Microsoft 365 Email Security: Improving Your Security Features

Microsoft 365 email security is the layered protection around every Exchange Online mailbox, combining built-in filtering, Microsoft Defender for Office 365, encryption, data loss prevention, and SPF, DKIM and DMARC to stop phishing, malware and data leaks. Office 365 runs on the same stack. Your plan decides which layers you own.

Email is still the front door for most attacks. Phishing is how attackers steal credentials, and the scale is hard to ignore. Microsoft tracks more than 600 million identity attacks every day, and over 99% of them are password-based, according to its 2024 Digital Defense Report, which is why a stolen mailbox password is still the cheapest way for an attacker to get inside a business. Your Microsoft 365 tenant already ships with most of the tools to push back, from attachment sandboxing and link checking to encryption, data loss prevention and the DNS records that prove your mail is really yours. Most of them sit half configured. Some aren’t licensed at all. Both are fixable.

This guide covers what each plan includes, which protections to switch on, and where email authentication fits, so you can compare what you pay for against what is actually running in your tenant today. It’s written for owners and IT leads who run Microsoft 365 or still call it Office 365. Same product, same settings. Let’s start with licensing.

Three stacked protection layers over an email envelope, showing built-in security, Defender Plan 1 and Plan 2

What does Microsoft 365 email security include on each plan?

Microsoft describes its email protection as a ladder with 3 rungs. Every subscription with cloud mailboxes gets the built-in security features, which most admins still know as Exchange Online Protection. Defender for Office 365 Plan 1 adds defenses against zero-day malware, phishing and business email compromise, including Safe Links and Safe Attachments that also cover files and messages in SharePoint, OneDrive and Teams. Plan 2 adds investigation, hunting, automation and phishing simulations, per Microsoft’s Defender for Office 365 overview.

LayerIncluded withWhat it adds
Built-in security (Exchange Online Protection)Every Microsoft 365 subscription with cloud mailboxesAnti-malware, anti-spam, spoof intelligence, zero-hour auto purge
Defender for Office 365 Plan 1Microsoft 365 Business Premium, plus Office 365 E3 and Microsoft 365 E3 from July 1, 2026Safe Links, Safe Attachments, impersonation protection, Real-time detections
Defender for Office 365 Plan 2Microsoft 365 E5, A5 and G5Threat Explorer, Threat Trackers, automated investigation and response, attack simulation training

That July change matters. The Defender for Office 365 service description now lists Plan 1 inside Office 365 E3 and Microsoft 365 E3, effective July 1, 2026. If you’re on E3 and priced a Plan 1 add-on last year, check the billing page in the Microsoft 365 admin center before you renew it, because you may now be paying for the same protection twice.

One caution. A license isn’t a configuration. Impersonation protection stays off until someone turns on a Standard or Strict preset policy, which is the first item in our list of Microsoft 365 security settings most SMBs miss.

How does Defender for Office 365 stop phishing, malware and bad links?

Defender for Office 365 is the cloud service that screens mail for credential phishing, business email compromise and ransomware. It uses machine learning, Microsoft’s threat signals and detonation to judge messages, attachments and links. Here’s how the 4 core protections compare.

ProtectionWhat it doesWhat it blocks
Safe AttachmentsDetonates email attachments in a sandbox before they reach the inboxMalware and ransomware payloads
Safe LinksRewrites and re-checks URLs at the moment you click themPhishing and malicious links
Anti-phishingUses machine learning and impersonation detectionCredential theft, spoofing, domain impersonation
Anti-spamFilters unsolicited and bulk mailSpam, mass phishing, email harvesting

Safe Attachments

Safe Attachments opens every attachment in a sandbox before delivery. Bad file? It never lands. The same protection covers files in SharePoint Online, OneDrive and Teams, and your policies decide whether suspicious attachments get blocked, replaced or redirected for review by an admin before anyone opens them.

Safe Links

Safe Links checks URLs in email and other Microsoft 365 apps, then checks them again at the moment someone clicks. That second check is the point. A link that was clean at breakfast and weaponized by lunch still gets caught. Microsoft explains the full mechanism in its Safe Links overview.

Anti-phishing

Anti-phishing works in 2 tiers. Spoof intelligence ships with every mailbox. Impersonation protection, the part that catches a fake message from your CFO or a lookalike vendor domain, needs Defender for Office 365. The difference matters. Your policy decides what happens next, from junking the message to quarantining it to adding a safety tip that warns the reader the sender only looks like someone they already know. If your team still falls for lookalike senders, our guide to spotting phishing attacks is a good companion for training.

