It addresses threats including impersonation, account takeover, malicious content, unwanted mail, interception, data leakage, fraud, and disruption.
No single gateway or protocol secures the entire channel. A sound design combines sending-domain authentication, transport protection, account security, content analysis, endpoint safeguards, data controls, resilient administration, user reporting, and incident response. High-risk business actions such as payment changes need controls outside email itself.
Key points
Domain authenticationSPF and DKIM authenticate particular domain-level identifiers; DMARC checks their alignment with the visible From domain and publishes a handling preference for failures.
Account protectionPhishing-resistant MFA, conditional access, secure recovery, and monitoring reduce account takeover risk.
Message protectionFiltering, attachment and link analysis, encryption where required, and data-loss controls address content and handling.
Operational protectionLogging, mailbox-rule monitoring, administrative separation, backups or retention, reporting, and response support investigation.
Important limitationA message from a legitimate but compromised account may pass technical authentication and still be malicious.