Email security and phishing

Is email filtering in place for inbound mail?

Almost every organisation answers yes, and the useful part of the answer is whether the policies were configured or merely inherited.

Verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether inbound mail passes through spam and malware filtering before it reaches users. It is the baseline question in the email block, and the more specific questions about detonation and authentication build on it.

Why it is underwritten

Filtering removes the volume, which is what makes the remaining, targeted messages noticeable. Carriers ask because a no here is disqualifying and because the follow-up detail distinguishes a tuned deployment from an untouched default.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Filtering configuration is directly readable in Microsoft 365, including whether policies were customised or left at their defaults.

PlatformWhere the setting livesWhat has to be true
Microsoft 365Anti-spam policy configuration and its actionsCustom policy with thresholds and actions chosen deliberately, rather than the default policy alone
Microsoft 365Anti-malware policy and the common attachment filterExecutable and script attachment types blocked at the gateway
Microsoft 365Quarantine policies and release permissionsUsers cannot release malware from quarantine themselves, and quarantined items are reviewed
Microsoft 365Outbound spam policy and admin notificationOutbound limits and alerting configured, which is how a compromised mailbox is detected early
Microsoft 365Allow-lists in transport rules and anti-spam policiesSender and domain allow-lists reviewed, since a broad allow entry bypasses filtering entirely for that sender
Allow-lists are filtering bypasses

A domain added to an allow-list to fix a false positive years ago will deliver anything sent from a spoofed address in that domain, filtering skipped. These entries accumulate, nobody removes them, and they are the most common self-inflicted gap in an otherwise well-configured mail estate.

What a defensible yes requires

  • Anti-spam and anti-malware policies are configured rather than inherited defaults.
  • Dangerous attachment types are blocked by the common attachment filter.
  • Quarantine release permissions prevent users from releasing malicious content.
  • Outbound spam limits and notifications exist, so a compromised mailbox surfaces quickly.
  • Allow-lists are inventoried and reviewed rather than accumulated indefinitely.

How this answer goes wrong

The default policies are in place and untouched, and a set of allow-list entries added over several years bypasses them for the senders most likely to be impersonated. The answer is yes and the effective coverage is partial in exactly the places that matter.

Frequently asked

Is the built-in filtering enough for this question?

For this specific question, generally yes, provided policies are configured and allow-lists are controlled. The detonation question is where the plan level starts to matter.

Should users be able to release quarantine items?

For spam, reasonably. For malware and high-confidence phishing, no. Those releases should require an administrator.

Why does outbound filtering matter here?

Because outbound volume limits and alerts are usually the first indication that a mailbox has been compromised and is sending on the attacker's behalf.

How do we audit allow-lists?

Export transport rules and anti-spam allow entries, and review each with the person who requested it. Most will have no current justification.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture