Skip to main content

Security Updates

Email Security and Continuity Enhancements

We are updating the email protection systems we run for clients. This note lists what is in place today and what comes next.

850 I.T. Team

A glowing padlock and shield surrounded by email and network symbols.

Our clients carried on working through major service outages and cyber incidents this year, including the recent Amazon AWS disruption. We repeatedly test the custom setups and redundancies we run.

We are finalizing the Emergency Mailbox setup as the next change for a potential Microsoft service outage. It holds undeliverable mail in a queue and retries delivery until the main service returns.

We are adding email protection layers for phishing detection, attachment and link scanning, business email compromise (BEC) prevention, outbound encryption, and data loss prevention (DLP).

Core protection

What every client is covered by.

The filter blocks spam, malware, and phishing before the inbox. The list below shows what runs inside it.

  • AI-powered detection

    Artificial intelligence and machine learning scan email for suspicious content, including content that has not been reported before. They flag new phishing attempts and changing attack techniques.

  • Custom content filtering

    We can filter junk before it reaches your team using rules for your organization based on keywords, attachments, or sender addresses.

  • Impostor email protection

    Detects and blocks spoofed messages that attempt to impersonate trusted contacts, executives, or internal staff.

  • Geo-blocking

    Filters incoming mail from regions where you do not do business.

  • End-user digests

    Each user receives daily or weekly digests listing quarantined emails. Users can review the list and release legitimate messages that the filter flagged by mistake.

Targeted attack protection

Checks for targeted email attacks.

We are adding tools that scan links and attachments, identify impersonation attempts, and let administrators pull malicious messages from inboxes.

  • URL and predictive defense. Scans and rewrites email links to block access to malicious sites, including new phishing sites.

  • Attachment defense. Checks email attachments and runs them in an isolated sandbox before delivery.

  • BEC detection. Uses behavioral analysis and artificial intelligence to identify business email compromise (BEC) attacks.

  • Email warning tags and message pull. Alerts administrators to suspicious emails and lets them pull a malicious message back from every inbox.

Illustration of links being checked before they open
Illustration of outgoing email being encrypted

Outbound email protection

Controls for outgoing email.

We scan outgoing messages for threats, apply rules to block sensitive data, and encrypt sensitive emails in transit.

  • Data loss prevention (DLP). Automatically detects and blocks sensitive data, such as credit card numbers, personal identifiers, or confidential documents, from being sent outside the organization.

  • Automatic encryption. Encrypts sensitive emails automatically in transit to support your privacy obligations.

  • Outbound filtering. Scans outgoing messages for potential threats or compromised accounts that could be unknowingly sending spam or malware.

  • Policy-based controls. Administrators can set custom rules to restrict outbound communication to approved recipients, specific regions, or domains.

Email continuity and archiving

Mail delivery and storage during an outage.

During a provider outage, a separate inbox handles sending and receiving while the system queues incoming mail and archives messages.

  • Emergency inbox

    Provides a separate mailbox where you can send and receive messages while your main mail service is down.

  • Email spooling

    Stores all incoming mail during an outage and automatically attempts delivery again after service returns.

  • Email archiving and storage

    Encrypts archived messages and applies controls against tampering and unauthorized access.

  • Email search and discovery

    Search tools retrieve historical emails for audits, internal investigations, or legal discovery.

We are rolling these changes out in stages to every client. We continue to monitor the systems and report on how they run. Send questions about these changes to our support team through the support page.

Feature glossary

The terms, explained.

Automatic remediation

A feature available to Advanced+ and Professional+ customers using Microsoft 365. This feature allows Proofpoint Essentials to automatically retract emails post-delivery if they are later identified as malicious.

Data loss prevention (DLP)

Adds various data loss prevention options to the filters section, such as dictionaries and smart identifiers that can detect sensitive information patterns.

URL defense

Scans inbound emails for malicious links, rewrites URLs to route through a protection service, and performs click-time analysis to detect threats that emerge after initial delivery.

Attachment defense

Scans inbound and outbound emails for known malicious attachments using signature-based detection and reputation analysis.

Attachment defense sandboxing

Scans inbound and outbound emails for unknown attachments and applies a temporary hold while the attachment is executed in a secure, isolated environment to observe its behavior.

Outbound relaying

Scans outbound mail, encrypts what needs encrypting, and applies data loss prevention before it leaves your organization.

All insights

Talk through your email security.

Thirty minutes on the phone about what fixing your email would involve. No sales pitch.