← All services
Email Security & Archive

Email Security & Archive

Protected inboxes and a complete, compliant record of every message.

Overview

Stop threats and keep the records you need

In short: Filtering, impersonation protection, continuity and an archive written outside the mailbox. Establish what your Microsoft licence already does before adding a gateway: for many estates the honest reasons to add one are continuity and archive depth rather than filtering.

Email is still the number one way attackers get in, and the number one place important records quietly go missing. Both problems are invisible right up until they aren't.

Who this is for
Phishing and business email compromise are a real and growing risk for your team
You need a searchable, tamper-proof record of correspondence for compliance or disputes
An email outage would stop your business communicating, with no fallback

The problem

One convincing phishing email is all it takes, and once it lands, a missing archive means you can't even reconstruct what happened. Meanwhile a mailbox outage with no continuity leaves the whole business unable to send or receive until it's fixed.

What we would do

Establish what your Microsoft 365 licence already does before adding a gateway. For many estates on Business Premium or E5, properly configured Defender covers the filtering, and the honest reasons to add a gateway are continuity, independent archiving and vendor separation rather than better detection.

  • If you have a retention or production obligation, an archive held outside the platform that generates the mail is a materially stronger position.
  • If an hour without email has a real cost, continuity is worth buying regardless of how good the filtering is.

When we are not the answer: If you are paying for a gateway whose continuity has never been tested and whose archive nobody searches, you are paying for a product doing nothing your Microsoft licence is not. We will tell you to drop it.

How we help

Email is still the number one route in for attackers, and the number one place important records go missing. We layer advanced protection in front of your mailboxes and keep a tamper-proof archive behind them.

More on how we deliver email security and archiving

Your people are shielded from phishing and malware, and your business keeps a searchable, compliant record of correspondence for as long as you need it.

Retro pixel-art illustration of a glowing envelope shielded from descending pixelated bug sprites
What's included

Everything you need, managed for you

Anti-phishing, anti-malware and spam filtering
Compliant, searchable email archiving
Email continuity during outages
Retention and legal-hold policy management
Data loss prevention and encryption
Detailed reporting and quarantine control

What does Microsoft 365's built-in email protection already cover?

More than people assume, and it is worth being precise about it before spending money on top. Exchange Online Protection, included with every mailbox, handles connection filtering, anti-spam, anti-malware and basic anti-phishing, plus outbound spam control and the quarantine that holds what it catches.

Defender for Office 365, included in some plans and available as an add-on to others, layers on link rewriting and detonation, attachment sandboxing, impersonation protection for named people and domains, and the investigation tooling that lets somebody trace where a message went after delivery.

The honest position is that most organisations are not using what they already pay for. Anti-phishing policies sit at defaults with no impersonation protection configured for the finance team or the directors who are actually targeted, domain authentication is published but not enforcing, quarantine is never reviewed, and inbound mail rules created by users are never audited.

Turning on and tuning what is already licensed is the cheapest security improvement available in most tenants, and it should always come before a purchase decision about an additional layer.

What does a dedicated email security layer add on top?

Three things principally: independence, continuity and depth of archiving. Independence matters because a layer sitting in front of or alongside Microsoft's own filtering uses different detection engines and different threat intelligence, so the messages one misses are not automatically the messages the other misses. It also means the protection and the mail platform do not share a single failure: when the platform has a bad day, the filtering layer is still standing.

Continuity is the capability Microsoft's own stack does not really offer, because the platform cannot provide a fallback for itself. Depth of archiving is the third: a dedicated archive is written outside the mailbox and outside the tenant, which is what makes it defensible as an independent record rather than a copy of something an administrator could change.

Beyond those, a dedicated layer typically adds:

  • A cleaner quarantine and release workflow for users
  • More granular policy control
  • Reporting a non-specialist can actually read, which sounds minor until you have to answer a client security questionnaire

Why is business email compromise the expensive one?

Because it contains no malware, no suspicious link and often no spelling mistake, so there is very little for a filter to detect. The pattern is consistent: an attacker gets into one mailbox, usually through a convincing credential-harvesting page rather than anything technical, and then reads quietly for a while.

