PS ProTech(305) 699-5652
← All posts

All professional firms

What email security does that your inbox doesn't

· PS ProTech · 3 min read

Your email already has a spam filter, and it's good at its job. So it's reasonable to ask why anyone would pay for email security on top.

The answer is that spam and targeted attacks are different problems.

What the built-in filter is for

Microsoft and Google filter email in enormous volume. They're very good at recognizing messages sent to millions of people: bulk spam, known scams, attachments carrying known malware.

A targeted attack is none of those things. It's one email, sent to one person at your firm, written for them. It has no attachment and no bad link. It reads:

Hi Maria, are you at your desk? I need a payment sent before 3. I'm in mediation so email only.

Nothing in that message is malicious in a way a bulk filter can measure. It's a sentence from someone who appears to be a partner.

What dedicated email security adds

It checks who the sender really is. An email can show any name it likes. Email security looks underneath: is this address the one that partner normally uses? Is the domain one letter away from yours? Has this sender ever written to this person before?

It reads for intent. Requests to move money, change bank details, buy gift cards or sign in somewhere are flagged because of what they ask for, however well they're written.

It follows links. A link can point to a harmless page when the email is delivered and be switched to a fake sign-in page an hour later. Email security checks the link when it's clicked, not only when it arrives.

It warns the reader. A banner at the top of a message, such as "This sender is outside your firm and has not emailed you before," puts the right doubt in someone's mind at the right moment.

It can pull a message back. If one phishing email is identified, the same message can be removed from every other mailbox it reached.

Protecting your name, not only your inbox

There's a second half to this that firms often miss. Criminals can send email that appears to come from your firm, to your clients.

Three settings on your domain, known as SPF, DKIM and DMARC, tell the world which servers are allowed to send email as you and what to do with messages that fail the check. Set up properly, they stop most of that impersonation. Set up badly or not at all, your clients can receive a convincing invoice "from you" with someone else's bank details.

It costs nothing to configure and it's one of the first things we check.

How to tell if you need it

Ask these about your firm:

  • Do you move money on emailed instructions? Client funds, closings, payroll, invoices.
  • Would a message from a partner be acted on without question?
  • Do clients send you documents by email from addresses you can't verify?
  • Has anyone received a message this year that looked real and wasn't?

A yes to any of them means targeted email fraud is a live risk. For firms handling closings it's the main one, as we describe in wire fraud at closing.

What it won't do

No filter catches everything, and a message that arrives by text or phone bypasses it entirely. Email security works alongside three other things:

The short version

Your inbox filter stops bulk junk. Email security stops the message written for one person at your firm. With AI now writing those messages flawlessly, as we cover in how AI changed phishing, the second problem is the one growing.

Email security is included from our Business plan. You can price it for your headcount in the plan builder, or ask us to check your domain's settings in a free IT and cybersecurity review.

See what it costs for your firm.

Build a plan in two minutes. No call required.