Improve Office 365 phishing protection with practical steps for today's modern threats. Learn when native controls are enough and when to add protection.
Office 365 phishing protection: what security teams need to know
- Microsoft 365 has anti-phishing controls built in, but configuration gaps and evolving attack techniques leave real blind spots in most environments.
- Hardening native settings closes the most common phishing gaps, but QR code phishing and business email compromise (BEC) often require additional detection layers.
- API-based email security adds org-specific detection for threats that bypass native controls, without replacing Microsoft protections or changing your MX record.
Microsoft detected roughly 8.3 billion phishing threats in Q1 2026 alone. During the same period, QR code phishing more than doubled. The challenge for Microsoft 365 security teams is two-sided. Many environments still have configuration gaps that make inboxes easier to reach than they should be. And even well-configured environments face attack techniques designed specifically to pass standard filters.
This guide covers practical ways to address both sides, from the native Microsoft 365 settings most environments under-configure to phishing protection software that layers on top without replacing your existing Microsoft controls. For more on how the two work together, see the Microsoft 365 email security overview.
Why phishing emails still get through Office 365
Phishing reaches Microsoft 365 inboxes for two distinct reasons: configuration gaps and evasion techniques. Distinguishing between them matters because they call for different responses.
Configuration gaps account for a large share of what reaches inboxes. Missing email authentication records, anti-phishing policies left at default settings, and Safe Links or Safe Attachments applied to only part of the tenant are all common. These gaps are addressable without additional tooling.
Evasion techniques are harder. Attackers have adapted to signature-based filtering, and several of the most active current techniques are built around passing standard controls:
QR code phishing (quishing): A QR code image replaces the malicious URL, bypassing link-scanning controls. A message containing a QR code is 1.4x more likely to be an attack, and per the 2026 Sublime Email Threat Research Report (ETR) QR code attacks grew 282.7% from H1 to H2 2025. Standard link filters don't decode image content.
Living off trusted services (LOTS): Attackers deliver phishing through legitimate platforms like Google Docs, Microsoft SharePoint, and Dropbox, where URL reputation filters won't flag the legitimate sender domain. ETR data shows 12% of all email attacks in 2025 abused trusted sites, with 32.8% of LOTS attacks using uncommon or emerging platforms. Many of these campaigns end on credential phishing pages hosted on infrastructure that blocklists don't touch.
Targeted personalization: Signature-based controls and centralized detection models struggle with highly targeted messages. ETR research shows 90% of malicious emails are customized to each targeted organization, meaning generic detection logic built for broad threat populations misses a substantial share of targeted attacks.
AI-generated content: The share of attacks bearing signals of AI-generated content rose from 4.2% in Q1 2025 to 19.3% in Q4 2025, a roughly fivefold increase (ETR). These messages are more convincing and carry fewer of the signals legacy filters are tuned to catch.
Configuration gaps are addressable through tighter native settings. Evasion techniques require detection that goes beyond what standard filter configurations provide. The seven recommendations that follow reflect both.
7 ways to improve Office 365 phishing protection
1. Tighten anti-phishing policy settings in Microsoft Defender
The anti-phishing policies in both Exchange Online Protection (EOP) and Microsoft Defender for Office 365 ship with defaults that leave protection below what most environments need. Reviewing and hardening these settings is where most environments find the biggest initial gains. Defender applies the same centralized detection logic across all Microsoft 365 customers. It doesn't learn your organization's specific sender relationships or communication patterns, which is why targeted attacks can still get through even when every setting below is configured correctly.
Impersonation protection: Enable sender and domain impersonation protection in Defender for Office 365 (Plan 1 or Plan 2). Add executives, finance team members, and key external partners to the protected users list. This catches lookalike domain attacks and display-name spoofing that authentication controls don't stop.
Mailbox intelligence: Enable mailbox intelligence-based impersonation protection. It trains on each user's send and receive history to flag messages from senders who don't fit established patterns, adding a behavioral signal on top of policy-based detection.
Spoof intelligence: Review the spoof intelligence insight in the Microsoft Defender portal and align your allow/block list with your actual legitimate senders. Misconfigured spoof settings drive both missed attacks and blocked legitimate mail.
