The short answer
There is no single email security product that solves the problem. Attackers use email to steal passwords, deliver malware, impersonate executives and redirect payments. The most effective defense combines technology and process:
- Authenticate your domain with SPF, DKIM and DMARC so others cannot easily send email as you.
- Protect accounts with multi-factor authentication, preferably phishing-resistant.
- Filter and inspect incoming mail, links and attachments.
- Prepare your people with training, simulations and an easy way to report suspicious messages.
- Verify payment and account changes through a separate channel before acting.
1. Authenticate your email domain
Without domain authentication, anyone can send a message that appears to come from your address, to your customers, suppliers or staff. Three standards work together:
- SPF (Sender Policy Framework) lists the servers allowed to send email for your domain.
- DKIM (DomainKeys Identified Mail) adds a cryptographic signature that proves a message was not altered.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving servers what to do with messages that fail those checks, and sends you reports.
Joint guidance from CISA, the NSA, the FBI and MS-ISAC recommends enabling DMARC with SPF and DKIM and setting DMARC to "reject" for the mail you send, so spoofed messages are refused before delivery (CISA). NIST's trustworthy email guidance describes DMARC as a gradually tightening policy, from "none" (monitoring) through "quarantine" to "reject", and recommends publishing an SPF record on domains that do not send mail so they cannot be used for spoofing (NIST).
Start in monitoring mode. DMARC reports often reveal forgotten services (a newsletter tool, a billing system, a website form) that send email for you and need to be added before you enforce.
2. Protect accounts with strong MFA
Most email compromises start with a stolen password. Multi-factor authentication (MFA) stops many of them, but not all MFA is equal. CISA notes that some forms are vulnerable to phishing, "push bombing" (repeated push prompts until someone approves), SIM swaps and similar attacks, and calls phishing-resistant MFA, such as FIDO security keys and passkeys, the gold standard (CISA).
Practical steps:
- Require MFA for every mailbox, with no exceptions for executives.
- Use phishing-resistant methods for administrators and finance staff first.
- Block legacy email protocols that bypass MFA.
- Enable number matching or similar protections if you use push approvals.
3. Filter and inspect incoming mail
Modern email security, whether built into Microsoft 365 or Google Workspace or added as a separate service, should:
- Scan attachments in a sandbox and block risky file types.
- Rewrite and check links at the time they are clicked, not only on delivery.
- Flag external senders and look-alike domains.
- Detect impersonation of executives and known suppliers.
- Block known malicious domains, URLs and IP addresses at the email gateway, as the joint CISA guidance recommends (CISA).
Filtering reduces volume; it never catches everything. That is why the next two steps matter.
4. Prepare your people
Staff are not the weakest link; they are the last line of defense when filters miss something. The joint CISA guidance recommends regular training on social engineering and phishing, including the importance of reporting suspicious emails, links and attachments, and using the reporting features built into email platforms (CISA). Internal phishing simulations and clear procedures for verifying suspicious requests round this out.
- Give everyone a one-click "report phishing" button.
- Thank people who report, including false alarms. Never punish someone for reporting a mistake.
- Keep training short, frequent and based on real examples, including QR-code phishing and fake invoices.
- Use simulation results to target coaching, not to shame.
See building a security awareness training program.
5. Verify payments and account changes out of band
Business email compromise (fraudulent requests to change banking details, pay urgent invoices or buy gift cards) often involves no malware at all. The message may even come from a real, compromised supplier mailbox.
- Require a phone call to a known number (not one in the email) before changing any supplier's or employee's banking details.
- Require two people to approve payments above a set amount.
- Treat urgency, secrecy and changes in payment instructions as warning signs.
- Include phishing and payment fraud in your incident response plan so staff know what to do if money has already moved, including contacting your bank immediately to try to recall a wire or ACH transfer.
Email security checklist
- SPF published and accurate for all sending services
- DKIM signing enabled for our domain
- DMARC in place, with a plan to move from "none" to "reject"
- Unused domains protected against spoofing
- MFA required on every mailbox; phishing-resistant MFA for admins and finance
- Legacy authentication blocked
- Attachment sandboxing and time-of-click link checks enabled
- External sender warnings turned on
- One-click phishing report button available to all staff
- Callback verification required for banking changes
- Incident plan covers compromised mailboxes and payment fraud
Limitations
These measures reduce risk; they do not remove it. DMARC protects your exact domain but not look-alike domains registered by attackers. Training effects fade without reinforcement. Review your controls at least yearly, and whenever you add a new service that sends email on your behalf.
Next step
Our email security service configures domain authentication, filtering and account protection, and our cybersecurity awareness training prepares staff. If you use Microsoft 365, see our Microsoft 365 security baseline.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- Phishing Guidance: Stopping the Attack Cycle at Phase One, CISA, NSA, FBI and MS-ISAC
- Trustworthy Email (NIST SP 800-177 Rev. 1), National Institute of Standards and Technology
- Implementing Phishing-Resistant MFA (fact sheet), Cybersecurity and Infrastructure Security Agency (CISA)
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.