They learn how invoices are worded, who signs off what, when the finance manager is on leave, and which supplier is mid-project. Then they send an entirely ordinary email asking for bank details to be updated, from a real address, in the middle of a real thread.

That is why the controls that stop the loss are split across technology and process. The technical side is impersonation protection for your executives and key suppliers, domain authentication that stops your own domain being spoofed, and alerting on the tell-tale signs of a compromised mailbox, particularly newly created inbox rules that forward or delete.

The process side is the one that actually saves the money: any change to bank details is verified by telephone, on a number already held on file, never a number taken from the email. Most successful invoice frauds would have been stopped by a single phone call.

What do SPF, DKIM and DMARC do, and why is DMARC usually wrong?

They are the three records that let a receiving mail server decide whether a message claiming to be from your domain really is.

  • SPF lists which servers are permitted to send on your behalf.
  • DKIM adds a cryptographic signature, so the message can be shown to have come from an authorised sender and not been altered in transit.
  • DMARC ties the two together, tells receivers what to do when a message fails, and asks them to report back on what they are seeing.

Without all three, spoofing your own domain is trivial, which is exactly the scenario your staff are least equipped to spot.

DMARC is where most estates fall down, and always in the same way: the record is published in monitoring mode and left there. That produces reports nobody reads and instructs receivers to deliver failing mail anyway, so the protection is nominal.

Moving to enforcement is genuinely careful work, because every legitimate service that sends as your domain has to be found first:

  • The marketing platform
  • The accounting package
  • The booking system
  • The recruitment tool
  • The scanner in the corner that emails PDFs

Miss one and its mail stops arriving. That is why it is staged, with reporting reviewed between each step, rather than switched on in an afternoon.

What does email continuity actually mean in practice?

It means a separate service accepts, queues and holds your inbound mail when the primary platform is unavailable, and gives your people a way to read and send in the meantime, usually through a web interface.

When the platform comes back, the queued mail delivers into the mailboxes as normal. The point is not that mail is never delayed. It is that nothing is bounced back to the sender as undeliverable, and the business can still communicate rather than sitting and waiting.

Two things are worth understanding about it. First, continuity is deliberately limited: it is a way to keep trading through an outage, not a full replica of Outlook, so historic mail and the usual integrations may not be there.

Second, it is only useful if people know it exists before they need it, which means the access route, the sign-in method and the announcement plan have to be documented and, ideally, rehearsed. A continuity service nobody can find the URL for during an outage is a line on an invoice.

Archiving, retention and backup: what is the difference?

They answer three different questions and are routinely confused. Retention is a policy inside the mail platform that governs how long items are kept and when they are removed. Archiving is a separate, written-once record of every message that passed through, kept independently of the mailbox so it survives deletion, mailbox limits and administrator action, and built to be searched.

Backup is about recovery: getting data back into a working state after loss, corruption or an attack. The two are not interchangeable:

  • An archive is not a backup, because it is not designed to restore a mailbox
  • A backup is a poor archive, because it is not designed to be searched, held or produced as evidence

The practical consequence is that the answer to 'do we have a copy of that email from three years ago' depends on which of the three you actually have. Most organisations need retention configured properly whatever else they do, an archive if they have regulatory, contractual or litigation exposure, and backup because Microsoft's shared responsibility model puts your data in your hands. Our backup service covers the recovery side of that in detail, and the two are usually scoped together.

What does a compliant archive need to do?

Capture everything, keep it unaltered, and let you find it. Capture means journaling at the point of transmission so inbound, outbound and internal mail are all recorded, rather than depending on what happens to remain in a mailbox afterwards.

Unaltered means the stored copy cannot be edited or removed inside the retention period, including by an administrator, which is the property that makes an archive worth anything in a dispute. Finding it means search that works across the whole estate, including attachments, quickly enough that a request is answered in minutes rather than being a project.

Beyond that, the operational requirements are the ones that get overlooked at purchase and matter at use. Legal hold that can be applied to a person or a subject and reliably overrides normal disposal. An audit trail showing who searched, when and for what, because unlogged access to everyone's correspondence is its own problem.

