Cybersecurity

Email Security Gateway: What It Is and How It Protects You

An email security gateway sits between the internet and your inbox, scanning every inbound and outbound message for phishing, malware, spam and data loss risks before they reach staff. It is one of the most impactful single controls a business can deploy.

NH

Nathan Hill-Haimes

Technical Director

7 min read·Mar 2026

Email remains the number one entry point for attacks on UK organisations. The NCSC treats phishing as the most common route to compromise, which is exactly the traffic a gateway exists to filter. At AMVIA we configure and manage these gateways as part of our managed cybersecurity services — one provider, security-first, Microsoft-certified.

What is an email security gateway?

An email security gateway is a system — delivered as a cloud service, an on-premise appliance, or a built-in platform component — that processes every email entering or leaving your organisation before it reaches its destination. Think of it as a checkpoint at the boundary of your mail flow, applying several scanning techniques to catch threats and enforce policy.

In the cloud-first world most UK businesses now operate in, gateways are almost always cloud services that sit in the delivery path. Inbound email routes through the gateway before it reaches Microsoft 365 or Google Workspace, and outbound email passes through it on the way to the recipient. This needs no on-premise hardware and scales with email volume automatically.

What does an email security gateway actually do?

A gateway layers four jobs: stop bulk spam, block malicious attachments, detect phishing and impersonation, and inspect outbound mail for data loss. The first two are table stakes; the real value of a modern gateway is in the last two, where most damaging attacks now live.

Anti-spam and bulk mail filtering

The most basic function is identifying and filtering unsolicited bulk email so it never reaches the inbox. Modern spam filtering uses machine learning and reputation scoring of sending domains and IP addresses to achieve high catch rates. Most businesses have some spam filtering, but quality varies sharply between a basic provider filter and a dedicated gateway.

Anti-malware and attachment scanning

Every inbound attachment is scanned against known malware signatures and analysed for suspicious characteristics. Macro-enabled Office documents, executables, and archive formats (.zip,.7z) get particular scrutiny. Advanced gateways use sandboxing — running an attachment in an isolated environment to watch its behaviour — to catch threats with no known signature.

Anti-phishing and impersonation detection

This is where modern gateways add real value over basic filtering. Strong anti-phishing capabilities include:

  • Detection of emails impersonating your own domain or commonly spoofed brands
  • Analysis of headers, sender reputation and message content for phishing indicators
  • URL scanning at delivery and, in better implementations, at the moment of click (safe links)
  • Business email compromise (BEC) detection trained on the patterns of CEO and CFO impersonation attacks

Pairing gateway controls with phishing protection and user training closes the gap that technology alone cannot.

Outbound scanning and data loss prevention

Gateways scan outbound mail as well as inbound. This serves two purposes: stopping your systems from sending malware to customers and partners if you are compromised, and enforcing data loss prevention (DLP) policies that flag or block messages containing sensitive data such as payment card numbers, NHS numbers or confidential document keywords.

What are the gateway deployment options?

There are two practical routes for UK SMEs: use the gateway capabilities built into Microsoft 365, or layer a third-party gateway in front of it. The right choice depends on your sector, your risk appetite, and whether you have been burned by an email attack before.

Microsoft Defender for Office 365

Organisations on Microsoft 365 Business Premium or higher already have Microsoft's gateway capabilities built in. Per Microsoft's documentation, Defender for Office 365 Plan 1 includes anti-phishing policies, safe links, safe attachments and anti-malware scanning. Plan 2 — in Microsoft 365 E3/E5 or as an add-on — adds advanced hunting, automated investigation and response. Business Premium lists at £16.90 per user per month (ex VAT, annual) on microsoft.com/en-gb, so for many SMEs the included Defender capability is a sensible, already-paid-for starting point. We help businesses turn it on properly through Microsoft Defender for Business.

Third-party gateway solutions

Products such as Mimecast, Proofpoint, Barracuda and Abnormal Security sit in front of Microsoft 365 or Google Workspace, adding a filtering layer with different detection logic. Third-party gateways typically offer more granular reporting, richer admin controls, and — in Abnormal Security's case — an AI-driven approach to detecting BEC and social engineering that differs from Microsoft's methodology.

Layering a third-party gateway with Microsoft's native protection is a common configuration for UK businesses in regulated sectors — financial services, legal, and healthcare — where a single detection failure carries a high cost.

OptionBest forTypical add-on cost
Microsoft Defender for Office 365 Plan 1Most SMEs already on Business PremiumIncluded in Business Premium
Defender for Office 365 Plan 2Firms needing hunting + auto-investigationAdd-on / E5
Third-party gateway (Mimecast, Proofpoint, Barracuda, Abnormal)Regulated sectors, prior incidents, deep DLPfrom £2–£4 per user/mo (typical UK 2026 range)

What does an email gateway not cover?

A gateway operates at the message level, so it cannot catch everything. It will not stop a compromised-but-legitimate account, a payload-free social-engineering request, or a link that turns malicious after delivery. Those gaps are why MFA, training and account monitoring are necessary complements, not optional extras.

Specifically, a gateway does not protect against:

  • Compromised legitimate accounts sending phishing from real, authenticated inboxes — a gateway will deliver mail from a genuine Microsoft 365 account that has been taken over
  • Social engineering with no malicious link or attachment — a phone call, or an email requesting a bank-account change with no payload, passes gateway checks
  • Post-delivery threats where a URL was clean at delivery but later changed to host malicious content (mitigated by time-of-click scanning)

This is why we pair gateway controls with multi-factor authentication on Microsoft 365 and ongoing account monitoring.

How should you choose the right gateway?

For most UK SMEs, the Defender for Office 365 capability already in Microsoft 365 Business Premium is a solid, cost-effective starting point — properly configured. Businesses needing more depth should evaluate a third-party gateway: those in regulated sectors, those who have had a prior email incident, or those with complex outbound DLP requirements.

Third-party cloud gateways typically start from £2–£4 per user per month at market rates as of 2026. Weigh that against the alternative: the total cost of a single successful phishing attack almost always exceeds months of gateway subscription fees. The deciding question is not price — it is how much a single missed message would cost your business.

Is Your Email Gateway Properly Configured?

Having a gateway is not the same as having it correctly configured. AMVIA can review your current email security setup and close the gaps that leave businesses exposed.

Frequently Asked Questions