3 specs procurement must set for secure fax to email in Australia

Secure fax to email communications infrastructure

Secure fax to email, done properly on premise, is an inbound fax captured on an MFP or fax server, converted to a file, and forwarded over enforced TLS to a controlled internal mailbox — never a cloud fax provider. It needs enforced transport encryption, email authentication on the sending domain, and locked-down admin access on the device itself. Specify those three things correctly and the fax lands where it should, encrypted the whole way, with a clean audit trail behind it.

TL;DR:

  • Proper on-premise secure fax to email relies on enforced TLS, authenticated SMTP relays, and locked-down admin access to prevent leaks.
  • Protecting the device admin interface, SMTP transport, and recipient inbox is essential for maintaining end-to-end encryption and compliance.
  • Compliance frameworks like APP 11 and the Essential Eight demand controls such as MFA, firmware patching, centralized logging, and enforced TLS protocols.
  • Rolling out and maintaining secure fax-to-email requires formal planning, regular testing, and ongoing policy enforcement to avoid drift out of compliance.
  • Outsourcing management to a provider with clear SLAs on patching, logs, and security controls ensures ongoing compliance and reduces internal workload.

Global Office Machines
Equip Your Office With Confidence

Global Office Machines supplies and services multifunction devices, fax machines, and related office equipment for businesses across Australia.
Explore office equipment

Table of Contents

How does on-premise secure fax to email actually work?

The mechanics are simpler than most procurement documents make them sound. A fax call comes in over the phone line, the MFP or fax server appliance captures the image, converts it to a PDF or TIFF, then hands it to an internal mail gateway over SMTP for delivery to a nominated mailbox or workflow folder.

That handoff point is where most of the risk lives. There’s a meaningful difference between an MFP doing this natively (the device itself talks SMTP to your mail server) and a dedicated on-prem fax server or fax‑to‑email appliance sitting between the phone line and your network, which typically gives IT more granular control over routing, logging and encryption settings.

Three touchpoints need protection, and each gets skipped in a rushed rollout:

  • The device admin interface — often left on default credentials or exposed without MFA.
  • The SMTP hop — the leg between device and mail server, where transport encryption either is or isn’t enforced.
  • The recipient inbox — frequently a shared mailbox with far looser access controls than anyone realises.

Get the flow right and the fax never touches an external service. Get the SMTP leg wrong, though, and you’ve built a system that looks compliant on a datasheet but leaks personal information in plain text the moment it leaves the device. That’s the gap between “supports encryption” and “encryption enforced by default” — a distinction vendors rarely volunteer.

What security controls does Australian guidance actually require?

Two frameworks do the heavy lifting here, and procurement should be quoting both by name in any tender document.

APP 11 requires reasonable steps to protect personal information during storage and transmission, and to destroy or de-identify it once it’s no longer needed. A fax containing a client’s date of birth or Medicare number is personal information the moment it’s captured, so APP 11 applies from the second the device answers the call.

The Essential Eight maps cleanly onto device-level controls, even though it was written with general IT systems in mind rather than MFPs specifically:

  • Restrict administrative privileges on the device to named accounts only.
  • Enforce MFA for any remote device administration.
  • Patch firmware on a defined schedule, not “whenever someone remembers.”
  • Maintain backups of device configuration and logs.
  • Log admin actions and SMTP delivery events centrally.

On transport, insist on TLS 1.2 as a floor and TLS 1.3 where the device supports it. Understand the difference between opportunistic and enforced TLS: opportunistic TLS attempts encryption but silently falls back to plain text if the receiving server doesn’t support it, which defeats the purpose entirely. MTA-STS forces a policy of encrypted delivery only, refusing the fallback.

Email authentication matters more than most specifications acknowledge. If the device sends as “fax@yourcompany.com.au”, SPF, DKIM and DMARC all need to recognise that sending pattern, or the message risks landing in quarantine before anyone reads it.

Pro Tip: Route every device through a single authenticated SMTP relay rather than letting each MFP send directly. It’s far easier to get SPF and DKIM right for one relay IP than for a dozen printers scattered across three floors.

Network segmentation and passworded attachments round out the picture. Because email itself isn’t inherently secure, sensitive faxes (medical records, financial documents) often warrant a secure inbox workflow rather than a plain shared mailbox, particularly where multiple staff have access.

How do you implement and validate a secure fax-to-email deployment?

Treat this as a formal procurement and configuration cycle, not a one-off install job. Miss a step here and you’ll find out during an audit, which is the worst possible time.

  1. Write the spec first. Require TLS 1.3 support, admin MFA, a documented firmware update SLA and encrypted local storage for logs before you shortlist a single device.
  2. Design the network path. Place fax devices on a management VLAN, route outbound mail through an authenticated internal SMTP relay, and enforce MTA-STS on the domain.
  3. Install with certificates in place. Load the device’s TLS certificate, update firmware to the current release, and configure authenticated SMTP credentials rather than anonymous relay.
  4. Fix SPF before go-live. Add the device or relay IP to your SPF record, or route everything through the relay so SPF only needs one entry. Skip this and messages get quarantined or rejected by the receiving mail server, a failure mode that shows up constantly in the field but rarely appears in vendor documentation.
  5. Test before trusting. Send test faxes, confirm delivery without quarantine, verify DKIM signing on the relay, check that logs are reaching your SIEM, and run a vulnerability scan against the device’s exposed services.

