Email Security

Enable and Review Email Threat Protection

Use the protections included with your email service, assign quarantine and reporting owners, and test without live malware or credential collection.

Content review: 2026-09-22 · Estimated effort: Medium

Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.

Before you start

Before starting: identify the mail administrator, alert reviewer, and backup contact. Record current policies, licenses, mail gateways, and exceptions. Agree how users report missing or suspicious mail and how the business will recover from a false positive.

Put it into practice

  1. Inventory the service's included spam, malware, phishing, spoofing, and attachment controls. In Microsoft 365, inspect Email & collaboration > Policies & rules > Threat policies. Safe Links, Safe Attachments, and some impersonation features depend on Defender licensing; absence of a paid feature is not a reason to leave included controls unused.
  2. For Microsoft 365, compare applicable policies with the linked Standard preset guidance and pilot an appropriate recipient group before expanding. Inspect precedence so you know which policy actually applies. For other providers, use their included protection settings and current admin guidance; product labels and entitlements differ.
  3. Review broad allow lists, transport-rule bypasses, and third-party gateways that may undermine filtering. Remove unnecessary exceptions in a controlled pilot after confirming dependencies. Do not allow an entire domain simply because one message was incorrectly quarantined; investigate and use the narrowest supported correction.
  4. Assign quarantine review and alert handling to named people with backup coverage. Explain how staff report suspicious messages without interacting with links or attachments, and how to request release of legitimate mail. Verify sender context before releasing quarantined content; record decisions and recurring false positives.
  5. Verify: use benign mail to confirm normal delivery and the user-reporting route. Use only a provider-documented harmless test procedure, with approval and designated test recipients, to check filtering/quarantine behavior. Do not send real malware, collect passwords, or conduct surprise phishing simulations. A delivered ordinary email does not prove threat detection works.
  6. Record effective policy scope, test outcomes, reviewer, and limitations. If rollout disrupts mail, roll back the scoped change with approval and investigate rather than disabling protection globally. Recheck after license, gateway, or policy changes; even correctly configured filtering cannot catch every malicious message.

Make a start

Tools and templates

Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-22; check current vendor terms before choosing.

Start without another software subscription

Review protections included with the actual mailbox subscription, assign quarantine ownership and use the free verification worksheet.

Where this stops: Manual review and awareness training do not replace Safe Links, Safe Attachments or other licensed protections. Do not upload confidential mail to public scanning sites as a substitute.

See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.

Microsoft Defender preset security policies

Included protections for cloud mailboxes; advanced features require Defender licensing

Open Email & collaboration > Policies & rules > Threat policies > Preset Security Policies. Compare the Standard settings with your current policies and test an approved scope.

Limits: Safe Links, Safe Attachments and advanced impersonation protections are not included in every mailbox subscription. A free trial is not an ongoing free solution.

Your information: Messages and quarantine data are processed by the mail service. Use harmless test mail and keep customer content out of this worksheet.

Official instructions: Microsoft Defender preset security policies ↗

Download a working template

Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.

Fictional worked example

Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.

A team reviews its existing email protections and assigns responsibility for quarantine.

Use the Security change and verification record template.

What to enter before testing

Change ID
EXAMPLE-MAIL-01
Prerequisites and recovery access checked
Confirm license, policy scope and quarantine reviewer
Expected allowed and blocked behavior
Ordinary test mail arrives; approved benign protection test follows documented behavior
Actual test results
Not tested

How to verify

Compare the effective policy with the intended licensed protections. Use only provider-documented harmless tests in an authorized scope, then check delivery, quarantine visibility and the reviewer response route. Record which features were actually checked.

If the result is unexpected

If ordinary mail is incorrectly quarantined, investigate the message and policy before making a narrow approved correction. Do not broadly allow-list a domain or release suspicious mail just to pass the exercise. Never use live malware or collect credentials.

Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.

Sources and review approach

Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.

  • NIST CSF 2.0: PR.PS-01: protective configuration
  • NIST CSF 2.0: DE.CM-09: monitoring email content and services
How this guidance is prepared