Most attacks don't break in.
They arrive in the inbox.
Phishing, business email compromise, and malicious attachments are how the majority of security incidents start. We filter them in front of Microsoft 365 and Google Workspace, audit the mailboxes behind them, and stay reachable when something convincing gets through — so a well-written email doesn't turn into a wire transfer.
The inbox is the front door
Most attacks on a business don't start with someone breaking through a firewall. They start with a message that looks completely ordinary — an invoice from a vendor you actually use, a shared file notification, a short note from the owner asking someone in accounting to take care of something quickly.
The dangerous ones often have no malware in them at all. No attachment to scan, no link to check. Just a believable request from a name your team recognizes, sent from a domain that's one character off. Filters built to catch spam and known-bad files have very little to say about a message like that.
AllTech puts real filtering in front of your mail, hardens the tenant behind it, and reviews what's actually reaching your people — so the messages designed to look normal get caught before someone acts on one.
What this actually stops
These aren't a vendor's case study or an industry average. They're 31 days of our own inbound mail — 26 AllTech mailboxes, June 27 to July 27, 2026, straight out of the Cloudflare Email Security report we'd hand any client.
About 500 a day across 26 mailboxes
Malicious, spoofed, or suspicious — roughly one per person per day
Scams, credential theft, brand impersonation
Someone posing as one of our own people
Another 5,494 messages were filtered as spam or bulk marketing. We don't count those as attacks, because they aren't. And roughly 60% of everything scanned was ordinary business mail that went straight through untouched, which is how a properly tuned filter should behave. The 793 above are the messages that were actually trying something.
We run this on our own company first. If we're going to put it in front of your mail, you should be able to see what it does to ours.
Filtering, hardening, and a person to call
Delivered through Cloudflare Email Security in front of Microsoft 365 or Google Workspace — deployed and tuned by us, either as part of a Zero Trust rollout or as a standalone layer.
Caught Before Delivery
Mail is inspected before it reaches the mailbox, not quarantined after someone has already seen it in their inbox. Phishing, malware, and spoofed senders get stopped at the door.
Built for the Targeted Stuff
Commodity spam is the easy part. What we’re actually watching for is the message written specifically for your business: a lookalike domain, a display name matching your CFO, a payment request timed to the end of the month.
Links and Attachments Checked
Attachments are analyzed rather than pattern-matched, and links are evaluated at click time — because a URL that’s clean on delivery isn’t always clean an hour later.
Your Domain, Used Only by You
SPF, DKIM, and DMARC configured properly so your domain can’t be used to impersonate you to your own customers and vendors — and so your legitimate mail actually lands.
A Look Inside the Mailbox
Mailbox security audits through Exchange Online PowerShell: hidden forwarding rules, legacy authentication still enabled, sign-ins that don’t match how someone works, permissions nobody remembers granting.
Someone Who Answers
When a message gets through and someone clicks, you call a local engineer who already knows your tenant — not a support queue that starts by asking what your domain is.
The messages that get stopped
Most of what arrives is legitimate business mail, and most of what's filtered is ordinary spam nobody would have fallen for. The messages worth talking about are the ones written to be believed. A few examples of what that looks like:
Any one of these can be explained away in the moment. That's the point of them. In a single recent month on our own mail, filtering stopped 642 confirmed malicious messages, 204 impersonation attempts, and 115 spoofed senders before delivery. Catching them at the door — or noticing the mailbox rule an hour after it appears — is the difference between a near miss and a wire you can't get back.
Why the built-in filter isn't the whole answer
Microsoft 365 and Google Workspace both include filtering, and it does real work. Bulk spam, known malware, and mail from senders with a bad reputation get handled without anyone thinking about it. We keep all of that running.
The gap is in the attacks built to look ordinary. A message with no attachment, no link, and no malware — sent from a domain registered two days ago, matching the display name of someone the recipient trusts — doesn't look like a threat to a filter tuned for known-bad content. It looks like email.
We can put a number on that from our own mail. Of the 642 malicious messages caught in a recent 31-day window, the report found 108 with a malicious link and just 6 with a malicious attachment. The rest carried no link, no attachment, and no known-bad file — just words, from a name someone recognized.
The threat types line up with that. The most common was plain scam content, followed by identity deception and brand impersonation — attacks that work on the reader, not the machine. Over the same month, 204 messages were flagged specifically as impersonation attempts against people on our own staff, about seven a day. Content scanning doesn't catch those. What catches them is knowing who normally emails your organization, from where, and what a message from them usually looks like.