Defensible export in a format a solicitor or a regulator will accept. And a stated route for getting your data out if you leave the supplier, because an archive you cannot extract has quietly become a hostage rather than an asset.

How do you handle quarantine without burying people?

By deciding deliberately who reviews what, rather than letting the default decide for you. There are two failure modes and they pull in opposite directions. Send every user a digest of everything held and they stop reading it within a fortnight, then release something malicious because it was in a list they skimmed.

Route everything to IT and the queue grows faster than anyone can work it, so genuine business mail sits undelivered and people start asking suppliers to resend to a personal address, which is worse than the original problem.

What works is separating the categories. High-confidence malware and phishing should never be user-releasable at all: there is no legitimate reason to let somebody talk themselves into a message the system is confident about. Bulk and graymail can go to a user digest with a simple release, because the cost of a mistake is low.

The uncertain middle needs a named owner with the time to look, and a fast route for a user to ask about a specific message. Then review the pattern monthly, because a category that repeatedly holds legitimate mail is a tuning problem, and repeatedly releasing from it teaches people the wrong instinct.

What happens after a mailbox has been compromised?

The order matters, because the instinctive first move is the wrong one. Resetting the password alone leaves an attacker with a valid session, so the first actions are to revoke active sessions and refresh tokens, reset credentials, and re-register multi-factor authentication if there is any chance the attacker enrolled their own method.

Then remove what they left behind: inbox rules that forward or delete, added mailbox delegates, changed forwarding settings, and any application consent granted from the account, which is the persistence mechanism most often missed.

Only then does the investigation start, and this is where an archive and good logging earn their cost. What did they read, what did they send, and to whom? Did any message ask a client or supplier to change payment details, and if so those parties need telling immediately, by phone.

Whether the incident is notifiable to the ICO is a decision to be taken deliberately and on the basis of evidence, within the statutory timescale, and personal data in a mailbox somebody else has read is squarely the kind of thing that has to be assessed rather than assumed harmless. Trying to reconstruct any of this from a mailbox the attacker had time to tidy is exactly the position an independent archive avoids.

Where does staff training fit, and where does it not?

It fits as the layer that catches what technology cannot, which for email means the well-written message with no payload. The training that works is short, specific and about your own processes rather than generic awareness: what our invoices actually look like, that we never change bank details by email, that a request to buy gift cards is never real, and that reporting something that turns out to be legitimate is always the right call. The single most valuable habit you can build is a one-click report button people use without embarrassment.

Where it does not fit is as a substitute for controls, or as a way to move blame. Sophisticated phishing is designed to fool attentive people under time pressure, and any programme whose implicit message is that a click is a personal failing will produce staff who hide their mistakes, which is far more expensive than the click.

Simulated phishing is useful when it is used to measure whether reporting rates are rising, and counterproductive when it is used to name individuals. The technology should be good enough that people are the last line, not the first.

How much of this do you actually need, and where does our scope end?

Start with what you already own, because the sequence saves money. Tune the built-in protection, configure impersonation protection for the people who are genuinely targeted, get domain authentication to enforcement, and establish a quarantine process with an owner.

If that work has been done and the risk profile still justifies more, an additional layer is a reasonable next step, and it is more clearly justified where email downtime would stop the business trading, where a regulator or a client contract requires a retained searchable record, or where nobody internally has the time to review quarantine and alerts daily.

Archiving is a separate decision from filtering and should be taken on its own merits: what you are obliged to keep, for how long, and who might one day ask you to produce it. Our scope here is the email layer, from filtering and authentication through continuity to archive, alongside the Microsoft 365 configuration it depends on.

Broader identity hardening, Conditional Access and endpoint protection sit on our cyber security service, and recovering data rather than producing a record sits on our backup service. We would rather scope those separately and honestly than sell one thing labelled as another.

