Home/Questions/Email security and phishing/Which email security product
Email security and phishing

Which inbound email security product / Secure Email Gateway (SEG) does the Applicant use?

As with the endpoint question, the vendor name is a shortcut the underwriter uses to infer capability. Name the tier or the shortcut works against you.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier wants the product that filters your inbound mail, and increasingly the plan level. Where the answer is Microsoft, the difference between the included protection and the advanced plan is exactly the difference between the two previous questions on the form.

Why it is underwritten

Underwriters cannot inspect your mail flow, so they use the product name to estimate detection quality and the tier to determine whether detonation and time-of-click protection are present at all. A bare vendor name invites a conservative assumption.

Where the answer lives in Microsoft 365, Entra ID, and Azure

The tenant shows which Microsoft plan is licensed and onboarded, and whether a third-party gateway sits in the mail path.

PlatformWhere the setting livesWhat has to be true
Microsoft 365Defender for Office 365 plan and its enabled policiesThe specific plan, since the included protection and the advanced plan differ on exactly the capabilities carriers ask about
Microsoft 365Inbound mail flow connectorsWhether a third-party gateway is in front, which determines how the two layers interact
Microsoft 365Enhanced filtering configuration where a gateway is presentConfigured, so Microsoft still evaluates the original sender rather than the gateway
Gateway vendorProduct, tier, and enabled modulesThe gateway configuration. Attested
Managed serviceWho monitors mail security alerts and whenCoverage hours, which strengthens this answer and the monitoring answer elsewhere
Layering is fine, blinding is not

A third-party gateway in front of Microsoft is a common design and works well when enhanced filtering is configured. Without it, every message appears to arrive from the gateway, which degrades Microsoft's spoof and impersonation detection substantially. If you run both, check this setting.

What a defensible yes requires

  • The answer names the product and the plan or tier.
  • Where two layers exist, both are named and the routing is configured so neither is blinded.
  • The named product matches the capabilities claimed in the detonation and link protection answers.
  • Who monitors the alerts is stated.
  • Licensing covers the full mailbox count, consistent with the headcount reported elsewhere.

How this answer goes wrong

The form says a premium product and the tenant is licensed for the base plan, so the detonation answer given two questions earlier is unsupported. Underwriters read these answers together, and internal inconsistency is the most common reason a submission generates additional questions.

Frequently asked

Is Microsoft 365 alone acceptable?

Yes, at the plan level that includes detonation and time-of-click link protection. Name the plan explicitly.

Does a third-party gateway improve our submission?

It is neutral in most markets. What matters is capability and configuration, not the number of layers.

What if we changed product recently?

Say so with the date. A recent migration explains gaps in historical evidence and is better volunteered than discovered.

Do carriers verify this?

Not usually at underwriting. It surfaces during a claim, when the mail path is reconstructed from headers and the actual filtering layer becomes visible.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture