Phishing Protection for Business Email: A Practical Guide
Phishing protection for business email in layers: external tags, link checks at click time, one-click reporting, zero-hour purge and quarantine.
On this page
Phishing protection for business email works in layers. Filters stop most fraud before it lands. Labels warn staff when a message comes from outside the company. Links are checked when someone clicks, not only when the mail arrives. Staff get a one-click way to report a suspicious message. Admins can then remove that message from every mailbox, including after it has already been delivered.
Why phishing still works in 2026
Most attacks on a small or mid-sized company don't start with clever malware. They start with a believable email. "Your mailbox is full, sign in here." "Updated bank details for invoice 4471." "Can you buy some gift cards for a client? I'm in a meeting." The aim is to get one person to type a password or move money.
Spam filters have improved, but phishing is designed to look like normal business mail. The message is short, it often has no attachment, and the link may point to a brand-new site that no blocklist has seen yet. Some of these messages will get through any filter. So a good setup assumes that, and adds checks after delivery as well as before it.
Think about protection at four moments:
- Before delivery: authentication, spam and virus filtering, and detection of impersonation.
- When the message is read: clear warnings in the inbox.
- When someone clicks: a fresh check of the link at the moment it is opened.
- After delivery: reporting, organisation-wide removal and automatic clean-up when new information arrives.
Layer 1: stop spoofing and lookalikes before delivery
Start with your own domain. Publish SPF, DKIM and DMARC records so receiving servers can tell real mail from your company apart from forgeries. If those terms are new to you, read SPF, DKIM and DMARC explained and then how to set a DMARC policy. DMARC protects your domain from being forged. It does nothing about an attacker who registers a domain that only looks like yours.
That is where impersonation and lookalike detection come in. A good system checks inbound mail for:
- Colleague impersonation: the display name says "Anna Tran" (a real colleague), but the address is outside your organisation.
- Protected names: executives, finance staff, or anyone attackers like to pretend to be, including people who sometimes use a personal address.
- Lookalike domains:
congty-vn.cominstead ofcongty.vn,examp1e.cominstead ofexample.com, or homographs, where a Cyrillic letter looks just like a Latin one. - Spoofed domains: the sender claims a domain but fails DMARC, or someone pretends to send from your own domain.
For each type of finding you should be able to choose what happens: warn the reader, move the message to Junk, or hold it in quarantine.
Layer 2: make outside mail obvious
The simplest control is often the one that works best: a visible External tag on every message from outside the organisation. When "the CEO" emails asking for an urgent transfer and the message carries an External tag, most people stop and think.
A notice that says you have never received mail from this sender before adds to this. Real suppliers have a history with you. A fake "supplier" writing from a new address usually doesn't.
Some companies also add a subject prefix such as [EXTERNAL] so the warning shows up in Outlook and on phones. It works, but there is a trade-off. Changing the subject breaks the message's original DKIM signature, so turn it on knowingly rather than by default.
Layer 3: check links when they are clicked
Phishing sites are often set up minutes before a campaign and only reported later. A link that was "clean" when the email arrived at 9:00 may be on a phishing list by 9:40. Click-time link protection checks the link again each time someone opens it:
- Safe: the page opens normally.
- Suspicious: a warning page explains why. For example, the visible text shows one address but the link goes somewhere else, or the link points to a bare IP address.
- Dangerous: the page is on a known phishing or malware list, and a block page stops the visit.
Whether staff may override a block is a policy decision. Allowing it helps with false positives. Logging every override lets admins see who took the risk.
Layer 4: report, purge, and clean up after delivery
When one person spots a phishing email, others in the company have usually received it too. A Report phishing button (separate from "Report spam") should move the message out of the reporter's inbox and alert the admins. An admin then reviews the sender, the SPF/DKIM/DMARC results, the links and the attachments, and decides whether to act.
If it is phishing, the admin should be able to purge it from every mailbox in the organisation in one action. That includes copies sent again with a different message ID, and the sender can be blocked at the same time. Because a purge touches everyone's mail, it should start with a dry-run count ("37 messages in 29 mailboxes") and be reversible if the match was wrong.
Zero-hour auto purge (ZAP) handles the cases nobody reports. If information arrives after delivery that shows a message is dangerous, the message is moved out of the inbox automatically. For example, its link is added to a phishing list, the organisation blocks the sender, or several colleagues report it.
