Email Security for Indian SMBs 2026: Stop Phishing & BEC

A ₹8.4 lakh fraud started with one perfect-looking email. Learn practical, affordable email security for Indian SMBs to stop phishing and BEC this week.

Meera Nair29 September 2026 13 min read
Email Security for Indian SMBs 2026: Stop Phishing & BEC

Last month a friend who runs a 30-person export house in Ludhiana called me in a panic. Their accounts manager had wired ₹8.4 lakh to what she believed was a genuine supplier in Surat. The email looked perfect. Same signature, same tone, same invoice format they had seen dozens of times. Only the bank account had changed, "because of a GST audit," the message explained. The money was gone in under four hours. The real supplier had never sent that email.

This is Business Email Compromise, and it is quietly draining Indian SMBs faster than ransomware ever did. The FBI's IC3 pegs global BEC losses in the billions, but what nobody tells you is that Indian mid-market firms are prime targets precisely because they run lean, trust email implicitly, and rarely have a dedicated security person. Most owners I meet assume their Google Workspace or Microsoft 365 subscription protects them out of the box. It does not, at least not with default settings.

This guide is about practical, affordable email security for Indian SMBs that you can actually implement this week, whether you are on Workspace, 365, or still figuring out which to use. No enterprise SOC, no six-figure budgets. Just the specific settings, records, and habits that stop the attacks I see actually landing.

Key Takeaways
  • Configure SPF, DKIM, and DMARC on your domain. This trio is free and blocks the majority of spoofing. Most Indian SMBs have none of it set up correctly.
  • BEC does not use malware, so antivirus won't catch it. The defence is a payment verification process, not software.
  • Turn on multi-factor authentication for every account. A ₹0 setting stops the single most common breach path.
  • Your built-in Workspace or 365 plan already includes strong controls. The problem is they ship disabled or misconfigured.
  • Budget realistically: solid protection for a 25-person firm costs roughly ₹15,000–₹40,000 per year on top of licensing, mostly for a phishing-simulation tool and one afternoon of setup.
  • Train the humans. Technology filters most attacks, but the one that reaches your accountant needs a trained person to stop it.

Why is email security for Indian SMBs suddenly a bigger risk in 2026?

Three things changed. First, attackers moved from spray-and-pray spam to targeted, research-driven fraud. They read your LinkedIn, spot who your CFO is, notice you posted about a new vendor, and craft a message that fits your reality. Second, AI made this cheap. Perfectly written English, or Hindi, or Gujarati, at scale. The old giveaway of broken grammar is gone.

Third, and this is the India-specific part, the volume of digital B2B payments exploded post-UPI and post-GST digitisation. When every invoice, e-way bill, and payment confirmation flows through email, that channel becomes the crime scene. A fraudster doesn't need to hack your ERP. They just need to insert one convincing email into an existing payment conversation.

The uncomfortable truth is that your security posture is roughly where a mid-size firm's was in 2015. Meanwhile the attackers upgraded. Closing that gap doesn't require money so much as attention.

The three attack types you actually need to worry about

  • Phishing: A fake login page harvesting your Workspace or 365 password. Often disguised as a "shared document" or "mailbox full" alert.
  • Spoofing: An email that appears to come from your own domain, or a trusted partner's, but doesn't. This is what SPF/DKIM/DMARC stops.
  • Business Email Compromise (BEC): The expensive one. A carefully timed message asking for a payment redirect, a gift card, or urgent fund transfer, usually impersonating a director or supplier.

How do SPF, DKIM, and DMARC actually protect you?

These three DNS records are the foundation, and the fact that they're free is why every serious setup starts here. Think of them as the postal system for email authentication.

  • SPF (Sender Policy Framework) lists which servers are allowed to send email on behalf of your domain. If mail arrives from an unlisted server, receiving systems get suspicious.
  • DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your outbound mail, proving it wasn't tampered with in transit.
  • DMARC (Domain-based Message Authentication) is the policy layer. It tells the world what to do when SPF or DKIM fails: nothing, quarantine, or reject. It also sends you reports on who is spoofing your domain.

Here's the part nobody mentions: most Indian SMBs I audit have SPF set up (their web host added it years ago), no DKIM, and a DMARC policy of p=none, which means "detect but do nothing." That's like installing a burglar alarm and disconnecting the siren.

