Reviewing email security posture
Microsoft 365 Partner · CSP Reseller

Microsoft 365 Email Security

Spam filtering is not the problem. The message that costs you money has no malware, no attachment and no bad link — it just asks your accounts clerk to update some bank details.

Defender for Office 365 configured properly, impersonation policies that catch lookalike senders, and the SPF, DKIM and DMARC records that stop anyone sending mail as your domain.

Three things, in this order. Publish SPF, DKIM and DMARC so nobody can send mail as your domain. Turn on impersonation protection so lookalike senders are flagged rather than delivered cleanly. Then configure Defender for Office 365 — Safe Links and Safe Attachments — which Microsoft includes at Plan 1 with Business Premium, and only as URL time-of-click on Basic and Standard. Most organisations we review have bought the licence and done none of the configuration.

The controls

Six layers, and what each one is actually for

filter_alt

Baseline filtering

Anti-malware and anti-spam filtering is on every Microsoft 365 Business plan. It handles bulk junk well and is not the thing that fails you. What gets through is targeted, and targeted mail is a different problem.

link

Safe Links and Safe Attachments

Defender for Office 365 rewrites links and checks them at the moment of clicking rather than only on delivery, and detonates attachments in a sandbox first. This matters because a link that was clean when it arrived is frequently not clean an hour later.

person_search

Impersonation protection

Detects mail pretending to be your managing director or your accounts department — lookalike domains, display-name spoofing, near-miss addresses. This is the control that actually catches invoice fraud.

verified_user

Domain authentication

SPF, DKIM and DMARC published correctly so nobody else can send mail that appears to come from your domain. Protects your customers and your reputation, not just your inbox.

inventory_2

Quarantine that people actually use

A quarantine nobody reviews becomes a place legitimate mail goes to die, and then somebody disables filtering entirely. Configured with the right notifications and release permissions, it works.

policy

Mail flow rules

External-sender warning banners, blocking risky attachment types, and routing rules for specific senders. Unglamorous, and among the highest-value controls available.

The attack that works

How invoice fraud actually happens

Every element of this is mundane. That is the point — there is nothing for a malware scanner to find, which is why it keeps working against businesses that believe they are protected because they pay for filtering.

1

Reconnaissance

Your team's names, roles and email format are usually public — a website, LinkedIn, a tender document. Nothing needs to be hacked to learn who authorises payments.

2

The lookalike

A domain one character off yours is registered, or a display name is set to match a director while the underlying address is a free mailbox. Both look right on a phone screen.

3

The timing

The message arrives when the target is plausibly busy or the sender is plausibly travelling. Urgency is the whole mechanism.

4

The request

Changed bank details on a genuine-looking invoice, or an urgent transfer. The amount is chosen to be large enough to matter and small enough not to need a second signature.

5

Why filtering misses it

There is no malware, no attachment and no bad link. Nothing technically malicious is present, which is exactly why impersonation policies and an external-sender banner catch it when spam filtering does not.

Check before you buy

What email security your plan already includes

As stated by Microsoft, checked 21 September 2026. The gap between Standard and Premium in this table is the single strongest argument for Premium in most businesses.

CapabilityBusiness BasicBusiness StandardBusiness Premium
Anti-malware and anti-spam filteringYesYesYes
Defender for Office 365URL time-of-clickURL time-of-clickPlan 1
Safe Attachments (sandbox detonation)NoNoYes
Anti-phishing impersonation policiesLimitedLimitedYes
Purview Information ProtectionNoNoPlan 1
Data loss prevention for emailNoNoFor emails and files
Audit loggingStandardStandardStandard

Before buying a third-party filtering product, check what your plan already includes. We find unconfigured Defender alongside a paid-for alternative more often than we find a genuine gap.

Email security — common questions

help

Is Microsoft 365's built-in spam filtering enough?

expand_more

For bulk junk, yes — it is genuinely good and it is on every plan. It is not what fails you. What gets through is targeted: a message with no malware, no attachment and no malicious link, asking your accounts clerk to update bank details. Nothing in a spam filter is designed to catch that, which is what impersonation policies and sender banners are for.

help

What is Defender for Office 365 and do we already have it?

expand_more

Defender for Office 365 adds Safe Links, Safe Attachments and stronger anti-phishing on top of baseline filtering. Microsoft states Business Premium includes Plan 1, while Business Basic and Business Standard get URL time-of-click protection only. So whether you already have it depends entirely on your plan — worth checking before buying anything. Checked 21 September 2026.

help

What are SPF, DKIM and DMARC and do we need all three?

expand_more

SPF declares which servers may send mail for your domain. DKIM signs outgoing mail so it can be verified as genuinely yours. DMARC tells receiving servers what to do when the first two fail, and reports who is sending mail claiming to be you. Yes, you need all three — and DMARC is the one most businesses have never configured, which is why domain spoofing still works against them.

help

Someone sent our customers a fake invoice from our address. What now?

expand_more

First establish whether a mailbox was actually compromised or whether the address was simply spoofed from outside — those are very different problems with very different responses. Then check sign-in logs, check for mail-forwarding rules quietly added to the mailbox, reset credentials, and get DMARC published so external spoofing stops working. We handle this as an urgent piece of work; call rather than emailing if it is live.

help

Why does our own email land in customers' spam?

expand_more

Almost always SPF, DKIM or DMARC — either never set up, or broken by a change of provider, a new marketing tool, or an invoicing system that sends on your behalf without being authorised to. It is the same set of records that stops others spoofing you, which is why deliverability and anti-spoofing are really one job rather than two.

help

Do we need a third-party email security product as well?

expand_more

Usually not, if you are on Business Premium and it is configured properly. We see more organisations paying for an additional filtering product while leaving Defender misconfigured and DMARC unpublished than we see genuine gaps in Microsoft's stack. Configure what you already own first, then decide whether anything is actually missing.

help

Will stronger email security block legitimate mail?

expand_more

Some, initially — and how that is handled determines whether the configuration survives. Policies are tuned during the first weeks, quarantine notifications go to the right people, and release permissions are set so somebody can act without raising a ticket. A quarantine nobody can act on leads directly to filtering being switched off, which is worse than where you started.

help

How is this different from your Microsoft 365 security page?

expand_more

This page is about mail: what arrives in inboxes, what leaves your domain, and who can pretend to be you. The broader security page covers identity, devices and data — multi-factor authentication, conditional access, Intune device management and data loss prevention. Most organisations need both, and mail is usually the more urgent of the two.

Get an email security review

We check what is actually configured against what your plan already entitles you to — and in most reviews those two are not the same.

  • check_circle

    SPF, DKIM and DMARC checked and published correctly

  • check_circle

    Impersonation policies tuned for your actual directors and finance staff

  • check_circle

    Defender configured rather than merely licensed

For exporters, the cost of broken SPF, DKIM or DMARC is a quotation that never reaches the buyer — the case is made on our page for Microsoft 365 partner in Kollam.

If you have a live incident, call rather than emailing: +91 99467 89916. Otherwise admin@techgeum.com.

call