Not all email filtering is equal
Every email platform ships with some form of spam filtering. Microsoft 365 has Exchange Online Protection (EOP) built in. Google Workspace has its own spam engine. These tools catch bulk spam and known-bad senders — but they were not designed to stop modern targeted attacks: spear phishing, BEC, zero-day malware, or data exfiltration.
An email security gateway is a dedicated layer — either cloud-based or on-premises — that sits in front of your mail platform and applies advanced inspection before messages ever reach your users' inboxes. The difference in protection is significant.
Figure 1 — Built-in spam filters handle commodity threats. An email security gateway adds sandboxing, AI-based BEC detection, Safe Links, and DLP — the controls that stop targeted attacks.
What a spam filter does — and does not do
A basic spam filter operates on reputation and signatures. It asks: "Is this sender on a blocklist? Does this message match a known spam pattern?" It is effective against:
- Bulk unsolicited email (newsletters, marketing blasts)
- Known phishing domains and IPs
- Attachments matching known malware signatures
It is not effective against targeted attacks, because targeted attacks come from new infrastructure, use legitimate services (OneDrive, Google Drive, DocuSign), and are crafted specifically to avoid signature matching.
What an email security gateway adds
| Capability | How it works | Threat it stops |
|---|---|---|
| Safe Attachments (sandbox) | Every attachment is detonated in an isolated VM before delivery. Malicious behavior triggers quarantine. | Zero-day malware, ransomware droppers |
| Safe Links | URLs are rewritten and scanned at time-of-click, not just at delivery. Catches links that were clean at delivery but weaponized later. | Delayed-weaponization phishing, credential harvesting |
| AI impersonation protection | Machine learning models detect display-name spoofing, lookalike domains, and unusual sender behavior even when SPF/DKIM pass. | BEC, CEO fraud, vendor impersonation |
| Anti-phishing policies | Configurable rules for internal domain impersonation, mailbox intelligence, and first-contact safety tips. | Spear phishing, targeted credential theft |
| Data Loss Prevention (DLP) | Scans outbound email for sensitive data patterns (SSNs, credit card numbers, ePHI keywords) and blocks or encrypts automatically. | Accidental and intentional data exfiltration |
| Attack simulation training | Sends simulated phishing emails to your staff and routes failures to targeted training. | Human error — the #1 attack vector |
Microsoft Defender for Office 365 — Plan 1 vs. Plan 2
Microsoft offers two tiers of email security above the baseline EOP that comes with every M365 license:
- Defender for Office 365 Plan 1 — Safe Attachments, Safe Links, anti-phishing with impersonation protection. Covers the most critical gaps above EOP. Included in M365 Business Premium.
- Defender for Office 365 Plan 2 — Adds Threat Explorer, automated investigation and response (AIR), attack simulation training, and advanced hunting. Required for HIPAA and financial services compliance in most frameworks.
Third-party gateways vs. Microsoft native
Organizations sometimes deploy a third-party secure email gateway (Proofpoint, Mimecast, Abnormal Security) in front of M365. These tools offer deeper customization and are preferred in enterprise environments with complex mail flows. For SMBs, Microsoft's native Defender stack — properly configured — provides equivalent protection at lower cost and complexity.
The key word is properly configured. Default Defender settings leave significant gaps. IDENETY tunes anti-phishing policies, Safe Attachment profiles, Safe Links policies, and DLP rules as part of the M365 Security Baseline deployment.
See our Microsoft 365 Security Baseline article for the full configuration guide, and our Email Security: Stopping Phishing, Spoofing & BEC article for the broader threat landscape.
Contact our engineers to audit your current email security configuration and close the gaps before attackers find them.
.png)