Phishing That Gets Past Microsoft 365, and Why | Tech Fortress
Tech Fortress Book a Call
← All articles
Email Security 5 August 2026 · 6 min read

The phishing emails that get past Microsoft 365, and why

The dangerous emails are not the obvious ones. They are clean, well written, contain no attachment, and ask you to change a bank account.

Email security dashboard showing blocked phishing and impersonation attempts

Microsoft 365's built-in filtering is decent. It blocks enormous volumes of spam and known malware, and for that alone it earns its place. The problem is what it was designed for. Volume-based, signature-based filtering catches attacks that look like attacks.

The ones that cost businesses real money don't look like attacks at all.

Business email compromise: no malware required

A typical BEC attack contains no attachment, no malicious link, and nothing a scanner would flag. It is a well-written email, apparently from your managing director or a supplier you deal with monthly, asking for a payment to be processed or bank details to be updated.

There is nothing technically wrong with the message. That is the entire point. Filtering built to detect malicious content finds none, because there isn't any. The attack is social, and it works because it is plausible and it arrives when someone is busy.

Lookalike domains and display-name tricks

Two techniques do most of the heavy lifting here. The first is a domain that reads correctly at a glance — an rn where an m should be, a .co instead of .com, an extra hyphen nobody notices. The second is simpler still: set the display name to a colleague's name and send from anywhere. On a phone, most mail clients show the display name and hide the address entirely.

Nobody reads email addresses carefully on a phone between meetings. Attackers know precisely when to send.

Links that were clean when they were scanned

Filters check links on delivery. An attacker can send a link to a page that is entirely harmless at that moment, wait, then swap the page for a credential-harvesting login form an hour later. The email passed inspection. The link the user clicks is not the link that was scanned.

This is why time-of-click protection matters. Checking once at delivery is checking at the one moment the attacker controls.

What actually closes the gap

Layered email security adds the checks that volume filtering skips. Impersonation detection that knows who your executives and suppliers are, and flags messages pretending to be them. URL rewriting so links are checked when clicked rather than only when delivered. Attachment sandboxing that opens files in isolation to watch what they do. Outbound scanning so a compromised account can't quietly use your domain to attack your customers.

None of this replaces Microsoft 365. It sits in front of it and handles the categories Microsoft's filter was never built to handle.

And train people, but train them on the right thing

Awareness training helps, but only if it reflects reality. Teaching staff to spot bad spelling and dodgy attachments prepares them for attacks that mostly no longer happen. The useful training is procedural: any request to change bank details gets verified on a phone number you already had, never one supplied in the email. Urgency in a payment request is itself the warning sign.

Technology stops the message. Process stops the payment. You want both.

Want to see what's reaching your inboxes?

We'll assess your current email security and show you what's slipping through.

Book a Call

Related services

Email Security Security Awareness Training MDR