Business Email Security: Protecting Your Inbox from Attack
Email is the most common entry point for cyberattacks on UK businesses. Effective email security combines technical controls — SPF, DKIM, DMARC, secure gateways — with staff awareness to block phishing, spoofing and malware before they cause harm.
AMVIA Team
Editorial
Email is still the front door for attacks on UK businesses. If you only fix one thing this quarter, fix this. Below is what actually works, in the order we deploy it for clients, and where the common shortcuts leave you exposed. For the wider picture, start with our managed cybersecurity approach and how email fits into it.
Why is email still the number one attack surface?
Email remains the primary delivery route for cyberattacks because it is the one channel every employee uses, and every message demands a human judgement call about whether to trust it. Technical filters help, but attackers only need one person to click once.
The UK Cyber Security Breaches Survey found that phishing attempts remain the most commonly identified form of attack, affecting 84% of businesses that reported a breach (gov.uk Cyber Security Breaches Survey). The threat has also matured. Bulk spam still exists, but it now sits alongside targeted business email compromise (BEC) — where criminals impersonate senior staff or trusted suppliers to authorise fraudulent payments. BEC needs no malware at all; it wins through social engineering.
That shift matters because it changes what "protection" means. A spam filter alone cannot stop a polite, well-written email from a real-looking finance director. You need authentication, content filtering and human verification working together.
What are the core technical controls (SPF, DKIM, DMARC)?
The three email authentication standards work as a stack: SPF says who can send for your domain, DKIM proves a message was not tampered with, and DMARC tells receiving servers what to do when those checks fail. Most breaches we investigate have the first two but leave the third switched off.
| Control | What it does | Common gap |
|---|---|---|
| SPF (Sender Policy Framework) | Lists the IP addresses allowed to send email for your domain | Often too permissive or never updated when tools change |
| DKIM (DomainKeys Identified Mail) | Adds a cryptographic signature receivers verify against your DNS | Missing on third-party senders (CRM, marketing tools) |
| DMARC | Tells receivers to quarantine or reject failed mail, and reports abuse | Left in `none` monitoring mode indefinitely — no real protection |
SPF alone is not enough, but every business domain should have it configured correctly. DKIM works alongside SPF rather than replacing it: if a message is altered in transit, or a criminal forges your address, the signature fails. DMARC is the part most firms neglect. A policy set to `reject` is the strongest defence against domain spoofing, yet many UK businesses leave DMARC in monitoring mode for years and gain no active protection. Authentication is not a silver bullet either — a large share of phishing still passes DMARC checks because attackers use lookalike domains they themselves authenticate (84.2% of phishing emails passed DMARC checks, 2024 industry data).
If you run Microsoft 365, getting these records right sits naturally alongside Microsoft 365 security hardening.
Do I need an email security gateway as well?
Yes. Authentication stops spoofing, but it does not filter malicious content arriving through legitimate sending infrastructure. A gateway sits between the internet and your mailboxes and inspects every message for known and unknown threats before delivery.
A good email security gateway scans for:
- Known malware signatures and zero-day threats using sandboxing
- Phishing URLs checked against live threat intelligence
- Suspicious attachments — macro-enabled documents and obfuscated scripts
- Data loss prevention rules on outbound mail
Gateways such as Microsoft Defender for Office 365, Proofpoint and Barracuda operate here. Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, which covers safe links and safe attachments (Microsoft Security). Higher-risk organisations layer a dedicated gateway on top for deeper filtering. AMVIA deploys Microsoft Defender plus the Barracuda email suite, managed as one stack — see how that ties into Microsoft Defender for Business. Independent benchmarking shows attackers increasingly slipping past native defences and secure email gateways (a 47% rise in 2025 industry data), which is exactly why we monitor filtering effectiveness rather than assuming it.
How do I stop business email compromise and impersonation fraud?
BEC is hard to block with technology alone because the email can be entirely legitimate — sent from a real, uncompromised account set up to mimic a trusted contact. The decisive control is a verification habit: any request to move money or change bank details gets confirmed through a separate channel before action.