First contact safety tips: Enable safety tips to surface a visible warning when users receive email from a sender they haven't corresponded with before.
Quarantine over junk: Set the action for detected impersonation and spoof to "Quarantine message" rather than "Move to Junk." Messages in Junk are too easy to overlook and act on.
None of the settings above address what happens after a credential phishing attempt succeeds and a user's password is stolen. Phishing-resistant MFA (FIDO2 security keys, passkeys, or certificate-based authentication) limits the damage: even with valid credentials, an attacker can't authenticate without the second factor. Standard push-based MFA provides meaningful protection against most attacks but is vulnerable to adversary-in-the-middle (AiTM) techniques, where attackers proxy the login session in real time and steal the authenticated session cookie. Phishing-resistant methods close that gap. For the highest-risk users (finance, HR, executives), phishing-resistant MFA is worth prioritizing before any other setting on this list.
2. Enforce email authentication on every sending domain
SPF, DKIM, and DMARC work together to verify that messages claiming to come from your domain were actually sent by servers you've authorized. Without enforcement, anyone can spoof your domain and pass basic authentication checks.
SPF (Sender Policy Framework) defines which servers are permitted to send email on behalf of your domain. DKIM (DomainKeys Identified Mail) signs outbound messages with a cryptographic key so recipients can verify the message wasn't altered in transit. DMARC (Domain-based Message Authentication, Reporting, and Conformance) ties SPF and DKIM together under a single policy that applies to the visible From: address. It tells receiving servers what to do when a message fails authentication: monitor it (p=none), quarantine it, or reject it. It also enables aggregate and forensic reporting, so you can see which senders are authenticating correctly and catch spoofing attempts before they reach users.
The step most organizations skip is moving DMARC from monitoring (p=none) to enforcement (p=quarantine or p=reject). A p=none policy generates reports but lets spoofed messages through. Only p=quarantine or p=reject stops them.
Audit all sending domains, including parked domains that don't actively send email. Parked domains are a frequent target precisely because they're unprotected.
Authentication records close the spoofing door on your domain. They don't stop lookalike domain attacks, where an attacker registers billing-contoso[.]com instead of spoofing contoso[.]com directly. Catching that requires the impersonation controls in Step 1.
3. Enable Safe Links and Safe Attachments
Safe Links rewrites URLs at delivery and scans them again at click time, so a link that appeared clean when the message arrived can still be blocked if it's weaponized later. Safe Attachments detonates attachments in a sandbox before delivering them to users.
Safe Links covers URLs in message text. It doesn't parse image content, which is why QR code phishing bypasses it regardless of license tier.
Both features require Defender for Office 365 Plan 1 or Plan 2, or an M365 Business Premium, E3 with Defender add-on, or E5 license.
One of the most common gaps: applying Safe Links and Safe Attachments to specific user groups rather than the full tenant. Attackers probe for unprotected accounts and domains, so partial coverage creates exploitable blind spots.
In Safe Links policies, enable real-time URL scanning and set the policy to prevent users from clicking through to the original URL. Letting users override the scan on unfamiliar links defeats much of the protection.
4. Run attack simulation training
Phishing doesn't stop at the inbox. Users who act on messages that reach them are the final layer of defense, and training them is a repeatable part of a phishing protection program.
Microsoft Attack Simulator, included in Defender for Office 365 Plan 2 and some M365 E5 licenses, sends simulated phishing messages to your users and delivers targeted training to those who interact with them. A single campaign tells you where you stand. Repeated campaigns across the same user population show whether your training is working. The most useful metric isn't the click rate on any one simulation; it's the trend across campaigns over time.
Simulation outcomes depend partly on how much real phishing users encounter between campaigns. Teams flooded with genuine threats become desensitized before the training has a chance to land. Reducing what reaches the inbox makes the training investment go further.
Sublime includes phishing simulation and training as part of the platform, so security teams can run campaigns and manage user education alongside detection and response without switching tools.
