Skip to main content
Back to blog
Security

Email security for Indian businesses: stopping the attacks that actually land

Most breaches still start with an email. Here is what genuinely reduces that, in order, and why filtering alone is not enough.

2026-08-176 min readBy Mohd Ahsan, Head of Managed Services
Filtered inbox showing quarantined phishing messages

Email remains the most common way into a business, and the attacks that succeed are rarely the crude ones your filter already catches. They are the plausible ones: an invoice with changed bank details, a message that appears to come from a director, a login page that looks exactly right.

Authenticate your own domain properly

SPF, DKIM and DMARC together let receiving servers verify that mail claiming to be from your domain actually is. Publishing them is the single most effective step against somebody impersonating your business to your own customers.

The common failure is stopping halfway. SPF and DKIM published, DMARC left in monitoring mode indefinitely, which instructs nobody to do anything. Watch the reports until you are confident every legitimate sender is aligned, then move to quarantine and then reject. Half-configured DMARC provides reassurance rather than protection.

Impersonation protection inside the tenant

Domain authentication does not stop somebody registering a lookalike domain or using a free mailbox with your director's display name. Anti-phishing policies with impersonation protection for your own domain and your key people catch a large share of that.

External sender warnings help too, provided they are used sparingly. A banner on every message is a banner nobody reads.

The attack that costs the most

Business email compromise, where an attacker either compromises or convincingly imitates an account and redirects a payment, does more financial damage than ransomware for many businesses and involves no malware at all. Filtering does not stop it because there is nothing malicious to detect.

What stops it is process. Any change to payment details is verified by phone to a number already on file, never a number in the email. Payments above a threshold need a second approver. Finance staff are told explicitly that urgency from a senior name is a warning sign rather than a reason to hurry.

Watch for forwarding rules

A standard move after compromising a mailbox is to create a rule that forwards or deletes certain messages, so the real user never sees the replies. Alert on mailbox rule creation, particularly rules involving external forwarding. It is a small configuration change and it catches a category of compromise that otherwise runs for months.

MFA changes the arithmetic

Most credential phishing exists to harvest a password. Multi-factor authentication makes a harvested password largely useless. Attackers have adapted with token theft and consent phishing, which is why conditional access and device compliance matter on top, but MFA remains the highest-value single control.

Training that is worth doing

Annual slide decks change little. What works is short, frequent and specific: what a real attack against your business looks like, and a genuinely easy way to report a suspicious message. Make reporting one click and thank people who use it, including when they are wrong. A culture where people hesitate to report is worse than one with a few false alarms.

A short priority order

MFA everywhere. SPF, DKIM and DMARC through to enforcement. Impersonation protection configured. Alerting on forwarding rules and unusual sign-ins. A written payment verification process finance actually follows. Reporting made easy. That covers most of what we see succeed.

Talk to the team

Have a question about this topic?

If you would like help applying any of this to your environment, send us the specifics and an engineer will reply.