Email Security Gateway: What It Is and How It Protects You
An email security gateway sits between the internet and your inbox, scanning every inbound and outbound message for phishing, malware, spam and data loss risks before they reach staff. It is one of the most impactful single controls a business can deploy.
Nathan Hill-Haimes
Technical Director
Email remains the number one entry point for attacks on UK organisations. The NCSC treats phishing as the most common route to compromise, which is exactly the traffic a gateway exists to filter. At AMVIA we configure and manage these gateways as part of our managed cybersecurity services — one provider, security-first, Microsoft-certified.
What is an email security gateway?
An email security gateway is a system — delivered as a cloud service, an on-premise appliance, or a built-in platform component — that processes every email entering or leaving your organisation before it reaches its destination. Think of it as a checkpoint at the boundary of your mail flow, applying several scanning techniques to catch threats and enforce policy.
In the cloud-first world most UK businesses now operate in, gateways are almost always cloud services that sit in the delivery path. Inbound email routes through the gateway before it reaches Microsoft 365 or Google Workspace, and outbound email passes through it on the way to the recipient. This needs no on-premise hardware and scales with email volume automatically.
What does an email security gateway actually do?
A gateway layers four jobs: stop bulk spam, block malicious attachments, detect phishing and impersonation, and inspect outbound mail for data loss. The first two are table stakes; the real value of a modern gateway is in the last two, where most damaging attacks now live.
Anti-spam and bulk mail filtering
The most basic function is identifying and filtering unsolicited bulk email so it never reaches the inbox. Modern spam filtering uses machine learning and reputation scoring of sending domains and IP addresses to achieve high catch rates. Most businesses have some spam filtering, but quality varies sharply between a basic provider filter and a dedicated gateway.
Anti-malware and attachment scanning
Every inbound attachment is scanned against known malware signatures and analysed for suspicious characteristics. Macro-enabled Office documents, executables, and archive formats (.zip,.7z) get particular scrutiny. Advanced gateways use sandboxing — running an attachment in an isolated environment to watch its behaviour — to catch threats with no known signature.
Anti-phishing and impersonation detection
This is where modern gateways add real value over basic filtering. Strong anti-phishing capabilities include:
- Detection of emails impersonating your own domain or commonly spoofed brands
- Analysis of headers, sender reputation and message content for phishing indicators
- URL scanning at delivery and, in better implementations, at the moment of click (safe links)
- Business email compromise (BEC) detection trained on the patterns of CEO and CFO impersonation attacks
Pairing gateway controls with phishing protection and user training closes the gap that technology alone cannot.
Outbound scanning and data loss prevention
Gateways scan outbound mail as well as inbound. This serves two purposes: stopping your systems from sending malware to customers and partners if you are compromised, and enforcing data loss prevention (DLP) policies that flag or block messages containing sensitive data such as payment card numbers, NHS numbers or confidential document keywords.
What are the gateway deployment options?
There are two practical routes for UK SMEs: use the gateway capabilities built into Microsoft 365, or layer a third-party gateway in front of it. The right choice depends on your sector, your risk appetite, and whether you have been burned by an email attack before.
Microsoft Defender for Office 365
Organisations on Microsoft 365 Business Premium or higher already have Microsoft's gateway capabilities built in. Per Microsoft's documentation, Defender for Office 365 Plan 1 includes anti-phishing policies, safe links, safe attachments and anti-malware scanning. Plan 2 — in Microsoft 365 E3/E5 or as an add-on — adds advanced hunting, automated investigation and response. Business Premium lists at £16.90 per user per month (ex VAT, annual) on microsoft.com/en-gb, so for many SMEs the included Defender capability is a sensible, already-paid-for starting point. We help businesses turn it on properly through Microsoft Defender for Business.
Third-party gateway solutions
Products such as Mimecast, Proofpoint, Barracuda and Abnormal Security sit in front of Microsoft 365 or Google Workspace, adding a filtering layer with different detection logic. Third-party gateways typically offer more granular reporting, richer admin controls, and — in Abnormal Security's case — an AI-driven approach to detecting BEC and social engineering that differs from Microsoft's methodology.
