Email security intake that captures mailbox count and change authority
Every email security enquiry captures the concern type, email platform, and mailbox count behind the request, plus header screenshots and DNS records, so you can tell a live compromise from a routine policy review before the scoping call.
The exact intake your email security leads complete
This is the real 6-question guided intake for Email Security — the same flow your customers finish before you ever pick up the phone.
What a qualified email security lead should tell you
Assessment and remediation of email-based security risks—phishing, spoofing, business email compromise, and weak authentication—covering both active-incident response and preventive hardening of an organization's email platform.
- Best Describes Current Email
- Email Platform Organization Or
- How Many Mailboxes Be
- Have Authority Approve Changes
- Soon This Issue Addressed
- Protections Interested In Adding
The questions your team needs answered
Every email security intake asks these — and why each one matters.
| Question | Why it matters |
|---|---|
| What best describes your current email security concern? | The reported concern type carries the heaviest scoring weight and separates active incident-response cases from preventive or policy-review engagements. |
| Which email platform does your organization or account use? | Knowing the exact email platform lets you scope the right remediation tools and authentication approach before the call. |
| Roughly how many mailboxes need to be protected? | Mailbox count signals engagement size, from a small business account to a 51+ mailbox organization needing a broader rollout. |
| Do you have authority to approve changes to this email system? | Change-approval authority separates leads who can authorize remediation work from those who first need to loop in a decision-maker. |
| How soon do you need this issue addressed? | Stated urgency shows whether the request needs an immediate response or can be scheduled as a standard scoping call. |
| Which protections are you interested in adding or improving? | The specific protections requested tell you which parts of the engagement — filtering, authentication, encryption, or training — to prepare for before the call. |
How Cliont scores email security leads
Every answer is weighted automatically — no manual review required.
Value signals
- Ongoing phishing or spoofing attacks
- Setting up preventive protections
- Reviewing policies or configurations
- Not sure
- Have Authority Approve Changes: yes
- Within this week
Urgency signals
- Suspected active compromise or breach
- Immediately
See the lead your team receives
Email Security Lead — Suspected Active Compromise
From first click to qualified lead
Follow prospects and clients through one smooth, guided flow.
They land & meet you
Your video greeting plays instantly — a real face instead of a blank form.
They explain the project
Smart questions adapt to their project and capture the full scope.
They share the details
The scope and any documents come attached, so you can scope before the first call.
You get a ready lead
Scored and qualified — waiting for you to win it.
Built for email security workflows
| Cliont capability | Email Security application |
|---|---|
| Weighted scoring engine | Ranks 'suspected active compromise' well above 'reviewing policies or configurations' so breach reports never sit behind planning enquiries in your queue. |
| Multi-select capture | Records which protections a client wants improved — filtering, DMARC, encryption, access controls, or training — so the scoping call starts with a defined scope instead of a discovery conversation. |
| Authority gating | Flags leads who answer 'no' on change-approval authority so you can request the actual decision-maker before booking a scoping call that stalls. |
| CRM routing | Sends each qualified email security lead into your CRM tagged with platform, mailbox count, and urgency so account setup starts with the right sizing information. |
Common email security lead scenarios
Suspected active compromise
The requester reports a suspected breach and needs it addressed immediately, pairing the highest-weighted concern option with the top urgency answer for instant flagging.
Ongoing phishing campaign
Phishing or spoofing attacks are already underway with a within-the-week timeline and a mid-size mailbox count, warranting a fast but not emergency response.
Preventive protection rollout
The client is setting up protections proactively with a longer 'just planning ahead' timeline and interest in domain authentication or awareness training, better suited to a scheduled engagement.
Requester lacks change authority
A real phishing concern is reported but the person answers 'no' on approving system changes, signaling you'll need to loop in a decision-maker before scoping.
Policy or configuration review
A larger organization wants an audit of existing email security policies rather than incident response, combining a lower-urgency concern type with a 51+ mailbox count.
Connect Cliont to your workflow
Send leads
HubSpot, HighLevel, Salesforce, JobNimbus
Book projects
Google Calendar, Outlook Calendar, Calendly
Notify your team
Email, SMS, Slack
Automate follow-up
Zapier, Webhooks, API
Simple, transparent pricing
Choose the plan that works for your business.
Professional
Unlimited intake forms and leads for your growing business.
- Unlimited intake forms
- Custom video greetings
- AI-powered voice bot
- English + Spanish support
- Automatic lead scoring
- Digital estimates & e-signatures
- Photo, video & file upload
- Advanced analytics dashboard
Pay Per Lead
Only pay when you receive a qualified lead.
- Unlimited intake forms
- Custom video greetings
- AI-powered voice bot
- English + Spanish support
- Automatic lead scoring
- Digital estimates & e-signatures
- Photo, video & file upload
- Charged only for submitted leads
More cybersecurity intake templates
Email Security lead-intake FAQs
How does the intake tell an active breach apart from a routine phishing complaint?
The first question asks the client to select their current concern, and 'suspected active compromise or breach' carries the highest weight of any option, so it's flagged well above general phishing reports or policy reviews.
Does the client's email platform get captured before the scoping call?
Yes — the intake records whether they're on Microsoft 365, Google Workspace, another hosted provider, or self-hosted mail, so you know which authentication and filtering tools apply before you speak with them.
What if the person filling out the form can't approve changes themselves?
The intake asks directly whether the respondent has authority to approve changes to the email system; a 'no' answer scores lower and tells you to identify the actual decision-maker before committing scoping time.
Can the same intake handle a 5-person business and a 500-mailbox organization?
Yes, mailbox count is captured as a range from 1-5 up to 51 or more, so you can size the engagement and staffing needs before the first call.
What happens if a client selects 'Not sure' for their security concern?
It's still scored and delivered rather than discarded, since uncertainty is common among non-technical requesters, but it's ranked below clear breach or active-attack reports so you can prioritize accordingly.
Which specific protections can a lead express interest in?
The catalog captures multi-select interest in spam/phishing filtering, SPF/DKIM/DMARC domain authentication, encryption, access controls, and awareness training, so you know what to prepare for before the call.
Turn email security visitors into qualified clients
Give every email security visitor a guided intake instead of a dead contact form — and get a scored, qualified lead before you take the first call.