Protecting corporate email from phishing and BEC relies on a combination of technical controls and employee training: filtering alone isn't enough, because targeted emails are often designed specifically to fool a person. Below is a practical checklist for closing the main gaps.
This is a follow-up to the full guide "What Is Mail Security", focused on the most dangerous scenarios — phishing and business email compromise.
How phishing differs from BEC
In short: phishing is usually mass-scale and tries to trick victims into giving up data via a fake page, while BEC is a targeted attack that spoofs a trusted sender — usually without any attachments or links.
- Phishing — an email with a link to a fake site or a malicious attachment.
- BEC — impersonating an executive, a business partner, or a colleague to trigger a wire transfer or a data leak; technically, such an email is often "clean," which makes it more dangerous for signature-based filters.
Technical checklist
Set up baseline authentication and filtering mechanisms — they stop a large share of attacks before they ever reach the user:
- SPF, DKIM, DMARC. Configure all three records and move your DMARC policy to reject forged mail after a monitoring period.
- Attachment filtering. Block dangerous file types, scan archives and macro-enabled documents, ideally in an isolated environment.
- Link inspection. Analyze links, including at click-time, to catch sites that get weaponized after the email has already been delivered.
- Anti-BEC rules. Flag external emails and detect look-alike domains and mismatches between the sender's display name and address.
- Outbound mail protection to reduce the risk of leaks and account compromise.
Organizational checklist
Technical controls need to be backed up by processes and training, because the final call is often made by a person:
- regular employee training on recognizing phishing and BEC;
- a clear channel for forwarding suspicious emails;
- a procedure for confirming payments and changes to payment details through a second channel;
- reviewing incidents and updating rules based on the findings.
How to spot a BEC email
A BEC email usually plays on urgency and trust rather than relying on attachments. Watch for:
- an unexpected request to urgently wire money or change payment details;
- a sender address that looks legitimate but is off by a character or a domain;
- a display name that matches someone you know, while the actual address is external;
- a request to "not call, just confirm everything by email."
The strongest defense against BEC is confirming critical actions through a second, independent channel.
Common mistakes
Protection most often falls short due to incomplete setup and missing processes:
- DMARC is left in monitoring mode and never moved to reject;
- attachments are checked but not links (or the other way around);
- there's no anti-BEC logic designed for emails without attachments;
- employees don't know where to report suspicious emails;
- settings are configured once and never revisited after incidents.
Practice hands-on
It's easier to apply these measures on lab environments. In the BI.ZONE Mail Security courses, you configure filtering policies and work through detections and phishing/BEC protection scenarios on isolated infrastructure. Product capabilities are covered on the BI.ZONE Mail Security page; a general overview of the category is in the "What Is Mail Security" guide.