Ask most people what their email filter does and they will say it blocks junk. That was the problem worth solving in 2010, and it is largely solved. The messages that cost businesses money now are not junk. They are short, plausible, and often contain no attachment, no link, and nothing a traditional filter would object to.
The message that gets through
Consider an email from a supplier you have worked with for years. Same signature, same tone, replying inside an existing thread. It says their bank has changed and asks you to update the details before the next payment.
There is no malware to detect. The grammar is fine. The account may genuinely belong to your supplier, because they were compromised first. Everything a spam filter examines looks correct, and your finance team has no reason to hesitate.
That is the modern attack, and it is why email security has had to change from filtering junk to judging intent.
What good protection is doing now
Checking whether the sender is who they claim. Authentication records — SPF, DKIM and DMARC — are how a receiving system proves a message really came from the domain it claims. Configured properly, they stop your own domain being spoofed and flag inbound mail that fails the test. Most small businesses have these records partly set up and never finished, which is worth checking.
Noticing lookalike domains. A single character changed in a supplier’s domain is invisible in a hurried read and obvious to a system comparing against domains you actually correspond with.
Learning normal. If your director has never emailed from a phone in another country at 4am, and never asks for gift cards, that is a pattern — and a departure from it is worth flagging even when the message itself is clean.
Examining links when they are clicked. Attackers routinely send a harmless link and arm the page hours later, after delivery checks have passed. Inspecting at click time closes that trick.
Opening attachments somewhere safe first. Documents get detonated in isolation so a macro runs in a sandbox rather than on a machine in your office.
Watching outbound as well as inbound. Rules that hold or encrypt messages carrying card numbers, health records, or client files turn a moment of haste into a prompt rather than a disclosure.
Technology does not finish the job
Every layer above reduces what reaches your team. None of it makes the decision when a plausible payment request lands anyway. That decision is made by a person, which is why the businesses that avoid invoice fraud are usually the ones with a rule everyone knows: bank details are never changed on the basis of an email, full stop, and verification happens by phone to a number you already had.
The technology and the habit protect different halves of the same problem. Shring Secure Mail handles the first half, and our awareness training handles the second.
If you are not certain what your current filtering actually inspects — or whether your authentication records were ever finished — ask us to check. It takes very little time and the answer is usually informative.