Email Security for Microsoft 365

Keep Microsoft 365. Add better protection.

If you run mail on Microsoft 365, you already have spam filtering. It is called Exchange Online Protection, it is included in your license, and for a lot of organizations it is enough. Before you pay anyone for a second layer, it is worth knowing exactly what you have and whether it is switched on properly.

This page covers what Microsoft gives you, how to configure it, where it runs out, and what a service like ours adds. If you want the shorter version of the same argument, we have written an honest answer to whether you need a third-party spam filter at all, including the cases where you do not.

What Microsoft 365 Already Does

Exchange Online Protection ships with every Microsoft 365 plan that includes Exchange Online. It filters inbound and outbound mail, scans for known malware, checks sender authentication (SPF, DKIM and DMARC), and applies a bulk mail score so newsletters and marketing blasts can be treated separately from genuine spam.

It is competent. It handles high-volume commodity spam and known malware well, it is updated continuously by Microsoft, and it costs you nothing extra. Any vendor who tells you it is useless is selling something.

Safe Links and Safe Attachments are not part of it. Those belong to Microsoft Defender for Office 365, which is a separate licence (Plan 1 or Plan 2), though it is bundled into some Business Premium and E5 subscriptions. This is the single most common licensing surprise we see. Check what you already own before you buy anything, from us or anyone else.

Configure It Properly Before You Buy Anything

A surprising number of tenants are running the out-of-the-box defaults. Working through the following will tell you whether your spam problem is a filtering problem or a configuration problem. All of it lives in the Microsoft Defender portal at security.microsoft.com, under Email and collaboration.

  • Review your anti-spam policy. The default policy applies to everyone unless you have created others. Check what action it takes on spam, whether that is moving to Junk or quarantining, and confirm somebody is actually reviewing the quarantine.
  • Set the bulk threshold deliberately. Bulk Complaint Level scores mail from mailing lists and marketing platforms on a scale. The default is permissive. If your users complain about newsletters rather than about spam, this is the setting to change.
  • Turn on end-user quarantine notifications. Without them, quarantined mail is invisible to the person it was addressed to, and your helpdesk becomes the release mechanism.
  • Consider the preset security policies. Microsoft publishes Standard and Strict presets. They are stricter than the defaults and they are a reasonable starting point if nobody has tuned anything.
  • Check your outbound policy. Outbound spam filtering protects your domain's reputation if an account inside your organization is compromised. It is easy to forget because the symptom lands on other people.
  • Fix SPF, DKIM and DMARC for your own domain. This is free, it is not filtering, and it stops other people being able to send mail that claims to come from you. If you publish no DMARC record, or one still set to p=none, that work is not finished.
  • Use the Tenant Allow/Block List properly rather than letting individual users build private allow lists that hide a wider problem.

Microsoft moves things around in that portal regularly, so treat the names above as what to look for rather than a fixed click path. If you work through all of it and the problem is solved, you do not need us, and we would rather you found that out now.

Where It Runs Out

Assuming it is configured properly, there are a few things Microsoft's filtering does not do, and one of them gets almost no attention.

It cannot hold your mail when the destination is unreachable. If your tenant is unavailable, or you run a hybrid setup and the on-premises server goes down, senders get bounces or their mail servers retry until they give up. There is no queue on your side holding it. This is the failure people remember, because the mail that goes missing is the mail that was sent during the outage.

A filtering service sitting in front of your tenant keeps accepting mail during an outage and delivers it when the destination answers again. SpyderMail holds mail for 7 days or more by default. It is the least glamorous feature we sell and the one customers thank us for.

One engine sees what one engine sees. A second filter with a different rule set, different reputation data and a different update cycle catches things the first one missed. That is the entire security argument for layering, and it is a real one.

Per-user control is limited. Managing allow and block lists per mailbox, with each user able to release their own mail without a password or a helpdesk ticket, is a different model from the tenant-wide administration Microsoft is built around.

Support is a queue. When mail from one customer stops arriving, the question is how fast a person can look at the headers with you. That is a judgement about vendors, not about technology.

What SpyderMail Adds

We step between the internet and your Microsoft 365 tenant. Your mailboxes, Outlook clients and calendars do not move, and nothing gets installed. Setup is one DNS change, pointing your MX records at us instead of at Microsoft. Removing us is the same change in reverse, which we think is the right way to sell something.

Our service level guarantee is a floor rather than a typical figure: 99.999% availability, 99% spam protection, and 100% protection against known viruses. In normal operation the service identifies more than 99.9% of spam, with one of the lowest false positive rates in the industry.

Enterprise-Level Filtering

We provide multiple layers of comprehensive protection for Microsoft Office 365 users, against the most current email-borne threats.

Support You Can Reach

Call during office hours, Monday to Friday 8:30am to 5:00pm MST, and speak with an experienced anti-spam person. There is no charge for SpyderMail-related support.

Simple Setup

NO software to install – just point your MX record to our servers.

Mail Bagging

If your mail server goes down, we save your email for up to 7 Days!

Regular Reports

You can choose from daily, weekly and monthly reports on email security for your domain.

Management Portal

You get access to the Management Portal, where you can control your antispam filter settings, manage your whitelist and blacklist, and do powerful searches on messages.

Flexible Per User Settings

Users can manage their own whitelists & blacklists … so you don’t have to.

Encrypted Email

We support TLS (Transport Layer Security) so you can encrypt sensitive emails.

Geographic Redundancy

Our data centers are in multiple cities so we stay up if one site goes down.

What It Costs

Per user, per month, in US dollars. Inbound Only and Essentials are both $1.99, the difference being that Essentials also filters outbound mail. Email Cloud is $2.99 and adds 90 days of email continuity. ClickSmart, which rewrites links so they are rechecked at the moment someone clicks them, is an add-on to any plan.

We publish those numbers because most of this industry does not, and because a price you have to request is a price that wastes your afternoon. Full plan comparison is on the pricing page.

Try it against your own mail flow for 30 days. One DNS change to start, one to stop.

Start Free Trial