TLDR: Email security is practices, protocols, and technologies that protect email from phishing, impersonation, and data loss. It covers five layers across inbound filtering and encryption to sender authentication. The authentication layer stops impersonation because it’s the only one that checks the sender instead of the content.
When email was initially built, the founders likely didn’t imagine that the channel would one day be the most prominent attacking tool for hackers and spammers.
Email security today is retrofitting those protections to keep your messages secure and trustworthy. That’s easier said than done, though.
That’s why email security covers such a broad spectrum for a single communication channel. Filters, gateways, encryption, authentication protocols—all of it patches a system that was never designed to verify anyone.
We keep it simple here. We cover the email threats you’re up against, the defensive layers you need, and the protocols that keep you (and your customers) protected.
What is email security?
Email security is the collection of practices, protocols, and technologies that protect email accounts, messages, and infrastructure from unauthorized access, loss, and compromise.
This typically breaks down into two categories:
- Inbound protection keeps dangerous messages away from your people. Phishing, malware, malicious links, spam.
- Outbound protection keeps attackers from impersonating you with email. Domain spoofing, brand impersonation, data leaving (when it shouldn’t).
Most organizations overinvest in inbound protection but completely forget outbound. They focus on making the inbox impenetrable but leave the domain door wide open —and the attack that causes damage never needs to hit their inbox at all. It hits a customer from a domain that looks exactly like theirs.
Your business needs inbound and outbound protection. That usually involves different tools, though.
6+ email threats your security needs to stop
Email is the entry point for most cyberattacks. We can’t cover every perceivable way attackers might try to compromise your business, but here are a few of the most common threats:
- Phishing. Fake messages designed to steal credentials, money, or access. This includes spear phishing (aimed at specific people), clone phishing (copies a real message), and quishing (hides the payload in a QR code).
- Business email compromise. An attacker impersonates an executive or vendor to authorize a fraudulent payment. BEC doesn’t usually use malware or malicious links, and that’s how it slips past inbound protection tools.
- Domain spoofing and impersonation. Attackers send mail using your domain or register a lookalike domain. Your customers can’t tell the difference (and neither can most filters).
- Account takeover. An attacker gets control of a real mailbox. Everything they send is technically legit but nearly impossible to detect.
- Malware and ransomware delivery. Malicious attachments and links that install software on the endpoint. It’s oldschool for attackers, but it still works, so they keep doing it. Fortunately, it’s the threat that traditional filtering handles best.
- Data loss. Sensitive information leaves the organization. This could be someone sending it deliberately or making an innocent mistake.
Most threats to your business aren’t using some advanced technology. They’re simply using age-old manipulation. Yes, even AI is just using smart sequence prediction to deceive you. However, traditional inbound protection isn’t designed to double-check if your CEO is compromised or just having an off day.
That’s why tools built to scan your email content miss the bulk of these threats.
The layers of email security
Email security is broad. It covers a range of problems, solutions, and products. The table below groups them in layers that’s easier to digest:
| Layer | Stops | Direction | Solutions |
| Secure email gateway | Malware, malicious links, spam | Inbound | Proofpoint, Mimecast, Cisco, Barracuda |
| API-based filtering (ICES) | BEC, social engineering, anomalies | Inbound | Abnormal, IRONSCALES, Sublime |
| Email authentication | Domain spoofing, exact-domain impersonation | Outbound | Valimail |
| Encryption and DLP | Interception, accidental data exposure | Outbound | Microsoft Purview, Zix, Virtru |
| Security awareness training | Human error and manipulation | The user | KnowBe4, Hoxhunt |
Each layer exists to fill a gap that others might have missed. A gateway can’t stop someone spoofing your domain since that message never touches your infrastructure. And authentication can’t tell you if an inbound attachment is dangerous.
Neither replaces the other, and any vendor that claims to be the end-all-be-all email security solution introduces a false sense of security. You don’t want a jack of all trades here—you want the best-of-the-best platforms to protect your business in very specific ways.
Email security protocols that validate who sent an email
Chasing content verification is a never-ending game. The content keeps getting better, and you can’t rely on typos as giveaways anymore. No, you need to verify the sender at the source, and that’s not something you can fake your way through. Not when you’ve got these email security protocols in place, at least.
1. SPF: List of senders
Sender Policy Framework (SPF) publishes a list of IP addresses authorized to send mail for your domain. A receiving server checks the sending IP against that list.
If it’s on the list, it passes. If not, it fails. Simple as that.
SPF’s limitation is that it validates the envelope sender, but that doesn’t check the “From” address your recipient sees. It also breaks when mail is forwarded since the forwarding server’s IP won’t be on your list.
2. DKIM: Tamper-proof messages
DomainKeys Identified Mail (DKIM) attaches a cryptographic signature to outgoing messages. The receiving server retrieves your public key from DNS and verifies the signature to confirm (1) your domain signed the message and (2) nobody altered it in transit.
DKIM survives forwarding, which makes it more reliable than SPF in real-world mail flow. However, it’s better to have them both in place.
3. DMARC: Take action
SPF and DKIM each verify something, but neither connects that verification to the address your recipient reads.
DMARC does, though.
It requires that SPF or DKIM (not necessarily both) pass and align with the visible “From” domain. Then, it tells receiving servers what to do when that check fails:
- Nothing (p=none)
- Quarantine (p=quarantine)
- Reject outright (p=reject)
p=reject stops exact-domain impersonation. At p=reject, a message claiming to be from your domain has to prove it. No proof, no inbox. You don’t even make it to the spam folder.
DMARC also sends you reports on who’s sending mail as your domain. This is how you find services (legit or not) claiming to be your brand.
4. BIMI: Logos in the inbox
Brand Indicators for Message Identification (BIMI) shows your verified logo next to your emails in supporting inboxes. First, you’ll need DMARC at enforcement. That’s what makes BIMI a trust signal for recipients. It’s also a very good reason to get your authentication homework finished.
7 high-priority email security best practices
You could probably find 20+ email security action items to start ticking off. Yes, they exist, but let’s start with the most high-priority email security best practices. These do most of the heavy lifting, and they’re non-negotiable for any brand that’s serious about security:
- Get DMARC to enforcement. Valimail’s 2026 State of DMARC Report shows that 78% of domains have a DMARC record, but only 42% reached enforcement. A DMARC record without enforcement provides no protection.
- Deploy phishing-resistant MFA. FIDO2 keys and passkeys defeat credential phishing and adversary-in-the-middle attacks.
- Meet the sender requirements. Google, Yahoo, and Microsoft require authentication, low spam rates, and one-click unsubscribe from bulk senders. Google’s sender guidelines spell out the specifics.
- Layer inbound filtering with outbound authentication. They cover different threats. Running one without the other creates a gap.
- Watch for lookalike domains. Authentication protects your domain, but it can’t stop someone registering a similar one. Monitoring covers what your protocols can’t.
- Train for behavior. AI-generated phishing uses good grammar and scary-accurate details. Teach your people to verify unusual requests instead of spotting typos.
- Rotate DKIM keys on a schedule. Every six to twelve months, use a new selector.
Start by finding out who’s sending as you
Most organizations underestimate how many services send email using their domain:
- Marketing platforms
- CRMs
- Ticketing systems
- Billing tools
- HR platforms
And the list goes on and on.
You can’t protect a sending ecosystem you don’t know inside and out. Start there, then work outward.
Valimail Monitor is free and identifies every service sending as your domain by name rather than IP address. Check your domain to see where your authentication stands today.
Frequently asked questions
What are the main types of email security?
Email security covers secure email gateways, API-based platforms, email authentication protocols, encryption and data loss prevention, and security awareness training.
What are the email security protocols?
The primary protocols are SPF (lists authorized sending IPs), DKIM (cryptographically signs messages), DMARC (requires SPF or DKIM to align with the visible “From” domain), and BIMI (displays a verified logo on authenticated mail). MTA-STS and TLS-RPT add encrypted transport between mail servers.
How do I make my email more secure?
Start with authentication: configure SPF and DKIM, then publish a DMARC record and work toward p=reject. Add phishing-resistant MFA on all accounts, layer inbound filtering appropriate to your risk, and monitor for lookalike domains.