Watch for these warning signs:
- A request to change bank account details for a supplier payment
- An "urgent" instruction from the CEO to transfer funds, outside normal channels
- A reply on an existing thread where the reply-to address quietly differs
- Requests that skip normal approval steps because of claimed urgency
Train staff to verify any payment instruction or change of financial details by phoning a known number — never a number supplied in the suspicious email. This pairs with broader phishing protection, because the same playbook defends against credential theft. A high proportion of advanced phishing now bypasses multi-factor authentication (around 83% in 2024 industry data) — MFA is essential but not a complete answer, so verification culture matters.
What about email encryption, backup and policy?
Encryption protects confidentiality, backup protects recoverability, and policy makes both repeatable. Together they cover what filtering misses: data leaving the business, data lost to error, and behaviour that drifts without rules.
Encryption. TLS encrypts mail in transit between major providers as standard. End-to-end encryption — where only sender and recipient can read the message — suits legal advice, financial data and personal information. Microsoft 365 Message Encryption and S/MIME are both available in the Microsoft 365 ecosystem. For ad hoc sensitive files, a secure transfer portal often beats encrypted email.
Backup. Mailboxes are subject to legal hold, retention rules and continuity needs. Exchange Online archiving helps, but Microsoft's native retention is not a substitute for an independent backup that can recover individual items deleted by error or malice. Plan this deliberately with proper Microsoft 365 backup.
Policy. A written email security policy should cover acceptable use, handling links and attachments from unknown senders, reporting suspected phishing, and verifying unusual payment requests. Policy achieves nothing without reinforcement through training and simulated phishing. Strong authentication should sit on top of MFA across Microsoft 365 so a stolen password alone is not enough.
The NCSC publishes practical, vendor-neutral guidance on phishing defence that aligns with this layered approach (NCSC phishing guidance).
Is Your Email Domain Fully Protected?
Many UK businesses have partial email authentication in place but gaps that leave them vulnerable to spoofing. AMVIA can check your SPF, DKIM and DMARC configuration and close the gaps quickly.
Frequently Asked Questions
Phishing is bulk, untargeted email sent to deceive large numbers of recipients. Spear phishing is targeted: the attacker researches one individual or organisation and references real colleagues, projects or relationships, which makes it far harder to spot. Independent benchmarking reports a sharp rise in attacks evading native defences and secure email gateways (KnowBe4, 2025).
Yes. SPF and DKIM authenticate your mail, but DMARC tells receiving servers what to do when authentication fails and gives you visibility of who is sending using your domain. Without a DMARC policy set to quarantine or reject, your domain stays exposed to spoofing even with SPF and DKIM in place.
Microsoft 365 includes Exchange Online Protection across all plans for basic spam and malware filtering. Business Premium and higher add Defender for Office 365 with anti-phishing policies, safe links and safe attachments. Many organisations supplement this with a third-party gateway for additional depth and reporting.
Common indicators include unexpected password reset requests, unusual login notifications, colleagues asking for urgent financial action, and links whose real destination differs from the displayed text. If you suspect an email was opened, change passwords immediately and contact your IT team. Authentication alone is not decisive — a large share of phishing still passes DMARC checks (Egress, 2024).
Business email compromise is an attack where criminals impersonate executives, suppliers or colleagues — using spoofed addresses, compromised accounts or lookalike domains — to trick employees into making fraudulent payments or disclosing sensitive data. It needs no malware and causes substantial financial losses across UK businesses each year. Separate-channel verification of payment changes is the strongest defence.
Ongoing, not annual. Quarterly simulated phishing exercises, paired with brief teaching moments when staff interact with a simulated lure, are far more effective than a once-a-year presentation. The aim is habitual vigilance, not a tick-box certificate that fades within weeks.
Related Reading
What Is DMARC?
A detailed explanation of the DMARC email authentication protocol and how to implement it for your business domain.
Email Phishing: Keeping Your Business Safe
A practical guide to recognising phishing attacks and building the staff awareness needed to stop them.
Email Security Gateway
How email security gateways work and which solution is right for your business size and risk profile.
Protect your business → Get Cybersecurity Assessment