Layering a third-party gateway with Microsoft's native protection is a common configuration for UK businesses in regulated sectors — financial services, legal, and healthcare — where a single detection failure carries a high cost.
| Option | Best for | Typical add-on cost |
|---|---|---|
| Microsoft Defender for Office 365 Plan 1 | Most SMEs already on Business Premium | Included in Business Premium |
| Defender for Office 365 Plan 2 | Firms needing hunting + auto-investigation | Add-on / E5 |
| Third-party gateway (Mimecast, Proofpoint, Barracuda, Abnormal) | Regulated sectors, prior incidents, deep DLP | from £2–£4 per user/mo (typical UK 2026 range) |
What does an email gateway not cover?
A gateway operates at the message level, so it cannot catch everything. It will not stop a compromised-but-legitimate account, a payload-free social-engineering request, or a link that turns malicious after delivery. Those gaps are why MFA, training and account monitoring are necessary complements, not optional extras.
Specifically, a gateway does not protect against:
- Compromised legitimate accounts sending phishing from real, authenticated inboxes — a gateway will deliver mail from a genuine Microsoft 365 account that has been taken over
- Social engineering with no malicious link or attachment — a phone call, or an email requesting a bank-account change with no payload, passes gateway checks
- Post-delivery threats where a URL was clean at delivery but later changed to host malicious content (mitigated by time-of-click scanning)
This is why we pair gateway controls with multi-factor authentication on Microsoft 365 and ongoing account monitoring.
How should you choose the right gateway?
For most UK SMEs, the Defender for Office 365 capability already in Microsoft 365 Business Premium is a solid, cost-effective starting point — properly configured. Businesses needing more depth should evaluate a third-party gateway: those in regulated sectors, those who have had a prior email incident, or those with complex outbound DLP requirements.
Third-party cloud gateways typically start from £2–£4 per user per month at market rates as of 2026. Weigh that against the alternative: the total cost of a single successful phishing attack almost always exceeds months of gateway subscription fees. The deciding question is not price — it is how much a single missed message would cost your business.
Is Your Email Gateway Properly Configured?
Having a gateway is not the same as having it correctly configured. AMVIA can review your current email security setup and close the gaps that leave businesses exposed.
Frequently Asked Questions
Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, which gives a solid baseline of anti-phishing, safe links, safe attachments and anti-malware. Most SMEs without specific regulatory pressure will find this sufficient when it is configured properly. Businesses in high-risk sectors, those with a prior incident, or those needing advanced BEC detection may benefit from an added third-party layer.
Safe links rewrites URLs in inbound email so that when a user clicks, they are first routed through the vendor's threat-intelligence service, which checks the destination in real time. If the link became malicious after delivery — a time-of-click attack — the user is blocked. Safe links is part of Microsoft Defender for Office 365 and is one of the most valuable controls a gateway provides.
Yes. Every email security system can be bypassed by a sufficiently determined attacker. Common techniques include newly registered domains with no negative reputation, attacks sent via compromised legitimate accounts, links that are clean at delivery but malicious at click, and social engineering that carries no malicious payload at all. Layered controls — MFA, training, monitoring — exist to address exactly these vectors.
Cloud-based gateways add minimal latency, usually well under a second for message processing, so most users notice no difference in delivery times. Sandboxing of attachments can introduce a brief hold while the file is analysed, but this is typically seconds rather than minutes. The protection gained far outweighs the small processing delay.
A gateway with data loss prevention can scan outbound email for patterns that match personal data — national insurance numbers, payment card numbers, health information — and flag or block messages that risk breaching UK GDPR. As the ICO makes clear, appropriate technical controls are part of your obligations. A gateway does not replace a full data-protection programme, but it is an important control against accidental or deliberate exposure via email.
Related Reading
Email Protection: Layers of Defence Explained
How email gateways fit into a complete layered email protection strategy for business.
Email Security Risks
The biggest email security threats facing UK businesses and how to mitigate them.
Email Security Fundamentals
Understanding the four pillars of business email security from authentication to user training.
Protect your business → Get Cybersecurity Assessment