Most managed email security providers build their service around a common set of capabilities. Here's what's typically included:
Email authentication and protection
Providers configure and monitor inbound authentication protocols like SPF, DKIM, and DMARC, which verify that an email actually came from the domain it claims to be from. This is the foundation that makes it possible to catch spoofed and impersonated senders before a user ever sees the message.
Inbound filtering
Inbound filters scan every incoming message for spam, malware, and phishing indicators before it reaches an inbox. Modern filtering combines reputation-based checks (sender IP and domain history) with machine learning models that catch attacks a static rule set would miss.
Outbound filtering
Outbound filtering scans emails leaving your organization for malware, sensitive data, or signs that an internal account has already been compromised and is being used to send phishing emails to others, otherwise known as account takeover.
Advanced threat protection (ATP)
ATP goes beyond basic filtering to catch sophisticated attacks: sandboxing suspicious attachments, checking links at the moment they're clicked (not just when the email arrives), and using behavioral analysis to flag messages that look unusual for a given sender or user.
Business email compromise and account takeover detection
This is where analyst-led investigation and response add value. BEC attacks often don't contain malware or malicious links at all; they're just a convincingly worded request from a "trusted" sender. Detecting this requires monitoring for anomalous account behavior, unusual sign-in patterns, and impersonation attempts, not just scanning message content.
Data loss prevention (DLP)
DLP tools monitor outbound and internal email traffic for sensitive data such as financial records, health information, and credentials. They block or flag messages that violate policy, whether that's driven by regulatory compliance requirements (e.g., HIPAA, PCI-DSS, GDPR) or internal data governance.
Email encryption
Encryption can protect message content in transit and, depending on the implementation, at rest. It helps prevent unauthorized parties from reading intercepted content, but protection depends on the encryption method, key management, endpoint security, and how the recipient accesses the message.
Compliance monitoring and reporting
For regulated industries, managed providers help maintain audit trails, retention policies, and documentation needed to demonstrate compliance plus regular reporting so your leadership team has visibility into what's actually happening in your email environment.