Cybersecurity

Email Protection for Business: Layers of Defence Explained

Effective email protection for UK businesses is not a single product — it is a stack of complementary controls. Authentication protocols, gateways, encryption, backup and user training each address different threats and together provide meaningful defence in depth.

NH

Nathan Hill-Haimes

Technical Director

8 min read·Mar 2026

If you treat email security as a single box to tick, you have already lost. Email is the channel attackers reach for first, and no single product stops every technique. This guide walks through the six layers that together make up real email protection, what each one defends against, and where the common gaps sit. It is also the foundation of our wider managed cybersecurity service for UK businesses.

Why does single-layer email protection fail?

Single-layer email protection fails because attackers continuously adapt to evade whatever filter is most widely deployed. Email carries payment instructions, client data and login credentials, so it attracts attackers at every skill level. One product, however capable, will eventually be bypassed — which is why security architects build in depth, not in a single wall.

Defence in depth means multiple overlapping layers, each addressing a different threat vector. When one layer fails or is bypassed, the next catches what slipped through. The UK's National Cyber Security Centre frames phishing defence the same way: layered technical controls plus user awareness, not one silver bullet (NCSC phishing guidance). Phishing remains the single most common attack type reported in the government's Cyber Security Breaches Survey 2025 (gov.uk), so the email channel is where most attacks begin.

What does email authentication (SPF, DKIM, DMARC) do?

Email authentication operates at the DNS level and verifies whether a message claiming to come from your domain was actually sent by an authorised source. It is the foundation layer. Without it, anyone can spoof your domain to send convincing phishing emails to your customers, suppliers and staff.

  • SPF (Sender Policy Framework): publishes the IP addresses authorised to send email for your domain; receiving servers check inbound mail against that list.
  • DKIM (DomainKeys Identified Mail): adds a cryptographic signature to outbound mail, letting receiving servers confirm the message was not altered in transit.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance): tells receiving servers what to do when SPF or DKIM fail, and reports authentication results back to you.

Configure all three. Get DMARC wrong and you either leave the door open or quietly bin your own legitimate mail — which is why it belongs with a provider who manages it day to day. This is also the first thing we check in any managed email security review.

What does an email security gateway add?

A gateway scans every inbound and outbound message before it reaches the inbox, using signature detection, machine learning and sandboxing — detonating suspicious attachments in an isolated environment to watch their behaviour. It is the layer that catches the bulk of malware, spam and known phishing before a user ever sees it.

A capable gateway provides:

  • Anti-spam and anti-malware scanning
  • Anti-phishing and impersonation detection
  • URL filtering and safe links that re-check links at the moment of click, not just at delivery
  • Attachment sandboxing
  • Outbound data loss prevention (DLP)

Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, a solid gateway layer, at £16.90 per user per month (Microsoft 365 UK pricing). Market alternatives such as Mimecast and Proofpoint sit in the same space. For SMEs we typically run Microsoft Defender for Business and add the Barracuda email gateway in front for deeper filtering where the data justifies it. That is the AMVIA stack — Microsoft Defender plus Barracuda, not a tangle of disconnected tools.

How do MFA and endpoint protection close the gap?

Even the best gateway occasionally lets a message through — a zero-day, or pure social engineering with no malicious payload. The next layer works at the identity and endpoint level. Multi-factor authentication means a phished password alone is useless, and endpoint protection re-scans documents and links when they are opened, not just at delivery.

Multi-factor authentication on email accounts is the single highest-return control you can deploy: it blocks account takeover even when credentials are stolen, which is the most common outcome of a successful phish. We set up MFA across Microsoft 365 as standard. At the endpoint, Microsoft Defender for Endpoint — and commercial EDR from vendors such as CrowdStrike, SentinelOne and Sophos Intercept X — catches what was undetectable at the gateway. Pair this with dedicated phishing protection for the cases that target people rather than systems.

When do you need email encryption?

Email encryption protects message content from interception in transit and at rest. Most server-to-server email is already encrypted in transit with TLS automatically. End-to-end encryption — where only sender and recipient can read the message — needs extra configuration and matters most when you routinely handle confidential or regulated data.

TLS is not the whole story: it does not encrypt content sitting in the recipient's mailbox, and it does not stop a compromised server reading messages. For sensitive information, Microsoft 365 Message Encryption (OME), S/MIME certificates, or a secure file-sharing portal provide the right level. Legal, healthcare and financial services firms are the most likely to need a formal encryption policy — the ICO expects appropriate technical measures for personal data in transit (ICO security guidance).

Why isn't Microsoft 365 archiving a backup?

Microsoft 365 archiving and retention policies are run by Microsoft inside their own platform. If an admin error, malicious insider or platform-level issue wipes data, your recovery options are limited and bounded by Microsoft's tools. Archiving preserves mail for compliance; it is not an independent, restorable backup.

An independent third-party Microsoft 365 backup creates copies outside Microsoft's environment, giving you granular item-level recovery from any point in the retention window with no dependency on Microsoft's own recovery process. For business continuity that is the standard recommendation — and it is the layer most SMEs assume they already have and do not.

How important is user awareness training?

Every technical control can be undone by one employee acting on a convincing email. Regular security awareness training, including simulated phishing, builds the critical-thinking habits that complement the technical stack. The NCSC is explicit that user education is not a substitute for technical controls — and technical controls are not a substitute for it.

Treat training as a layer, not a poster. Short, frequent, scenario-based exercises change behaviour; an annual slideshow does not. The aim is a workforce that pauses on the unusual payment request and reports it, rather than one that never makes mistakes.

Which email protection stack does AMVIA recommend?

For most UK SMEs we recommend Microsoft 365 Business Premium as the core, hardened by AMVIA, with Barracuda added where data sensitivity demands deeper filtering, MFA enforced everywhere, and independent backup behind it. The table below maps each layer to the threat it addresses and a representative tool.

LayerThreat addressedRepresentative control
Authentication (SPF/DKIM/DMARC)Domain spoofing, impersonationDNS records, DMARC reporting
Gateway filteringMalware, spam, known phishingMicrosoft Defender for Office 365, Barracuda
MFA & endpointAccount takeover, zero-day payloadsMicrosoft Entra MFA, Defender for Endpoint
EncryptionInterception, confidentiality breachMicrosoft 365 Message Encryption, S/MIME
BackupData loss, malicious deletionIndependent third-party backup
User awarenessSocial engineeringSimulated phishing, training

One provider running all six layers removes the gaps that appear when email security is split across disconnected vendors. That single-accountable model — security-first, Microsoft-certified — is what Microsoft 365 security with AMVIA is built around.

How Many Layers Does Your Email Security Have?

Most businesses have some email protection in place — but gaps between layers leave them exposed. AMVIA can map your current email security controls and close the gaps efficiently.

Frequently Asked Questions