{"id":679,"date":"2026-08-13T11:33:49","date_gmt":"2026-08-13T11:33:49","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=679"},"modified":"2026-08-13T11:33:49","modified_gmt":"2026-08-13T11:33:49","slug":"email-security","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/email-security\/","title":{"rendered":"Email Security: Phishing, Spoofing and DMARC"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: EMAIL SECURITY\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Email security is the set of controls that stop phishing, impersonation and malicious attachments from reaching your team, and stop attackers sending mail that appears to come from your domain.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Threat protection<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Email security covers two directions. Inbound: filtering messages that carry phishing links, malicious attachments or payment fraud. Outbound: publishing SPF, DKIM and DMARC records so nobody else can send mail claiming to be your domain. Most breaches still start with an email, which is why buyers and auditors both ask about it.<\/p>\n<\/div>\n\n<p>The attacks that succeed rarely look technical. A convincing message asking for a payment redirect or a password reset defeats a filter tuned only for malware.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#threats\">The threats that get through<\/a><\/li>\n    <li><a href=\"#auth\">SPF, DKIM and DMARC<\/a><\/li>\n    <li><a href=\"#layers\">Layers of email security<\/a><\/li>\n    <li><a href=\"#osto\">How Osto protects the inbox<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"threats\">The threats that get through<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Threat<\/th><th>What it looks like<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Credential phishing<\/strong><\/td><td>A convincing login page reached from a link, harvesting the password and often the one-time code too<\/td><\/tr>\n    <tr><td><strong>Business email compromise<\/strong><\/td><td>No link, no attachment, just a plausible request to change bank details or approve a payment<\/td><\/tr>\n    <tr><td><strong>Domain impersonation<\/strong><\/td><td>A lookalike domain, or your real domain spoofed because DMARC is not enforced<\/td><\/tr>\n    <tr><td><strong>Malicious attachments<\/strong><\/td><td>Documents and archives carrying a payload, often password protected to defeat scanning<\/td><\/tr>\n    <tr><td><strong>Thread hijacking<\/strong><\/td><td>A reply injected into a real conversation from a supplier whose mailbox was already compromised<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The one with no technical signature<\/p>\n  <p>Business email compromise carries nothing for a scanner to detect. It is caught by behavioural signals, by payment approval processes that require a second channel, and by staff who know to verify.<\/p>\n<\/div>\n\n<h2 id=\"auth\" class=\"c-sage\">SPF, DKIM and DMARC<\/h2>\n\n<p>Three DNS records that together let a receiving server decide whether mail claiming to be from your domain really is. They protect your customers and partners from being phished in your name.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"SPF checks the sending server, DKIM checks the signature, and DMARC decides what to do when either fails.\">\n  <defs><marker id=\"emA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n  <text x=\"20\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">THREE RECORDS, ONE DECISION<\/text>\n\n  <rect x=\"12\" y=\"44\" width=\"222\" height=\"96\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"123\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#4a52a8\">SPF<\/text>\n  <text x=\"123\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Which servers are<\/text>\n  <text x=\"123\" y=\"115\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">allowed to send as you<\/text>\n\n  <rect x=\"248\" y=\"44\" width=\"222\" height=\"96\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"359\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">DKIM<\/text>\n  <text x=\"359\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">A signature proving the<\/text>\n  <text x=\"359\" y=\"115\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">message was not altered<\/text>\n\n  <rect x=\"484\" y=\"44\" width=\"264\" height=\"96\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"616\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">DMARC<\/text>\n  <text x=\"616\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">What to do when SPF or<\/text>\n  <text x=\"616\" y=\"115\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">DKIM fails, plus reporting<\/text>\n\n  <line x1=\"123\" y1=\"146\" x2=\"123\" y2=\"172\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#emA)\"\/>\n  <line x1=\"359\" y1=\"146\" x2=\"359\" y2=\"172\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#emA)\"\/>\n  <line x1=\"616\" y1=\"146\" x2=\"616\" y2=\"172\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#emA)\"\/>\n\n  <rect x=\"12\" y=\"180\" width=\"736\" height=\"52\" rx=\"12\" fill=\"#f4f5fd\"\/>\n  <text x=\"380\" y=\"202\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">DMARC policy: none (monitor only) &#8594; quarantine &#8594; reject<\/text>\n  <text x=\"380\" y=\"222\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">A policy left at none publishes reports but blocks nothing. Enforcement means quarantine or reject.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Most domains publish all three records and leave DMARC at none, which stops no impersonation at all.<\/figcaption>\n<\/figure>\n\n<h2 id=\"layers\" class=\"c-apri\">Layers of email security<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Filter at the gateway<\/p>\n    <p>Reputation, attachment analysis and link rewriting, applied before the message reaches a mailbox.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Authenticate the domain<\/p>\n    <p>SPF, DKIM and DMARC at enforcement, so nobody can send as you and your mail is trusted.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Train and verify<\/p>\n    <p>Awareness training plus a rule that payment or bank detail changes are confirmed on a second channel.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto protects the inbox<\/h2>\n\n<p>Osto provides inbound email security, filtering phishing attempts and malicious payloads before they reach your team. Because it runs in the same platform as <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mdm\/\">endpoint control<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> and the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a>, a suspicious message can be correlated with what happened next on the recipient&#8217;s device and account, which is how a click gets caught before it becomes an incident. Security awareness training is built into the compliance platform, so the human layer produces evidence too.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Stop the email before someone clicks it<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto filters inbound phishing and malicious payloads, and correlates a suspicious message with what happened next on the device.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Inbound filtering &middot; Endpoint correlation &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is email security?<\/summary>\n  <p>The controls that protect an organisation&#8217;s email: filtering inbound phishing and malicious attachments, and publishing SPF, DKIM and DMARC records so attackers cannot send mail that appears to come from your domain.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between SPF, DKIM and DMARC?<\/summary>\n  <p>SPF lists which servers may send on your behalf. DKIM adds a cryptographic signature proving the message was not altered. DMARC tells receiving servers what to do when SPF or DKIM fails, and sends you reports.<\/p>\n<\/details>\n\n<details>\n  <summary>Is Microsoft 365 or Google Workspace filtering enough?<\/summary>\n  <p>Both filter well for volume spam and known malware. They are weaker against targeted phishing and business email compromise, which carry no malicious payload. Most organisations add a layer and enforce DMARC.<\/p>\n<\/details>\n\n<details>\n  <summary>Why is DMARC at &#8220;none&#8221; a problem?<\/summary>\n  <p>A policy of none means receiving servers report failures but deliver the message anyway. Impersonation still lands. Protection begins only when the policy is moved to quarantine or reject.<\/p>\n<\/details>\n\n<details>\n  <summary>Do frameworks require email security?<\/summary>\n  <p>ISO 27001:2022 covers malware protection in Annex A 8.7 and awareness training in A 6.3. SOC 2 auditors look for <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-evidence-collection\/\" target=\"_blank\" rel=\"noopener\">threat protection and training records<\/a>. Security questionnaires ask about phishing controls and DMARC enforcement directly.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> MFA &middot; DLP &middot; SIEM &middot; MDM &middot; Phishing &middot; Security Awareness Training<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Email security is the set of controls that stop phishing, impersonation and malicious attachments from reaching your team, and stop\u2026<\/p>\n","protected":false},"author":8,"featured_media":680,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[258,260,261,259],"class_list":["post-679","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-business-email-compromise","tag-email-security","tag-phishing-protection","tag-what-is-email-security"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/679","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=679"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/679\/revisions"}],"predecessor-version":[{"id":681,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/679\/revisions\/681"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/680"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}