EMAIL SECURITY
Email Security: Stop Phishing, Spoofing and Account Takeover
Email is where phishing, fake invoices and stolen passwords start. We layer Microsoft's email protection, email authentication and Conditional Access, so bad messages get caught and a stolen password is not enough.
Protection that works in layers
Every Microsoft 365 mailbox comes with built-in protection through Exchange Online Protection. Microsoft Defender for Office 365 adds Safe Links, Safe Attachments and stronger anti-phishing, including protection against criminals pretending to be your executives or your domains.
A surprising amount of that protection is not switched on by default. Microsoft's own guidance says the Standard and Strict preset security policies stay off until someone turns them on, while only the basic built-in protection runs automatically. We check what your tenant is actually doing and close the gaps.
Email security is also about who gets into the mailbox. Conditional Access is Microsoft's zero trust policy engine. It checks the user, device, location and risk before letting anyone in, which is how a stolen password stops turning into a hijacked inbox.
Talk to our teamWhat email security covers
Seven layers, one plan, explained in plain English.
Email authentication
We set up SPF, DKIM and DMARC for every domain you send from, in that order, so criminals cannot easily send email that looks like it came from you.
Preset security policies
We turn on the Standard preset policy for your users and Strict for high-risk people such as finance and executives. Microsoft keeps the settings up to date automatically.
Safe Links and Safe Attachments
Links are checked when clicked and attachments are opened in a safe environment first, in email and in Teams, SharePoint and OneDrive.
Impersonation protection
We list your executives, finance team and key suppliers so look-alike senders and domains are flagged. Priority account protection can cover up to 250 high-value users.
Phishing reports and training
Staff can report suspicious email with the Outlook Report button, and where licensed we run Attack simulation training to test and teach your team.
Conditional Access for email
We require multi-factor authentication, block legacy sign-in methods and can require a compliant device or approved app to read email on a phone.
Account takeover and risk
Where Entra ID P2 is licensed, risk-based policies can challenge or block sign-ins that look compromised. Suspicious inbox rules are one of the signals Microsoft uses.
Mail flow, quarantine and rules
We review mail flow rules, allow and block lists and quarantine settings, because careless allow entries let malicious email through.
See which apps your policies actually cover
The Coverage tab in Conditional Access shows which applications have Conditional Access policies and which do not, over the past seven days. It is the quickest way to spot an app, such as email, sitting outside your protection.
We review this view during every email security check, so a missing policy never goes unnoticed.
How an email security project works
Check what is really on, then close the gaps.
01
Assess
We review your email authentication, threat policies, licences and sign-in policies, and show you where you are exposed.
02
Configure
We set up SPF, DKIM and DMARC, turn on the preset policies and tune impersonation protection for your key people.
03
Protect access
We build Conditional Access policies in report-only mode first, then enforce them in stages so staff are not locked out.
04
Monitor
We review quarantine, user reports and sign-in activity, and adjust the policies as threats change.
Why businesses choose us for email security
Protection your team barely notices, until it matters.
Security first
Security settings, multi-factor authentication and sensible access controls are part of the design, not an afterthought.
Plain-English advice
No jargon. We explain the options, the trade-offs and our recommendation.
Microsoft Solutions Partner
Microsoft recognises our team for its Microsoft expertise and customer success.
Ongoing support
After go-live our help desk is there when your team has questions.
Email security questions
Straight answers to what people ask us most.
What is the difference between Exchange Online Protection and Defender for Office 365?
Exchange Online Protection is the built-in protection included with every Exchange Online mailbox. Defender for Office 365 adds Safe Links, Safe Attachments and advanced anti-phishing such as user and domain impersonation protection. Plan 2 adds investigation and automation tools and Attack simulation training.
Is Defender for Office 365 included in Business Premium?
Yes. Defender for Office 365 Plan 1 is included in Microsoft 365 Business Premium and, from 1 July 2026, in Microsoft 365 E3 and Office 365 E3. Plan 2 is included in Microsoft 365 E5, and Business Premium customers can add it through Microsoft's Defender Suite add-on.
Are the Standard and Strict policies turned on automatically?
No. Built-in protection is on by default and gives basic Safe Links and Safe Attachments protection, but the Standard and Strict preset policies stay off until an admin turns them on and chooses who they apply to. Microsoft recommends starting with Standard for all users.
What are SPF, DKIM and DMARC?
They are three DNS records that help prove your email is genuine. SPF lists who can send for your domain, DKIM signs outgoing messages, and DMARC tells receiving servers what to do with messages that fail. Microsoft says to configure them in that order for every domain you use for email.
What is Conditional Access and do I need it for email?
Conditional Access is the Microsoft Entra policy engine that decides who can sign in, from what device and under what conditions, for example requiring multi-factor authentication. It needs Entra ID P1, which is included in Microsoft 365 Business Premium. It is a key defence against a stolen password being used to read email.
Can you block legacy sign-in methods?
Yes. Blocking sign-ins that use legacy authentication protocols is one of the most common Conditional Access policies. It is also a Microsoft Secure Score recommendation.
Will phishing still get through?
No product catches everything. Layered protection reduces what reaches inboxes and limits the damage if someone clicks, and user reporting helps Microsoft's filters learn. We also help your team learn to spot and report phishing.
How does this relate to zero trust?
Zero trust means verify explicitly, use least privilege and assume breach. Conditional Access applies those ideas to every sign-in, and the layers on this page assume that a bad email will eventually arrive.
Related services
Other ways we can help.
Microsoft, Microsoft 365, Microsoft Defender for Office 365, Microsoft Entra and Exchange Online are trademarks of the Microsoft group of companies. Total Solutions IT is a Microsoft Solutions Partner. Product screenshots: Microsoft Learn (CC BY 4.0). Used with permission from Microsoft.
Is your business email as protected as you think?
Talk to our team. We will check what is really switched on and show you the gaps.