Reviewing printer security best practices alongside this checklist catches configuration gaps a spec sheet alone won’t surface — default community strings on SNMP, for instance, or an admin panel still reachable from the general office VLAN.

Running a compliant fax-to-email service day to day

Deployment is the easy part. Keeping it compliant for the next three years is where most organisations quietly drift out of scope.

Retention needs a defined policy, not an assumption. APP 11.2 requires destruction or de-identification once information is no longer needed for the purpose it was collected — which means someone has to decide, in writing, how long a fax containing a client’s tax file number sits in a mailbox before it’s purged.

Build these into a standing operational rhythm rather than a launch-day checklist:

  • Forward device and SMTP logs to centralised logging, not local device storage that gets overwritten after a few thousand entries.
  • Schedule backups of device configuration and review them quarterly, not “as needed.”
  • Patch firmware on a fixed cadence and log every change for audit purposes.
  • Restrict privileged access to admin accounts and revoke them the day someone changes roles.
  • Document an incident response path for misdelivery or suspected compromise, and actually test it once a year rather than filing it and forgetting it.

None of this is exciting work, but it’s the difference between a system that was compliant on installation day and one that stays compliant. A printer fleet management approach that treats fax-capable MFPs as standard network endpoints, subject to the same patching and logging discipline as laptops, closes most of the gap here.

Why a managed on-prem setup beats a DIY fax-to-email rollout

Why a managed on-prem setup beats a DIY fax-to-email rollout — overview diagram

Most IT teams underestimate how much ongoing work a “set and forget” fax-to-email deployment actually demands. Firmware doesn’t patch itself, SPF records drift as devices get added or replaced, and log review has a habit of sliding down the priority list until an auditor asks for six months of history nobody kept.

A managed arrangement shifts that maintenance burden onto a provider with an SLA attached to it, which is usually the more realistic option for a business without a dedicated print security specialist on staff. When evaluating a managed print partner, insist on specifics: a firmware patching cadence in writing, log retention terms, and a documented escalation path for suspected compromise. Vague promises of “we handle security” aren’t a control, they’re a hope.

— Matthew

Get your secure fax-to-email setup right the first time

Getting the SMTP relay, SPF records and admin controls right on a handful of scattered MFPs is exactly the kind of detail that eats an internal IT team’s week. Global Office Machines runs managed print services across NSW, VIC, QLD, WA and SA, handling installation, firmware patching schedules and ongoing configuration so your fax-to-email path stays inside spec rather than drifting out of it six months after go-live.

Authorised dealers can spec a multifunction printer or on-prem fax server that supports enforced TLS and authenticated SMTP relay from day one, rather than retrofitting security onto hardware that was never built for it. If sustainability sits alongside security on your procurement criteria, refurbished devices offer an alternative to new units without cutting corners on the controls that matter. Get in touch for a site survey or a tender/spec review, and we’ll help you land on a deployment that passes an audit as easily as it passes a demo.

Where to check the official guidance

For the regulatory detail behind this checklist, go straight to the source rather than a summary of it. The OAIC’s guide to securing personal information covers transport, retention and destruction obligations under the Privacy Act. The ASD’s Essential Eight documentation and email hardening guidelines cover the technical controls, from patching cadence through to SPF, DKIM, DMARC and MTA-STS.

FAQ

Is fax-to-email actually encrypted end to end?

Only if you enforce it. Enforced TLS 1.2 or 1.3 on the SMTP hop between the device and mail server encrypts the transport, but opportunistic TLS falls back to plain text if the receiving server doesn’t support encryption, so the setting matters as much as the protocol.

Does APP 11 apply to faxes converted to email?

Yes. Personal information captured by a fax device and forwarded to an inbox is covered by APP 11 the moment it’s received, requiring reasonable protective steps during transmission and storage, plus destruction once it’s no longer needed.

Why do device-sent faxes sometimes get quarantined?

Mail filters reject or quarantine messages when the sending device’s IP isn’t authorised in the domain’s SPF record and the message isn’t relayed through an authenticated gateway. Routing all devices through one authenticated SMTP relay is the simplest fix.

What do managed print services charge for fees?

Pricing for managed print services and secure MFP deployment depends on fleet size and configuration requirements, so current rates are available directly on the Global Office Machines site rather than as a fixed published figure.

Can an MFP send fax-to-email directly, or do I need a fax server?

Both work, but they suit different scales. A single MFP can send fax-to-email natively for a small office, while a dedicated on-prem fax server gives larger environments centralised routing, logging and encryption control across multiple devices.