Advanced email filtering plus correctly configured SPF, DKIM and DMARC — stopping both what arrives in your inbox and what gets sent using your domain.
Two different problems
“Email security” usually gets sold as one thing — filtering — and it addresses only half the risk.
What arrives. Phishing, malicious attachments, links that lead somewhere unpleasant. This is what filtering handles, and most businesses have something in place.
What gets sent as you. Anyone can compose an email claiming to be from your accounts address. Without the right DNS records, receiving mail servers have no way to tell that it is forged and will generally deliver it. Your customer receives an invoice that looks entirely legitimate, with different bank details.
The second problem damages your customers and your reputation rather than your inbox, which is precisely why it goes unaddressed for years. Nothing looks wrong from where you are sitting.
Fixing the outbound half
SPF, DKIM and DMARC are three DNS records. Configured correctly, forged mail claiming to be your domain gets rejected by the receiving server before a human sees it.
The catch is “correctly”. Partial SPF records that miss half your legitimate senders, DKIM that was never enabled, and DMARC set to p=none and left there for three years are all extremely common. A DMARC record in monitoring mode tells receiving servers to do nothing, which means the protection is not switched on.
Deployment is staged deliberately: monitoring first, so the reports reveal every system legitimately sending as you — the accounting platform, the CRM, the booking tool nobody remembered — then authorise those, then tighten policy to quarantine and finally reject. Skipping the staging is how a business blocks its own invoices.
Fixing the inbound half
Within Microsoft 365, the controls worth configuring properly are anti-phishing and impersonation policies (catching the display-name trick, where the name says John Taylor and the address is a Gmail account), safe links with click-time checking, safe attachments, and external sender warnings.
The one that catches the most real incidents, though, is not a filter at all: alerting on inbox rule creation. The first action after a mailbox compromise is almost always a hidden rule that forwards or deletes incoming mail so the real owner does not see the replies. Alerting on that is cheap, and it is how a compromise gets caught in hours rather than after the payment is gone.
Where this connects
Email security is the delivery mechanism for most attacks, but the damage usually happens elsewhere: a stolen credential used to log in, which is what multi-factor authentication limits, or a person acting on a convincing message, which is what awareness training addresses.
None of the three works alone. Together they cover the path an actual incident takes.