The short answer
There is no single email security product that solves the problem. Attackers use email to steal passwords, deliver malware, impersonate executives and redirect payments. The most effective defence combines technology and process:
- Authenticate your domain with SPF, DKIM and DMARC so others cannot easily send email as you.
- Protect accounts with multi-factor authentication, preferably phishing-resistant.
- Filter and inspect incoming mail, links and attachments.
- Prepare your people with training, simulations and an easy way to report suspicious messages.
- Verify payment and account changes through a separate channel before acting.
1. Authenticate your email domain
Without domain authentication, anyone can send a message that appears to come from your address, to your customers, suppliers or staff. Three standards work together:
- SPF (Sender Policy Framework) lists the servers allowed to send email for your domain.
- DKIM (DomainKeys Identified Mail) adds a cryptographic signature that proves a message was not altered.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving servers what to do with messages that fail those checks, and sends you reports.
The Canadian Centre for Cyber Security says complete protection requires all three, configured to tell recipients to reject inauthentic messages. It recommends moving gradually from a DMARC policy of "none" (monitoring) through "quarantine" to "reject", and protecting domains you do not use for email as well (Cyber Centre).
Start in monitoring mode. DMARC reports often reveal forgotten services (a newsletter tool, a billing system, a website form) that send email for you and need to be added before you enforce.
2. Protect accounts with strong MFA
Most email compromises start with a stolen password. Multi-factor authentication (MFA) stops many of them, but not all MFA is equal. The Cyber Centre notes that attackers can defeat common methods through MFA fatigue (repeated push prompts), token theft and machine-in-the-middle phishing, and strongly recommends FIDO-based, phishing-resistant options such as security keys and passkeys (Cyber Centre).
Practical steps:
- Require MFA for every mailbox, with no exceptions for executives.
- Use phishing-resistant methods for administrators and finance staff first.
- Block legacy email protocols that bypass MFA.
- Enable number matching or similar protections if you use push approvals.
3. Filter and inspect incoming mail
Modern email security, whether built into Microsoft 365 or Google Workspace or added as a separate service, should:
- Scan attachments in a sandbox and block risky file types.
- Rewrite and check links at the time they are clicked, not only on delivery.
- Flag external senders and look-alike domains.
- Detect impersonation of executives and known suppliers.
- Block known malicious domains and IP addresses, as the Cyber Centre recommends (Cyber Centre).
Filtering reduces volume; it never catches everything. That is why the next two steps matter.
4. Prepare your people
Staff are not the weakest link; they are the last line of defence when filters miss something. The Cyber Centre recommends internal phishing simulations, awareness training and clear procedures for employees to verify and report suspicious messages internally (Cyber Centre).
- Give everyone a one-click "report phishing" button.
- Thank people who report, including false alarms. Never punish someone for reporting a mistake.
- Keep training short, frequent and based on real examples, including QR-code phishing and fake invoices.
- Use simulation results to target coaching, not to shame.
See building a security awareness training program.
5. Verify payments and account changes out of band
Business email compromise (fraudulent requests to change banking details, pay urgent invoices or buy gift cards) often involves no malware at all. The message may even come from a real, compromised supplier mailbox.
- Require a phone call to a known number (not one in the email) before changing any supplier's or employee's banking details.
- Require two people to approve payments above a set amount.
- Treat urgency, secrecy and changes in payment instructions as warning signs.
- Include phishing and payment fraud in your incident response plan so staff know what to do if money has already moved.
Email security checklist
- SPF published and accurate for all sending services
- DKIM signing enabled for our domain
- DMARC in place, with a plan to move from "none" to "reject"
- Unused domains protected against spoofing
- MFA required on every mailbox; phishing-resistant MFA for admins and finance
- Legacy authentication blocked
- Attachment sandboxing and time-of-click link checks enabled
- External sender warnings turned on
- One-click phishing report button available to all staff
- Callback verification required for banking changes
- Incident plan covers compromised mailboxes and payment fraud
Limitations
These measures reduce risk; they do not remove it. DMARC protects your exact domain but not look-alike domains registered by attackers. Training effects fade without reinforcement. Review your controls at least yearly, and whenever you add a new service that sends email on your behalf.
Next step
Our email security service configures domain authentication, filtering and account protection, and our cybersecurity awareness training prepares staff. If you use Microsoft 365, see our Microsoft 365 security baseline.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- Don't take the bait: Recognize and avoid phishing attacks (ITSAP.00.101), Canadian Centre for Cyber Security
- Implementation guidance: email domain protection (ITSP.40.065), Canadian Centre for Cyber Security
- Secure your accounts and devices with multi-factor authentication (ITSAP.30.030), Canadian Centre for Cyber Security
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.