Quarantine is for mail that is almost certainly malicious. It is held on the server rather than delivered to Junk, where a curious user might still open it. Users get a digest and can ask for a message back. An admin approves anything that was classed as phishing.
How the layers compare
| Layer | What it stops | Who acts | Typical setting |
|---|---|---|---|
| SPF, DKIM, DMARC | Forgery of your own domain | DNS admin, once | DMARC moving towards p=reject |
| Impersonation and lookalike detection | Fake executives, fake suppliers | Automatic | Warn first, then Junk or quarantine |
| External tag and first-time notice | Social engineering | The reader | On |
| Click-time link checking | Links that turn bad after delivery | Automatic, then the reader | On, with overrides logged |
| Report phishing and purge | A campaign hitting many staff | Users, then an admin | On |
| ZAP | Threats found after delivery | Automatic | On, 48-hour window |
| Quarantine | High-confidence spam and phishing | Automatic, then an admin | On for high scores |
How Zomail implements these layers
Zomail added these inbound anti-phishing controls in October 2026. Owners and admins manage them from a single anti-phishing policy page, and changes take effect within about a minute:
- External tag is on by default, together with the "you haven't received mail from this sender before" notice. An optional subject prefix (default
[EXTERNAL], up to 20 characters) is added at delivery, so IMAP apps see it too. - Click-time link checking is on by default in webmail and the Zomail app. It uses known phishing and malware lists (OpenPhish, URLhaus, PhishTank, Spamhaus DBL, SURBL) plus checks for suspicious links, and shows warning or block pages. Admins choose whether users may open a blocked link anyway, and every override is logged.
- Report phishing sits in the message's More menu. The admin review page shows the headers, the authentication results and the links as plain text. A purge starts with a dry-run count, can include messages with the same sender and subject from the last few days, can block the sender, and can be restored to each person's original folder.
- ZAP acts on mail delivered in the last 48 hours. It moves the message to Junk, or to quarantine if that is enabled. It leaves alone any message a user has explicitly marked "Not spam".
- Quarantine holds mail on the server for 30 days by default and sends a daily digest. Users can release spam themselves and request release of phishing. The spam score threshold can be adjusted.
- Impersonation and lookalike detection works with protected names (matched without regard to accents or case) and protected domains for partners and banks. You choose Standard or Strict, and an action for each finding: warn, Junk or quarantine. Organisation-wide allow and block lists complete the set.
These controls sit on top of layered spam filtering and antivirus scanning of every message. Settings are explained step by step in the anti-spam and anti-phishing guide.
A sensible rollout plan
- Confirm SPF, DKIM and DMARC pass for your domain.
- Keep the External tag and link checking on, and tell staff what the tag means.
- Add protected names for executives and finance, and protected domains for your bank and main suppliers.
- Run impersonation actions as "warn" for two weeks, check what they catch, then switch to Junk or quarantine.
- Turn on ZAP and quarantine.
- Show everyone the Report phishing button. One report can protect the whole company.
Pair this with the wider email security best practices and a payment-verification process against business email compromise.
If you want these protections built into your business email instead of bought as an extra gateway, Zomail includes them on its Cloud plans and on Private Mail. Prices are shown live on the pricing page.
FAQ
Is a spam filter enough to stop phishing?
No. Spam filters catch mass mailings and known bad senders. Targeted phishing is often short, comes from a new domain, has no attachment and links to a brand-new site. That is why you also need warnings in the inbox, link checks at click time and a way to remove mail after it has been delivered.
What is zero-hour auto purge (ZAP)?
ZAP removes a message from users' inboxes after delivery once it becomes known to be dangerous. For example, its link is added to a phishing list, or the sender is blocked. In Zomail it covers mail delivered in the previous 48 hours, and messages a user marked "Not spam" are left alone.
Does adding [EXTERNAL] to the subject cause problems?
It works in every mail app, but changing the subject breaks the original DKIM signature on the delivered copy. Many organisations rely on the in-app External tag instead and only use the subject prefix when staff mainly read mail in Outlook or on phones.
Should users be allowed to open a blocked link?
It depends on how much you trust your users and how many false positives you see. Allowing overrides with logging is a common compromise. Admins can see every override and follow up if a click turns out to be a real compromise.
What should staff do if they clicked a phishing link?
Report the message, change their password straight away, and sign out other sessions. Tell an admin so they can check the audit log and purge the message for everyone else. If two-factor authentication is on, a stolen password alone is much less useful to an attacker.