Email Security & Phishing Protection

Most attacks don't break in.
They arrive in the inbox.

Phishing, business email compromise, and malicious attachments are how the majority of security incidents start. We filter them in front of Microsoft 365 and Google Workspace, audit the mailboxes behind them, and stay reachable when something convincing gets through — so a well-written email doesn't turn into a wire transfer.

Delivered remotely
Microsoft 365 & Google Workspace
The problem

The inbox is the front door

Most attacks on a business don't start with someone breaking through a firewall. They start with a message that looks completely ordinary — an invoice from a vendor you actually use, a shared file notification, a short note from the owner asking someone in accounting to take care of something quickly.

The dangerous ones often have no malware in them at all. No attachment to scan, no link to check. Just a believable request from a name your team recognizes, sent from a domain that's one character off. Filters built to catch spam and known-bad files have very little to say about a message like that.

AllTech puts real filtering in front of your mail, hardens the tenant behind it, and reviews what's actually reaching your people — so the messages designed to look normal get caught before someone acts on one.

Measured on our own mail

What this actually stops

These aren't a vendor's case study or an industry average. They're 31 days of our own inbound mail — 26 AllTech mailboxes, June 27 to July 27, 2026, straight out of the Cloudflare Email Security report we'd hand any client.

15,592
Messages scanned

About 500 a day across 26 mailboxes

793
Real attacks stopped

Malicious, spoofed, or suspicious — roughly one per person per day

642
Confirmed malicious

Scams, credential theft, brand impersonation

204
Impersonation attempts

Someone posing as one of our own people

Another 5,494 messages were filtered as spam or bulk marketing. We don't count those as attacks, because they aren't. And roughly 60% of everything scanned was ordinary business mail that went straight through untouched, which is how a properly tuned filter should behave. The 793 above are the messages that were actually trying something.

We run this on our own company first. If we're going to put it in front of your mail, you should be able to see what it does to ours.

What you get

Filtering, hardening, and a person to call

Delivered through Cloudflare Email Security in front of Microsoft 365 or Google Workspace — deployed and tuned by us, either as part of a Zero Trust rollout or as a standalone layer.

Caught Before Delivery

Mail is inspected before it reaches the mailbox, not quarantined after someone has already seen it in their inbox. Phishing, malware, and spoofed senders get stopped at the door.

Built for the Targeted Stuff

Commodity spam is the easy part. What we’re actually watching for is the message written specifically for your business: a lookalike domain, a display name matching your CFO, a payment request timed to the end of the month.

Links and Attachments Checked

Attachments are analyzed rather than pattern-matched, and links are evaluated at click time — because a URL that’s clean on delivery isn’t always clean an hour later.

Your Domain, Used Only by You

SPF, DKIM, and DMARC configured properly so your domain can’t be used to impersonate you to your own customers and vendors — and so your legitimate mail actually lands.

A Look Inside the Mailbox

Mailbox security audits through Exchange Online PowerShell: hidden forwarding rules, legacy authentication still enabled, sign-ins that don’t match how someone works, permissions nobody remembers granting.

Someone Who Answers

When a message gets through and someone clicks, you call a local engineer who already knows your tenant — not a support queue that starts by asking what your domain is.

What we actually catch

The messages that get stopped

Most of what arrives is legitimate business mail, and most of what's filtered is ordinary spam nobody would have fallen for. The messages worth talking about are the ones written to be believed. A few examples of what that looks like:

A vendor invoice you were expecting, with the banking details quietly changed
A short, urgent request from a lookalike domain one character off from your own
A payroll email asking to update an employee’s direct deposit before Friday
A Microsoft 365 sign-in page that looks exactly right, hosted somewhere it shouldn’t be
A shared-file notification pointing at a credential harvesting form
A reply inserted into a real conversation already in progress
An attachment that passed inspection on delivery and turned malicious afterward
A QR code inside a PDF, placed there to route around link scanning
A forwarding rule sending copies of finance mail to an outside address

Any one of these can be explained away in the moment. That's the point of them. In a single recent month on our own mail, filtering stopped 642 confirmed malicious messages, 204 impersonation attempts, and 115 spoofed senders before delivery. Catching them at the door — or noticing the mailbox rule an hour after it appears — is the difference between a near miss and a wire you can't get back.

Beyond the spam filter

Why the built-in filter isn't the whole answer

Microsoft 365 and Google Workspace both include filtering, and it does real work. Bulk spam, known malware, and mail from senders with a bad reputation get handled without anyone thinking about it. We keep all of that running.

The gap is in the attacks built to look ordinary. A message with no attachment, no link, and no malware — sent from a domain registered two days ago, matching the display name of someone the recipient trusts — doesn't look like a threat to a filter tuned for known-bad content. It looks like email.