Anti-spam

Anti-spam filters unwanted mail, bulk senders and email-harvesting attempts. Nothing exotic here. The setting worth a look is the bulk complaint level threshold, because the default lets a lot of gray mail through. Tune it once. Revisit it yearly.

Why do SPF, DKIM and DMARC matter for Microsoft email security?

Filtering protects what comes in. Authentication protects your name on what goes out. Both matter. Microsoft says internet domains need SPF, DKIM and DMARC working together to prove a sender is real, and it stamps its own verdict on inbound mail as a composite authentication result in the message header.

Sealed email envelope passing through verification gates, representing SPF, DKIM and DMARC checks

Here’s the order we set them up in.

  1. Publish an SPF record that includes spf.protection.outlook.com and every other service that sends as your domain.
  2. Create the 2 DKIM CNAME records for each custom domain, then turn on DKIM signing in the Defender portal.
  3. Publish a DMARC record at p=none with reporting, read the reports for a few weeks, then move to quarantine and finally reject.

Step 2 is the one people skip. Don’t skip it. Mail from the default onmicrosoft.com domain is DKIM signed automatically, but a custom domain like yours needs its own CNAME records. Microsoft also changed the CNAME format for custom domains added from May 2025 onward, so copy the exact values from the DKIM page in your own Defender portal instead of an old blog post or a DNS template.

There’s a deliverability reason too. Starting May 5, 2025, Outlook began enforcing SPF, DKIM and DMARC for domains that send more than 5,000 messages a day, and Microsoft’s announcement names the 550 5.7.515 error that non-compliant senders get back. Most small businesses never hit 5,000 a day. Their marketing platform might. Check it.

Which Microsoft 365 controls protect sensitive email?

These controls come from Exchange Online and Microsoft Purview rather than Defender, and they matter most when regulated data leaves your tenant. An earlier version of this guide filed them under Defender. That was wrong. We’ve fixed it.

Microsoft Purview Message Encryption

Message encryption lets you send protected email to people inside and outside your organization. It works with Outlook.com, Yahoo, Gmail and other services, and outside recipients open the message through Microsoft’s encrypted message portal after signing in with a Microsoft, Gmail or Yahoo account, according to Microsoft’s Purview Message Encryption guide. It supports HIPAA and GDPR. It doesn’t turn itself on. You have to enable it.

Data Loss Prevention (DLP)

Leaks aren’t always malicious. DLP stops the accidental or deliberate leak of sensitive data such as card numbers, Social Security numbers or health records, and it can warn the sender with a policy tip before the message ever leaves the building. It’s a core tool for HIPAA and GDPR compliance. Microsoft’s Purview DLP documentation breaks down how the policies work across Microsoft 365.

Mail flow rules (also called transport rules)

Mail flow rules and transport rules are the same feature. Exchange Online calls them mail flow rules, and Microsoft’s own documentation still lists transport rules as the other name. We’d listed them as 2 features before. They’re 1. Use them to force encryption on messages that match a pattern, block risky attachment types, add an external sender warning, or route specific mail to a different destination such as a compliance mailbox or a partner’s secure server. Keep the list short.

What does Defender for Office 365 do after a threat gets through?

Blocking is half the job. The rest is finding what slipped past and cleaning it up. Some of these tools need Plan 2. Check your license first.

Alerts

Alerts flag suspicious activity in your mail environment, from malware detections to phishing campaigns to unusual sending. You can also build custom alerts around a sender, recipient, subject or attachment. Start with the defaults.

Automated Investigation and Response (AIR)

AIR is a Plan 2 feature. It investigates alerts on its own, gathers evidence, traces the root cause and recommends or applies the fix, such as deleting or quarantining the malicious messages it finds across every mailbox that received them.

Threat Analytics

Threat Analytics gives you reports from Microsoft security researchers on active campaigns. Use it to see whether a threat in the news actually touches your tenant. It’s context, not control.

Threat Explorer and Real-time detections

Threat Explorer is Plan 2. Plan 1 tenants get Real-time detections, a lighter view of the same mail data. Either one lets you find a message across the organization and remove it in a few clicks. Microsoft’s quick tell is simple. If you see Explorer under Email and collaboration in the Defender portal, you’re on Plan 2.

