Cybersecurity · Singapore

Microsoft 365 won't stop this: the truth about email security

Microsoft 365 filters a lot of spam and obvious phishing by default. Business email compromise is designed to slip past exactly that kind of filtering.

Quick answer M365 catches obvious spam and malware well. It's not designed to reliably stop business email compromise — messages that look completely legitimate and rely on a person acting fast, not on malware.

What Microsoft 365 catches by default — and what still gets through

Microsoft 365 includes real, genuinely useful email filtering out of the box: spam filtering, malware scanning, and basic anti-phishing checks across every mailbox. It catches a meaningful share of obvious attacks. What it's not designed to fully stop on its own is the more targeted category: messages that look legitimate, from a sender that looks right, asking for something plausible.

Microsoft's own documentation on anti-phishing protection in Microsoft Defender for Office 365 is a good starting point for understanding exactly what's included at which licence tier — worth checking directly rather than assuming.

ProtectionIncluded by defaultWhat layered security adds
Spam / bulk mailYes, strong out of the boxRefinement, fewer false positives
Known malware attachmentsYesSandboxing of unknown/novel files
Obvious phishing linksYesTime-of-click re-checking as threats evolve
Domain impersonation / lookalikesPartialDedicated detection & alerting
Business email compromiseWeak — no malware to catchSender-behaviour analysis
Teams / SharePoint linksLimitedExtended protection beyond the inbox

What business email compromise actually looks like

Business email compromise (BEC) rarely looks like a typical phishing email. There's often no suspicious link, no obvious malware attachment — just a message that appears to come from a real supplier, a real executive, or a real customer, asking for a bank detail change, an urgent invoice payment, or sensitive information. Because it doesn't trip the usual "this looks like spam" signals, it's exactly the kind of attack that slips past default filtering and relies on a person, under time pressure, making a fast decision.

The tell isn't in the email — it's in the process. BEC succeeds when a payment or data request skips a human verification step, not because a filter failed to catch it.

Layered email security: what it adds on top of Defender

Layered email security adds detection that goes beyond content scanning:

  • Sender behaviour analysis — flagging when a "known" contact suddenly emails from an unusual pattern
  • Domain impersonation and lookalike-domain detection
  • Protection extended to Teams and SharePoint, not just the inbox — attacks increasingly arrive through shared links, not just email
  • Faster, more visible incident response when something does get through, rather than relying on a single missed report

The human layer: why training still matters

No filtering layer, however good, replaces a team that knows what to look for and feels comfortable flagging something that feels off — including when it turns out to be nothing. Security awareness training works best when it's ongoing and realistic, not a once-a-year slide deck nobody remembers by month three.

What to check today

Three quick, concrete questions worth answering this week:

  1. Does your business have a documented process for verifying bank detail changes by phone, not email?
  2. Is MFA enforced on every mailbox, including shared and service accounts?
  3. Does your team know exactly who to tell, quickly, if something looks wrong?

If any of those answers is "not sure," that's the actual starting point — not a bigger tooling purchase.

Related service

Cybersecurity Solutions — email security and threat detection are core parts of Cloudeli's cybersecurity service.

FAQ

Questions, answered

Not sure what's actually protecting your inbox?

Book a free security assessment and we'll show you exactly what's covered today and what isn't.