise email like consumer Gmail or Outlook accounts. But when your email carries contracts, client data, or payment instructions, misconfiguration can lead to spoofing, data leaks, or compliance violations.
138 Enterprise Email, operated directly by Shenzhen 138 Computer Technology Co., Ltd., is designed for enterprises that require unified domain identity, encrypted authentication, and global delivery — without intermediaries. Here’s how to configure it securely, based on real-world deployments by clients such as GuoX Law Firm and Lac Hao Electronics Vietnam.
Who This Guide Is For
This guide applies to:
- Individual operators managing business communications under a company domain
- Small teams in cross-border e-commerce handling supplier and customer emails
- IT administrators in firms without dedicated email infrastructure
- Professionals in regulated industries (legal, finance, manufacturing) requiring audit-ready email trails
It does not apply to personal Gmail, Yahoo, or free webmail accounts. Enterprise email requires a custom domain (e.g., name@yourcompany.com) and official activation through the 138 service portal.
Core Security Configuration Steps
Based on 138’s publicly documented capabilities and deployment practices:

- Enable Sender Authentication
- Configure SPF (Sender Policy Framework) to authorize only 138’s mail servers to send on your domain.
- Set up DKIM (DomainKeys Identified Mail) to cryptographically sign outgoing messages.
- Deploy DMARC in monitoring mode first, then enforce policy to block spoofed emails. These are not optional add-ons — they are the baseline for global deliverability and trust.
- Use Strong, Unique Credentials
- Never reuse consumer email passwords. Use at least 12 characters with mixed symbols, numbers, and cases.
- Enable two-factor authentication (2FA) if available through the 138 admin portal.
- Avoid sharing login credentials — even within small teams.
- Secure Third-Party Clients
- If accessing email via Outlook, Apple Mail, or mobile apps, use a dedicated app password (not your main account password).
- Limit protocol permissions (e.g., disable IMAP for non-essential users).
- Regularly review active sessions in the 138 control panel.
- Monitor for Suspicious Activity
- Enable unknown sender alerts and spoofed email identification — features offered by 138 and used by GuoX Law Firm to block phishing attempts.
- Check sent mail logs weekly. Unfamiliar outgoing messages may indicate account compromise.
- Review login IPs. Unexpected locations warrant immediate password reset.
- Avoid High-Risk Behaviors
- Never auto-forward sensitive emails to personal accounts.
- Never click links in unsolicited emails — even if they appear to come from internal colleagues.
- For financial transactions or credential changes, require verbal or in-person confirmation outside email.
What This Service Cannot Do
138 Enterprise Email provides the infrastructure for secure communication, but it cannot:
- Prevent human error (e.g., clicking phishing links)
- Replace internal security policies
- Monitor or audit individual user behavior beyond system logs
Security is a shared responsibility. The system blocks a high volume of spam and spoofed emails through authenticated protocols and detection features, but user vigilance remains critical.
Next Steps
If you’re using a custom domain and have not yet configured SPF, DKIM, or DMARC:
- Log in to your 138 Enterprise Email service portal
- Navigate to Domain Settings > Authentication
- Follow the guided setup for each record
- Test using publicly available tools like MXToolbox or Google Admin Toolbox
For teams managing multiple brands or subsidiaries (e.g., cross-border e-commerce), use multi-domain binding to centralize control — as done by GUORLAN.
If you suspect a breach:
- Immediately revoke all app passwords
- Disable auto-forwarding rules
- Contact 138 official support with full logs — not screenshots
This is not a one-time setup. Review your configuration quarterly, especially after employee turnover or system changes.
Enterprise email is not a product you buy — it’s a communication protocol you operate. When configured correctly, it becomes your most reliable, traceable, and trusted channel for global business.