We can put a number on that from our own mail. Of the 642 malicious messages caught in a recent 31-day window, the report found 108 with a malicious link and just 6 with a malicious attachment. The rest carried no link, no attachment, and no known-bad file — just words, from a name someone recognized.

The threat types line up with that. The most common was plain scam content, followed by identity deception and brand impersonation — attacks that work on the reader, not the machine. Over the same month, 204 messages were flagged specifically as impersonation attempts against people on our own staff, about seven a day. Content scanning doesn't catch those. What catches them is knowing who normally emails your organization, from where, and what a message from them usually looks like.

There's a second gap inbound filtering can't close at all. Once credentials are stolen, the attacker is sending from a real mailbox on a trusted domain, and inbound filtering has no opinion about them. That's why email security has to include what's behind the mailbox: multi-factor authentication, conditional access, and someone regularly checking for the forwarding rules and sign-in patterns that show an account has already been taken.

How it works

From setup to the message that gets through

01

We Look at What You Have Now

Your tenant, your current filtering, your SPF and DKIM records, and what’s already reaching your team. Most environments have at least one gap nobody knew about.

02

Filtering Goes in Front

Email Security is deployed ahead of Microsoft 365 or Google Workspace. No mailbox migration, no change to how your team sends and receives mail.

03

Messages Get Analyzed

Sender reputation, domain age and similarity, attachment behavior, link destinations, and how the message compares to normal traffic for your organization.

04

We Harden the Mailbox Behind It

Authentication records, legacy protocols, forwarding rules, mailbox permissions, and MFA coverage — the things that decide how bad it gets if one message lands.

05

We Tune It

False positives get corrected. Delivery problems get fixed. Rules get adjusted as your business changes vendors, opens locations, and hires people.

06

We Respond When One Gets Through

Someone clicks eventually. We reset the account, kill active sessions, look for what was changed, and tell you in plain language what happened.

In practice

What this looks like day to day

Your team keeps using Outlook exactly the way they did before. The difference is what never arrives. Across 26 of our own mailboxes over 31 days, about 500 messages a day came in. They split like this:

60%
went straight through

Ordinary business mail, delivered without anyone touching it. A filter that’s constantly interfering with real work isn’t tuned — it’s just loud.

35%
was spam and bulk

Marketing, newsletters, and commodity spam. Handled automatically, no one’s day interrupted, and not something we’d dress up as a security win.

5%
was actually trying something

793 messages that were malicious, spoofed, or impersonating one of our people. That’s the part worth paying for.

Spread across 26 people, that's about one real attempt per person per day — every one of them handled before anyone had to make a judgment call in the middle of a busy afternoon.

Who this is for

Built for real environments

A Business That Moves Money by Email

Title work, construction draws, escrow, large vendor payments. If wiring instructions ever travel by email, you’re a target worth researching first.

A Finance or AP Team

Invoice fraud works because the invoice looks real and the timing is right. Filtering plus a verification habit is what breaks it.

An Owner Who Gets Impersonated

Names and titles are public. So is your email format. In our own numbers, a single mailbox absorbed 40% of all malicious mail sent to the company — attackers research who’s worth pretending to be, and who’s worth writing to.

A Law Firm or Accounting Practice

Client confidentiality isn’t optional, and a compromised mailbox exposes years of correspondence at once.

A Company on Microsoft 365 With Default Settings

Defaults are a starting point, not a configuration. Legacy authentication, unrestricted forwarding, and missing DMARC are common and quietly expensive.

A Business That’s Already Been Hit

Once an account has been compromised, the mailbox needs an actual review — not just a password reset and a hope that it’s over.

An Organization With Compliance or Insurance Requirements

Cyber insurance applications increasingly ask about email filtering and MFA. Answering honestly is easier when it’s already in place.

A Nonprofit or Municipality Running Lean

Donor records, resident data, and public email addresses, with no one on staff whose job is watching for this.

Honest expectations

What we don't do

We don't claim to stop every phishing email. Nobody can, and a vendor who tells you otherwise is selling something.

Filtering is one layer. It works best alongside multi-factor authentication (so a stolen password isn't enough), conditional access (so sign-ins from places your team doesn't work get blocked), security awareness training (so the ones that land get reported instead of clicked), and endpoint monitoring (so an attachment that opens doesn't get far).

The single highest-value thing isn't technical at all: a rule that no change to banking or payment details is ever accepted by email alone. Someone calls a known number and confirms it out loud. That one habit stops the most expensive attacks we see.

Our goal isn't a promise that nothing gets through. It's fewer attempts reaching your team, a harder target behind the mailbox, and a fast, honest response the day something does.

Find out what's actually reaching your inbox.

We'll review your Microsoft 365 or Google Workspace tenant, check your authentication records and mailbox rules, and show you what current filtering is and isn't catching. Plain findings, no pressure.

Trusted by dozens of businesses