What Microsoft 365 covers as standard, and what a dedicated email security and archiving layer adds.
CapabilityMicrosoft 365 built-inWhat a dedicated layer adds
Spam and malware filteringIncluded with every mailbox through Exchange Online ProtectionA second, independent detection engine, so a miss by one is not automatically a miss by both
Link and attachment protectionAvailable through Defender for Office 365, included in some plans and an add-on to othersComparable protection applied before mail reaches the platform, with its own policy and reporting
Impersonation protectionConfigurable, but off or at defaults in most tenants until somebody tunes itPolicy aimed at named executives, finance staff and key suppliers, with clearer reporting on what it caught
Domain authentication (SPF, DKIM, DMARC)Fully supported; the records are yours to publish and enforce either wayNothing inherent, but suppliers commonly provide the reporting analysis that makes DMARC enforcement achievable
Continuity during an outageNot offered; the platform cannot be its own fallbackInbound mail queued and held, with a separate way to read and send until the platform returns
Retention inside the mailboxRetention policies, holds and eDiscovery, depending on planNot a replacement; these remain useful and should be configured regardless
Independent archiveRecords live inside the tenant, under administrative controlA journaled, write-once record held outside the mailbox and the tenant, searchable and defensible
Recovery after data lossRecycle bins and holds, with finite windowsNot what an archive is for; recovery is a backup question and should be scoped as one
Frequently asked

Questions we hear a lot

Isn't Microsoft 365's built-in protection enough?

Microsoft 365 gives you a strong baseline, but layered email security adds advanced anti-phishing, continuity during outages and independent, tamper-proof archiving. For businesses facing real phishing risk or compliance obligations, that extra layer is the difference between a near miss and an incident.

What does email archiving give us that mailboxes don't?

A compliant archive keeps a complete, searchable, tamper-proof record of every message independent of the mailbox, so nothing is lost to deletion or mailbox limits. It's essential for legal hold, regulatory retention and reconstructing what happened after an incident.

What happens to email during an outage?

Email continuity keeps your people sending and receiving even if the primary mail platform is down, so a Microsoft 365 or Exchange outage doesn't stop the business communicating.

Is an email archive the same as a backup?

No, and treating them as interchangeable is how organisations end up with neither. An archive is a journaled, unalterable record of every message that passed through, built to be searched, held and produced as evidence. A backup exists to restore data to a working state after loss, corruption or an attack. An archive won't rebuild a mailbox for you, and a backup won't stand up as a defensible record in a dispute. Most businesses with regulatory or contractual exposure need both, scoped separately.

Why does DMARC need to be set to enforce, not just monitor?

Because in monitoring mode DMARC tells receiving servers to deliver mail that fails authentication anyway. You get reports, which are useful, but no protection, so anyone can still send convincing mail claiming to be from your domain. Enforcement is what actually blocks it. Getting there safely means finding every legitimate service that sends as your domain first, the marketing platform, the accounting package, the booking system, the scanner that emails PDFs, and staging the change while reviewing the reports, because missing one means its mail stops arriving.

How does business email compromise get past a good filter?

Because there's usually nothing to detect. There's no malware, no attachment and often no link: just an ordinary message from a real, compromised account, sent inside a real conversation thread, asking for bank details to be changed. Filters are good at payloads and poor at intent. The controls that stop the loss are impersonation protection and compromise alerting on the technical side, and on the process side a rule that no payment detail is ever changed without a phone call to a number already on file. That call is what actually prevents the loss.

What should we do first if we think a mailbox has been compromised?

Revoke the active sessions and refresh tokens, then reset the password, in that order, because a password reset on its own can leave a valid session running. Re-register multi-factor authentication if there's any chance the attacker enrolled their own method. Then remove the persistence: inbox rules that forward or delete, added delegates, changed forwarding, and any application consent granted from the account. Only then investigate what was read and sent, warn anyone who may have received a fraudulent payment request, by phone, and assess whether the incident is reportable to the ICO within the statutory timescale.

Email security and archiving is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Doncaster, Wakefield, Harrogate, Huddersfield, Scarborough and Bradford and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.

Know your Microsoft 365 security posture

Book a free security posture review and we'll show you where your Microsoft 365 and identity setup is exposed, and the fastest way to close the gaps.

Technology partners

Best-of-breed technology we use to deliver email security and archiving.

See all technology partners →