
Microsoft 365 Email Security
Spam filtering is not the problem. The message that costs you money has no malware, no attachment and no bad link — it just asks your accounts clerk to update some bank details.
Defender for Office 365 configured properly, impersonation policies that catch lookalike senders, and the SPF, DKIM and DMARC records that stop anyone sending mail as your domain.
Three things, in this order. Publish SPF, DKIM and DMARC so nobody can send mail as your domain. Turn on impersonation protection so lookalike senders are flagged rather than delivered cleanly. Then configure Defender for Office 365 — Safe Links and Safe Attachments — which Microsoft includes at Plan 1 with Business Premium, and only as URL time-of-click on Basic and Standard. Most organisations we review have bought the licence and done none of the configuration.
Six layers, and what each one is actually for
Baseline filtering
Anti-malware and anti-spam filtering is on every Microsoft 365 Business plan. It handles bulk junk well and is not the thing that fails you. What gets through is targeted, and targeted mail is a different problem.
Safe Links and Safe Attachments
Defender for Office 365 rewrites links and checks them at the moment of clicking rather than only on delivery, and detonates attachments in a sandbox first. This matters because a link that was clean when it arrived is frequently not clean an hour later.
Impersonation protection
Detects mail pretending to be your managing director or your accounts department — lookalike domains, display-name spoofing, near-miss addresses. This is the control that actually catches invoice fraud.
Domain authentication
SPF, DKIM and DMARC published correctly so nobody else can send mail that appears to come from your domain. Protects your customers and your reputation, not just your inbox.
Quarantine that people actually use
A quarantine nobody reviews becomes a place legitimate mail goes to die, and then somebody disables filtering entirely. Configured with the right notifications and release permissions, it works.
Mail flow rules
External-sender warning banners, blocking risky attachment types, and routing rules for specific senders. Unglamorous, and among the highest-value controls available.
How invoice fraud actually happens
Every element of this is mundane. That is the point — there is nothing for a malware scanner to find, which is why it keeps working against businesses that believe they are protected because they pay for filtering.
Reconnaissance
Your team's names, roles and email format are usually public — a website, LinkedIn, a tender document. Nothing needs to be hacked to learn who authorises payments.
The lookalike
A domain one character off yours is registered, or a display name is set to match a director while the underlying address is a free mailbox. Both look right on a phone screen.
The timing
The message arrives when the target is plausibly busy or the sender is plausibly travelling. Urgency is the whole mechanism.
The request
Changed bank details on a genuine-looking invoice, or an urgent transfer. The amount is chosen to be large enough to matter and small enough not to need a second signature.
Why filtering misses it
There is no malware, no attachment and no bad link. Nothing technically malicious is present, which is exactly why impersonation policies and an external-sender banner catch it when spam filtering does not.
What email security your plan already includes
As stated by Microsoft, checked 21 September 2026. The gap between Standard and Premium in this table is the single strongest argument for Premium in most businesses.
| Capability | Business Basic | Business Standard | Business Premium |
|---|---|---|---|
| Anti-malware and anti-spam filtering | Yes | Yes | Yes |
| Defender for Office 365 | URL time-of-click | URL time-of-click | Plan 1 |
| Safe Attachments (sandbox detonation) | No | No | Yes |
| Anti-phishing impersonation policies | Limited | Limited | Yes |
| Purview Information Protection | No | No | Plan 1 |
| Data loss prevention for email | No | No | For emails and files |
| Audit logging | Standard | Standard | Standard |
Before buying a third-party filtering product, check what your plan already includes. We find unconfigured Defender alongside a paid-for alternative more often than we find a genuine gap.
Email security — common questions
helpIs Microsoft 365's built-in spam filtering enough?
expand_more
For bulk junk, yes — it is genuinely good and it is on every plan. It is not what fails you. What gets through is targeted: a message with no malware, no attachment and no malicious link, asking your accounts clerk to update bank details. Nothing in a spam filter is designed to catch that, which is what impersonation policies and sender banners are for.
helpWhat is Defender for Office 365 and do we already have it?
expand_more
Defender for Office 365 adds Safe Links, Safe Attachments and stronger anti-phishing on top of baseline filtering. Microsoft states Business Premium includes Plan 1, while Business Basic and Business Standard get URL time-of-click protection only. So whether you already have it depends entirely on your plan — worth checking before buying anything. Checked 21 September 2026.
helpWhat are SPF, DKIM and DMARC and do we need all three?
expand_more
SPF declares which servers may send mail for your domain. DKIM signs outgoing mail so it can be verified as genuinely yours. DMARC tells receiving servers what to do when the first two fail, and reports who is sending mail claiming to be you. Yes, you need all three — and DMARC is the one most businesses have never configured, which is why domain spoofing still works against them.
helpSomeone sent our customers a fake invoice from our address. What now?
expand_more
First establish whether a mailbox was actually compromised or whether the address was simply spoofed from outside — those are very different problems with very different responses. Then check sign-in logs, check for mail-forwarding rules quietly added to the mailbox, reset credentials, and get DMARC published so external spoofing stops working. We handle this as an urgent piece of work; call rather than emailing if it is live.
helpWhy does our own email land in customers' spam?
expand_more
Almost always SPF, DKIM or DMARC — either never set up, or broken by a change of provider, a new marketing tool, or an invoicing system that sends on your behalf without being authorised to. It is the same set of records that stops others spoofing you, which is why deliverability and anti-spoofing are really one job rather than two.
helpDo we need a third-party email security product as well?
expand_more
Usually not, if you are on Business Premium and it is configured properly. We see more organisations paying for an additional filtering product while leaving Defender misconfigured and DMARC unpublished than we see genuine gaps in Microsoft's stack. Configure what you already own first, then decide whether anything is actually missing.
helpWill stronger email security block legitimate mail?
expand_more
Some, initially — and how that is handled determines whether the configuration survives. Policies are tuned during the first weeks, quarantine notifications go to the right people, and release permissions are set so somebody can act without raising a ticket. A quarantine nobody can act on leads directly to filtering being switched off, which is worse than where you started.
helpHow is this different from your Microsoft 365 security page?
expand_more
This page is about mail: what arrives in inboxes, what leaves your domain, and who can pretend to be you. The broader security page covers identity, devices and data — multi-factor authentication, conditional access, Intune device management and data loss prevention. Most organisations need both, and mail is usually the more urgent of the two.
Related pages
Microsoft 365 Security
The wider picture: identity, devices, data and admin control.
Microsoft 365 Business Email
Mailbox structure, shared addresses and domain setup.
Microsoft 365 Licensing Explained
Which plan includes Defender, and which only looks like it does.
Microsoft 365 Implementation
Where the security baseline gets applied in the first place.
Microsoft 365 Pricing in India
What Business Premium and the security add-ons actually cost.
Microsoft 365 Services
Licensing, implementation, migration, security and support.
Google Workspace Email Security
The equivalent controls on the Google side.
Get an email security review
We will tell you what is configured and what only looks configured.
Get an email security review
We check what is actually configured against what your plan already entitles you to — and in most reviews those two are not the same.
- check_circle
SPF, DKIM and DMARC checked and published correctly
- check_circle
Impersonation policies tuned for your actual directors and finance staff
- check_circle
Defender configured rather than merely licensed
For exporters, the cost of broken SPF, DKIM or DMARC is a quotation that never reaches the buyer — the case is made on our page for Microsoft 365 partner in Kollam.
If you have a live incident, call rather than emailing: +91 99467 89916. Otherwise admin@techgeum.com.