5. Automate abuse mailbox triage
User-reported phishing is one of the strongest threat signals available to a security team. When a user flags a suspicious message, it's often a real attack, and investigating it quickly affects how far the threat spreads.
Most Microsoft 365 environments handle these reports manually: an analyst checks the message, searches for other instances across the environment, and decides whether to remediate. At volume, this process creates a backlog that grows faster than teams can clear it.
Microsoft's native mechanism for post-delivery removal is Zero-hour Auto Purge (ZAP). ZAP retroactively removes messages from inboxes after Microsoft identifies them as malicious, including messages delivered before a spam or malware verdict was issued. It's worth enabling and is on by default for Exchange Online mailboxes, but it only acts on messages Microsoft has already classified. It doesn't triage user-reported submissions, correlate reports across the tenant, or act on threats that haven't yet reached a Microsoft verdict.
Automating abuse mailbox triage, from classification to investigation to remediation, turns a slow, manual workflow into a near-instant one. Sublime's abuse mailbox automation handles this end to end: user-reported emails are auto-classified, correlated across the environment, and remediated without analyst involvement.
6. Add computer vision to catch QR code phishing
Standard URL-scanning controls inspect links in email text. They can't read content embedded inside an image. QR code phishing works because the malicious URL is hidden in a graphic the filter doesn't parse.
Computer vision-based detection decodes QR codes in email images, extracts the embedded URL, and runs it through threat analysis. It's the same workflow Safe Links applies to text links, applied to image content. This closes a gap that exists in most Microsoft 365 environments regardless of plan or license tier.
Attachment-based QR attacks grew 314.5% from H1 to H2 2025 (ETR). Environments without computer vision-based detection are carrying a coverage gap that's actively being exploited.
Sublime applies computer vision natively to every inbound message. QR codes in images and attachments are decoded, the embedded URL is extracted, and it's run through the same threat analysis applied to text links, with no additional configuration required. This is one of the most common gaps Sublime closes in Microsoft 365 environments from day one.
7. Layer in detection for BEC and credential phishing
Business email compromise (BEC) and credential phishing are among the highest-cost attack types in most organizations, and both are built to pass standard signature-based filtering.
BEC attacks rarely carry malicious links or attachments. They impersonate executives or vendors to request fund transfers, invoice changes, or sensitive information. ETR research shows BEC and fraud accounted for nearly one in three confirmed email threats in 2025, with thread hijacking as the leading technique.
Credential phishing increasingly routes through legitimate services: a Google Drive link that leads to a spoofed login form, a SharePoint URL hosting a credential-harvesting page. URL reputation filters don't flag the link because the sending domain is legitimate.
Detecting these attacks requires analyzing message content, sender behavior, and contextual signals that go beyond what signature-based filters evaluate. Sublime builds detection logic specific to your environment, calibrated to your organization's vendors, communication patterns, and behavioral baselines, so targeted attacks that pass centralized detection models get caught. Elastic detected 20x more email attacks after layering Sublime on top of their existing Microsoft controls. The coverage gap between what Defender catches and what Sublime catches is widest precisely on BEC and credential phishing: the two attack types this step is designed to address.
When to use native vs. layered phishing protection for Microsoft 365
Native Microsoft 365 controls, properly configured, are the right starting point for any environment. For some organizations, they're sufficient. For others, the threats coming in exceed what native configuration addresses.
The table below covers the four most common deployment approaches and when each makes sense.
For most Microsoft 365 teams, the practical path is to harden native controls first, then evaluate an API-based solution for the detection and response gaps that remain. The best email security for Office 365 guide walks through how to compare third-party options in more detail.
Strengthen Office 365 phishing protection with Sublime
Sublime layers on top of Microsoft 365 to close the detection, investigation, and response gaps that native controls leave open, without replacing your existing Microsoft protections.
Sublime's Microsoft 365 email security integration connects via API with no MX record change and no routing disruption. From day one, Sublime applies detection logic tailored to your environment alongside Microsoft Defender and continuously builds new detections as the threat landscape shifts.
Org-specific detection: Where Defender applies centralized detection models across all customers, Sublime builds coverage specific to your environment. ADÉ (Autonomous Detection Engineer) generates and deploys new detections in hours, not vendor release cycles, closing gaps before the next wave of an attack hits.