How do you track Microsoft 365 email security over time?

Microsoft Secure Score measures your security posture across Microsoft 365, email included. It rates your settings, compares them with Microsoft’s recommendations and ranks the actions that would raise your score, so you can see which change buys the most protection for the least disruption to your users. Working that list is one of the fastest ways to close real gaps, as Microsoft details in its Secure Score guide. Two more tools help.

Message Trace

Message Trace tracks a message from sender to mailbox. You can see its status, recipients, subject, size and delivery errors, then export the results for analysis or reporting. It’s usually the first stop when a user swears an email never arrived. Start there.

Mail Flow Insights

Mail Flow Insights gives you dashboards on the health of your mail environment. Watch message volume, delivery and bounce trends, and you’ll spot a compromised mailbox or a broken connector before users do, since a sudden spike in outbound mail from one account is often the first visible sign that its password was stolen.

Is native Microsoft 365 email security enough?

So is it enough? Usually. For most small and midsize businesses, our honest answer is yes, once it’s licensed and configured. Business Premium already carries Plan 1. The gap we usually find isn’t a missing product. It’s a preset policy nobody turned on, a custom domain with no DKIM, or a DMARC record stuck at p=none for 2 years.

Two business leaders discussing whether native Microsoft 365 email security is enough

A third-party email security gateway can still earn its cost. It makes sense when you need a feature Microsoft doesn’t offer or your compliance team wants a second, independent filter in front of the mailbox, for example because an auditor or cyber insurer asked for layered email controls in writing. If you go that route and point your MX record at the gateway, set up Enhanced Filtering for Connectors so Microsoft still sees the original sending IP. Skip that step and Microsoft’s own filtering works half blind. Our email security solutions page covers how we decide between the 2 approaches.

Microsoft 365 Email Security Questions, Answered

What is Microsoft 365 email security?

Microsoft 365 email security is the set of tools that protect Microsoft 365 mailboxes from phishing, malware and data loss. The core layers are Exchange Online Protection, Microsoft Defender for Office 365, encryption, data loss prevention, and SPF, DKIM and DMARC for your domain.

Is Microsoft Defender for Office 365 included in my plan?

Probably, on Business Premium or E3. Plan 1 is included in Microsoft 365 Business Premium and, from July 1, 2026, in Office 365 E3 and Microsoft 365 E3. Plan 2 comes with Microsoft 365 E5, A5 and G5. Business Basic and Business Standard need a paid add-on.

Is Office 365 ATP the same as Defender for Office 365?

Yes. Office 365 Advanced Threat Protection was renamed Microsoft Defender for Office 365, so older guides that mention ATP Safe Links or ATP Safe Attachments describe the same features.

How are Safe Links and Safe Attachments different?

Safe Attachments opens email attachments in a sandbox to catch malware before delivery. Safe Links rewrites and re-checks URLs at click time, so a link that turns malicious after delivery still gets blocked.

Does Microsoft 365 encrypt email automatically?

Not for every message. You turn on Microsoft Purview Message Encryption and then add mail flow rules or sensitivity labels so that sensitive email is encrypted without the sender having to remember. That setup also supports HIPAA and GDPR requirements.

Do I still need DMARC if Microsoft 365 already filters my inbound mail?

You do. Inbound filtering protects your users, while DMARC protects your domain from being spoofed in mail sent to everyone else. Start at p=none with reporting, fix the senders that fail, then move to quarantine and reject.

How does Microsoft 365 Secure Score help?

Secure Score rates your current security settings, compares them with Microsoft recommendations and lists prioritized actions. Working through that list is the quickest way to find email protections you already license but still leave switched off.

Our Takeaway

Microsoft 365 email security is mostly a configuration problem, not a buying problem. Check which Defender plan you own, especially if you’re on E3. Turn on a preset policy. Finish DKIM and push DMARC past p=none. Then use Secure Score to keep the gains from drifting. That’s the whole plan. If you’d rather hand that work off, our managed IT services team handles it end to end, inside a broader cybersecurity program that also covers endpoints, identity and backups for your whole business.

Want a second set of eyes on your Microsoft 365 email security?

Speak to an IT Expert

We will review your Defender policies, DKIM and DMARC records and Secure Score, then tell you what is worth fixing. No cost and no obligation.

About Author

Learn More