There's a second gap inbound filtering can't close at all. Once credentials are stolen, the attacker is sending from a real mailbox on a trusted domain, and inbound filtering has no opinion about them. That's why email security has to include what's behind the mailbox: multi-factor authentication, conditional access, and someone regularly checking for the forwarding rules and sign-in patterns that show an account has already been taken.
From setup to the message that gets through
We Look at What You Have Now
Your tenant, your current filtering, your SPF and DKIM records, and what’s already reaching your team. Most environments have at least one gap nobody knew about.
Filtering Goes in Front
Email Security is deployed ahead of Microsoft 365 or Google Workspace. No mailbox migration, no change to how your team sends and receives mail.
Messages Get Analyzed
Sender reputation, domain age and similarity, attachment behavior, link destinations, and how the message compares to normal traffic for your organization.
We Harden the Mailbox Behind It
Authentication records, legacy protocols, forwarding rules, mailbox permissions, and MFA coverage — the things that decide how bad it gets if one message lands.
We Tune It
False positives get corrected. Delivery problems get fixed. Rules get adjusted as your business changes vendors, opens locations, and hires people.
We Respond When One Gets Through
Someone clicks eventually. We reset the account, kill active sessions, look for what was changed, and tell you in plain language what happened.
What this looks like day to day
Your team keeps using Outlook exactly the way they did before. The difference is what never arrives. Across 26 of our own mailboxes over 31 days, about 500 messages a day came in. They split like this:
Ordinary business mail, delivered without anyone touching it. A filter that’s constantly interfering with real work isn’t tuned — it’s just loud.
Marketing, newsletters, and commodity spam. Handled automatically, no one’s day interrupted, and not something we’d dress up as a security win.
793 messages that were malicious, spoofed, or impersonating one of our people. That’s the part worth paying for.
Spread across 26 people, that's about one real attempt per person per day — every one of them handled before anyone had to make a judgment call in the middle of a busy afternoon.
Built for real environments
A Business That Moves Money by Email
Title work, construction draws, escrow, large vendor payments. If wiring instructions ever travel by email, you’re a target worth researching first.
A Finance or AP Team
Invoice fraud works because the invoice looks real and the timing is right. Filtering plus a verification habit is what breaks it.
An Owner Who Gets Impersonated
Names and titles are public. So is your email format. In our own numbers, a single mailbox absorbed 40% of all malicious mail sent to the company — attackers research who’s worth pretending to be, and who’s worth writing to.
A Law Firm or Accounting Practice
Client confidentiality isn’t optional, and a compromised mailbox exposes years of correspondence at once.
A Company on Microsoft 365 With Default Settings
Defaults are a starting point, not a configuration. Legacy authentication, unrestricted forwarding, and missing DMARC are common and quietly expensive.
A Business That’s Already Been Hit
Once an account has been compromised, the mailbox needs an actual review — not just a password reset and a hope that it’s over.
An Organization With Compliance or Insurance Requirements
Cyber insurance applications increasingly ask about email filtering and MFA. Answering honestly is easier when it’s already in place.
A Nonprofit or Municipality Running Lean
Donor records, resident data, and public email addresses, with no one on staff whose job is watching for this.
What we don't do
We don't claim to stop every phishing email. Nobody can, and a vendor who tells you otherwise is selling something.
Filtering is one layer. It works best alongside multi-factor authentication (so a stolen password isn't enough), conditional access (so sign-ins from places your team doesn't work get blocked), security awareness training (so the ones that land get reported instead of clicked), and endpoint monitoring (so an attachment that opens doesn't get far).
The single highest-value thing isn't technical at all: a rule that no change to banking or payment details is ever accepted by email alone. Someone calls a known number and confirms it out loud. That one habit stops the most expensive attacks we see.
Our goal isn't a promise that nothing gets through. It's fewer attempts reaching your team, a harder target behind the mailbox, and a fast, honest response the day something does.
Email security works best in layers
Endpoint Security & Ransomware Protection
Most malicious attachments still have to execute somewhere. Endpoint monitoring catches what happens after a click.
Learn moreManaged SOC
Suspicious sign-ins and mailbox changes are more useful when someone is watching them around the clock.
Learn moreCloudflare Zero Trust
Email Security is one component of a full SASE deployment alongside Access, Gateway, and Tunnel.
Learn moreMicrosoft 365 & Entra ID
MFA, conditional access, and tenant configuration are where email security either holds or falls apart.
Learn moreRemote IT Support
What we deliver remotely vs. what needs someone on-site, in one place.
Learn moreFind out what's actually reaching your inbox.
We'll review your Microsoft 365 or Google Workspace tenant, check your authentication records and mailbox rules, and show you what current filtering is and isn't catching. Plain findings, no pressure.