Computer vision for QR code phishing: Sublime decodes QR codes embedded in email images and attachments, extracts the URL, and runs it through threat analysis. No additional configuration required.
BEC and impersonation detection: Sublime analyzes sender behavior, message content, and communication patterns to flag business email compromise and executive impersonation attempts, including thread hijacking and lookalike domain attacks that pass authentication checks.
Automated abuse mailbox management: ASA (Autonomous Security Analyst) triages user-reported messages in seconds, correlates them across the environment, and remediates confirmed threats without analyst involvement.
Transparent detection logic: Every Sublime verdict traces to the specific signals that triggered it. Analysts see exactly why a message was flagged, so investigation is fast and tuning is direct.
FAQs about improving Office 365 phishing protection
What are the best anti-phishing settings for Office 365?
The highest-impact settings in Microsoft Defender are impersonation protection for key users and domains, mailbox intelligence, spoof intelligence, and Safe Links with real-time URL scanning. The defaults for all of these are not optimized for most environments.
Enable first-contact safety tips and set quarantine (not junk) as the action for detected threats. Pair these with a DMARC enforcement policy (p=reject) on all sending domains. Together, these changes close the most common configuration gaps without requiring additional tooling.
How do email authentication protocols help prevent phishing in Office 365?
SPF, DKIM, and DMARC work together to verify that messages claiming to come from your domain were actually authorized by you. SPF defines which servers send on your behalf. DKIM signs messages so recipients can verify they haven't been altered in transit. DMARC tells receiving servers whether to monitor, quarantine, or reject messages that fail authentication.
The critical step most organizations skip is moving DMARC from p=none to p=quarantine or p=reject. Without enforcement, spoofed messages still reach inboxes even when SPF and DKIM records are in place.
How can you reduce false positives without weakening Office 365 phishing protection?
Most false positives in Microsoft 365 trace to overly broad rules or missing exceptions for legitimate senders. Reviewing the spoof intelligence allow list regularly and ensuring third-party senders authenticate properly with DKIM and DMARC removes a large share of false positives without touching detection sensitivity.
When adding layered protection, look for solutions with transparent detection logic and direct tuning capabilities. If an analyst can see exactly why a message was flagged and adjust the detection without filing a vendor support ticket, false positive rates stay manageable as the environment evolves.
Do you need an API-based solution, a SEG, or both for Office 365 phishing protection?
That depends on your threat profile and operational requirements.
An API-based solution adds detection and response capabilities without changing mail flow, making it the lower-friction path for most Microsoft 365 teams that have hardened native controls but are still seeing bypasses or need faster automated triage.
A secure email gateway adds inline inspection with URL rewriting and attachment sandboxing but requires an MX record change and introduces routing complexity. Some regulated industries require gateway-based inspection for compliance.
Running both provides the highest coverage ceiling but also the highest operational overhead. Start by identifying your remaining gaps after hardening native controls, then evaluate which layer addresses them.
When should you add Sublime to your Microsoft 365 environment?
The right time to evaluate Sublime is when native controls are hardened but phishing is still getting through, when your abuse mailbox backlog is growing faster than your team clears it, or when you need detection for QR code phishing, BEC, or credential phishing via trusted infrastructure.
Sublime deploys via API with no MX record change. It works alongside Microsoft Defender, so existing workflows aren't disrupted during or after rollout.
How does Sublime improve phishing protection for Office 365?
Sublime connects to Microsoft 365 via API and adds detection, investigation, and response capabilities that native controls don't provide. ADÉ (Autonomous Detection Engineer) generates org-specific detection coverage from day one and deploys new detections as attack patterns shift, without waiting on a vendor release cycle. ASA (Autonomous Security Analyst) triages user-reported messages in seconds and auto-remediates confirmed threats at scale. Computer vision decodes QR codes that Safe Links can't parse, and every verdict traces to the specific detection that fired, so analysts understand exactly why a message was flagged.
Get the latest
Sublime releases, detections, blogs, events, and more directly to your inbox.
.png)


