Most Breaches Start in the Inbox
Layered filtering, DMARC enforcement, and continuous phishing practice — so the message that gets through is the one that should, and nobody can send email pretending to be you.
45 min · Free · No commitment
Your spam filter is not an email security program
The obvious spam gets caught. That was never the problem. The problem is the message that looks exactly like an invoice from a vendor you genuinely use, arriving in the week you genuinely expected it, from a domain one character off from the real one — asking to update the bank details on file.
Business email compromise does not rely on malware, so tools that scan attachments never see it coming. It relies on a plausible message, a busy person, and a payment process that trusts email. The losses are frequently six figures, and insurers increasingly decline claims where basic email authentication was never configured.
Facet MSP treats email as its own security domain: advanced filtering through Proofpoint and Spambrella, DMARC enforcement and monitoring through Mailhardener so nobody can send mail as you, and ongoing phishing simulation through Phin so your team is practiced rather than merely warned once a year.
Filter, authenticate, and train
Advanced Threat Filtering
Attachment sandboxing, URL rewriting, and impersonation detection that goes well beyond keyword and blocklist filtering. Links are checked at the moment someone clicks them, not only at the moment the message arrived in the mailbox.
DMARC, SPF & DKIM Enforcement
Email authentication configured properly and taken all the way to enforcement, so mail claiming to be from your domain that fails authentication gets rejected outright. Without this, anyone on the internet can send email as your CEO.
Ongoing DMARC Monitoring
Enforcement without monitoring breaks legitimate mail. We watch the reports continuously through Mailhardener, catching the newsletter platform or invoicing tool that needs authorizing before your customers quietly stop receiving anything from you.
Impersonation & Lookalike Domain Detection
Alerts when a domain closely resembling yours gets registered — usually the first observable step in a targeted business email compromise attempt aimed at your finance team or, worse, at your customers.
Phishing Simulation & Training
Realistic simulated phishing through Phin, delivered continuously rather than as an annual compliance exercise, with short training that triggers at the moment someone clicks. Practice is what changes behavior; a video in January does not.
Mailbox Rule Monitoring
One of the first things an attacker does after taking over a mailbox is create a rule that hides their tracks — auto-forwarding, or moving replies straight to a folder nobody opens. We monitor for those rules and flag them immediately.
Payment Process Hardening
Technology alone will not stop a convincing wire fraud request. We help you put an out-of-band verification step into your payment approval process, which is the control that actually works when the message is good enough to fool a careful person.
Fewer things to catch, better odds of catching them
- Nobody can send email that appears to come from your domain
- Malicious links are checked when clicked, not just on arrival
- Your team meets realistic phishing attempts regularly, in a safe context
- Attacker mailbox rules surface immediately instead of hiding for months
- Lookalike domains targeting your customers get spotted early
- Insurance questions about email authentication have real answers
We fix the process, not just the filter
We take DMARC all the way to enforcement.
Plenty of providers publish a DMARC record set to "do nothing" and call it done. That is a checkbox, not a control. We monitor and move you to enforcement without breaking your legitimate mail.
Training is continuous, not annual.
A once-a-year video changes nothing measurable. Short, frequent simulations with in-the-moment coaching are what actually shift click rates, and we report the trend so you can see it moving.
We will tell you your process is the weak point.
If your finance team can change payment details on the strength of an email alone, no filter will save you. We say so plainly, and then we help you fix it.
Email security questions
Microsoft 365 already filters spam. Why add another layer?
Microsoft's built-in filtering is genuinely good at bulk spam and known malware, and we configure it fully as part of your engagement. It is weaker on targeted impersonation and business email compromise — which are precisely the attacks that cost real money. The added layer is aimed squarely at those.
What is DMARC, and why does it keep coming up?
It is the standard that lets receiving mail servers verify a message genuinely came from your domain and reject it if not. Without it in enforcement, anyone can send email appearing to be from your company. Insurers and larger clients increasingly ask whether you have it configured.
Will phishing simulations upset our staff?
They can, if handled badly — as a gotcha with public shaming attached. We run them as practice rather than as a test with consequences. The training that appears after a click takes under two minutes, and what we report to you is an aggregate trend, not a list of names to punish.
Someone already fell for a phishing email. What now?
Call us. The immediate steps are resetting the credential, revoking active sessions, checking for mailbox rules the attacker created, and reviewing everything that account could reach. If you are a client, this is covered — and it is exactly the scenario MDR is watching for.
Can you stop wire fraud?
Not with technology alone, and anyone promising otherwise is selling something. We reduce how many convincing attempts reach your team, and we help you add a verification step outside of email for any payment change. That combination is what actually works.
Ready to take this off your plate? Six questions.
Spend 90 seconds answering. We'll spend a few hours putting together a written assessment of where your IT stands — and a 45-minute call with one of our engineers.