A step-by-step DMARC rollout you can hand to your IT vendor

  1. Publish SPF. In your domain's DNS, add a TXT record. For Google Workspace it's v=spf1 include:_spf.google.com ~all. For Microsoft 365 it's v=spf1 include:spf.protection.outlook.com -all. If you use a bulk mailer or CRM, include their sending domain too.
  2. Enable DKIM. In the Workspace Admin console under Apps > Google Workspace > Gmail > Authenticate email, generate the key and publish the provided TXT record. In 365, do it via the Defender portal under Email & collaboration > Policies > DKIM.
  3. Start DMARC at monitoring. Publish a TXT record at _dmarc.yourdomain.in with v=DMARC1; p=none; rua=mailto:[email protected]. Collect reports for two to four weeks.
  4. Read the reports. You'll discover every service sending as you: your accounting tool, your e-way bill portal integration, marketing platforms. Add legitimate ones to SPF, fix DKIM where possible.
  5. Tighten to quarantine. Change to p=quarantine. Spoofed mail now lands in spam instead of the inbox.
  6. Move to reject. After a few more weeks of clean reports, set p=reject. Now spoofed email using your domain is bounced outright.
Common Mistake: Jumping straight to p=reject before you've mapped every legitimate sender. I've watched a firm in Pune silently block their own GST invoice reminders and payment receipts for a week because their billing software wasn't in SPF. Always spend the monitoring weeks first. The reports are boring; read them anyway.

What email security does Google Workspace vs Microsoft 365 give you by default?

Both platforms include far more than owners realise. The question is which tier and whether the controls are switched on. Here's how the practical protection compares for a typical Indian SMB.

Capability Workspace Business Standard M365 Business Standard M365 Business Premium
Approx. price/user/month (INR) ₹736 ₹770 ₹1,560
Built-in spam & phishing filter Yes, strong Yes (EOP) Yes (EOP)
Advanced anti-phishing / impersonation protection Partial No Yes (Defender for O365 P1)
Safe attachments / link scanning Basic No Yes
MFA support Yes, free Yes, free Yes, free
DLP (data loss prevention) Limited No Yes
Device management Basic MDM Basic Intune (full)

My practical read: if your firm handles significant payments or sensitive client data, Microsoft 365 Business Premium is worth the jump for Defender's impersonation protection alone. It actively flags emails pretending to be your directors. For most services and trading firms, Workspace Business Standard with tight configuration is genuinely sufficient and easier to manage.

If you're still deciding between platforms, we broke this down in detail in our comparison of Google Workspace vs Microsoft 365 for Indian SMBs. And when you're ready to buy, eDarpan handles Google Workspace licensing and Microsoft 365 licensing with local billing and GST invoices, so you're not fighting international payment gateways.

How do you actually stop Business Email Compromise?

This is the section that saves real money, so read it twice. BEC succeeds because it exploits process, not technology. There is no malware to scan, no bad link to block. The fraudulent email is technically clean. It just contains a lie.

The defence is procedural, and it costs nothing but discipline.

The verification rules every Indian SMB should adopt

  1. Never change a supplier's bank details on email alone. Any request to update account numbers must be confirmed by a phone call to a known number, not the number in the email.
  2. Set a payment threshold requiring dual approval. Anything above, say, ₹1 lakh needs a second person's sign-off through a channel other than email.
  3. Treat urgency as a red flag, not a reason to hurry. "The director needs this transferred before he lands in Mumbai" is the oldest trick going. Genuine urgency survives a two-minute verification call.
  4. Flag external emails visibly. Both Workspace and 365 can prepend an [EXTERNAL] banner to messages from outside your domain. An email "from your MD" that carries this banner is instantly suspect.
  5. Verify domain look-alikes. Train staff to spot rnicrosoft.com, yourcompany-invoices.in, or a .co where you expect .com.

A worked example: the Gurgaon logistics firm that got hit twice

A 40-person logistics company in Gurgaon lost ₹6.2 lakh to a supplier-impersonation scam in early 2025. The fraudster had monitored a compromised vendor mailbox, waited for a genuine invoice, and sent a follow-up "correcting" the bank details. Textbook BEC.

After the incident they brought us in. Here's exactly what we implemented, and the cost:

  • Enforced MFA across all 40 accounts using free authenticator apps. Cost: ₹0.
  • Fixed SPF, enabled DKIM, moved DMARC to p=reject over three weeks. Cost: consulting time only.
  • Turned on the external-sender banner and 365 Defender impersonation protection (they upgraded 12 finance and management users to Business Premium). Incremental cost: about ₹9,500/month.
  • Introduced a written payment-change verification policy with a callback rule and dual approval above ₹1 lakh. Cost: ₹0.
  • Ran a phishing simulation and 45-minute training session for all staff. Cost: about ₹18,000/year for the tool.

Total additional spend: under ₹1.3 lakh in the first year, against a ₹6.2 lakh single loss. Three months later, a near-identical attack arrived. The accounts executive saw the external banner, noticed the bank change, called the supplier's known number, and confirmed the email was fake. The process worked. That callback was worth every rupee of the setup.

What are the quick wins you can turn on this week?

If you do nothing else, do these. Each is fast and most are free.

  1. Enforce MFA for every user. Not optional, not "recommended." Enforced. This alone blocks the vast majority of account takeovers.
  2. Enable the external-email banner. A five-minute admin console change that pays off constantly.
  3. Publish and enforce DMARC using the rollout above.
  4. Disable legacy authentication protocols (IMAP/POP/SMTP basic auth) that bypass MFA. In 365 this is under Conditional Access; in Workspace, disable "less secure app access."
  5. Turn on alerts for suspicious sign-ins and for admin actions like creating forwarding rules. Attackers love setting a silent forward on your CFO's mailbox.
  6. Audit mail-forwarding rules right now. Check every account for auto-forwards to external addresses. This is a classic sign of an already-compromised inbox.
Pro Tip: The single most overlooked breach indicator is an inbox rule that quietly deletes or forwards emails containing words like "invoice," "payment," or "bank." Attackers set these so the victim never sees the real supplier's follow-up. Audit forwarding and filter rules across all accounts quarterly. It takes ten minutes and I have caught two active compromises this way.

Do you need a third-party tool on top of Workspace or 365?

Often, yes, but not the expensive kind. The two categories worth paying for as an SMB are phishing-simulation training and, for higher-risk firms, an advanced email gateway.

Phishing simulation is the highest-ROI add-on. Tools that send fake phishing tests to your staff and train the ones who click cost roughly ₹150–₹400 per user per year. For a 25-person firm that's ₹4,000–₹10,000 annually. Cheap insurance against the human error that no filter catches.

An advanced email security gateway (the layer that sits in front of your mailbox and does deep link and attachment analysis) makes sense once you're above 50 users or handling regulated data. Below that, 365 Business Premium's built-in Defender usually covers the same ground without a separate contract.

Don't buy a gateway before you've done the free work. I regularly meet firms paying ₹40,000 a year for a security appliance while their DMARC is still on p=none and half their staff have no MFA. That's a lock on the window with the front door wide open. If you're unsure what your gaps are, our IT consulting team runs a focused email-security audit that pays for itself in avoided risk.

How does email security fit into your broader IT and compliance picture?

Email is one channel, but the same discipline extends across your stack. If you're moving systems to the cloud, the security defaults matter just as much there, which is why we cover them as part of our cloud migration and managed services. And if you rely heavily on email for customer communication, shifting transactional messages to more secure, verifiable channels helps too. Many of our clients move OTPs and payment confirmations to WhatsApp Business API or bulk SMS precisely to reduce reliance on spoofable email.

On the compliance side, India's DPDP Act raises the stakes on protecting personal data, and a breached mailbox full of customer PII is now a reportable, penalty-carrying event. If you're weighing where your data sits, our guide to data residency rules in India and the India sovereign cloud landscape are useful companions to this piece.

For businesses registering a new entity or needing a compliant GST address alongside their digital setup, our virtual office service for GST and company registration is a common starting point. And you can see the full range of what we do on our services overview.

Frequently Asked Questions

Does Google Workspace or Microsoft 365 protect against phishing by default?

Partially. Both include strong spam and basic phishing filters out of the box, but advanced protections like impersonation detection, safe-link scanning, and enforced MFA either require configuration or a higher tier such as M365 Business Premium. The defaults stop obvious spam but not a well-crafted BEC email. You must configure the platform, not just buy it.

How much does email security cost for a small business in India?

The foundation (SPF, DKIM, DMARC, MFA, external banners) is free, requiring only setup time. Beyond that, a phishing-simulation tool runs about ₹150–₹400 per user per year, and upgrading key staff to M365 Business Premium adds roughly ₹800 per user per month. A 25-person firm can be well protected for ₹15,000–₹40,000 annually above licensing.

What is Business Email Compromise and how is it different from phishing?

Phishing tries to steal your credentials, usually through a fake login page. BEC skips the technical hack and instead impersonates a trusted person or supplier to trick you into sending money or data. BEC emails often contain no malware or bad links, so security software can't catch them. The defence is a strict payment-verification process, not a filter.

What is DMARC and do I really need it?

DMARC is a DNS policy that tells receiving mail servers what to do with email that fails authentication, and it stops criminals from spoofing your domain. Yes, you need it. Without an enforced DMARC policy, anyone can send email that appears to come from your company, which is the launchpad for most supplier fraud.

Is multi-factor authentication enough to secure our email?

MFA is the single most important control and blocks most account takeovers, but it's not enough alone. It won't stop BEC (where no login is compromised) or spoofing of your domain. Combine enforced MFA with SPF/DKIM/DMARC, external-sender banners, and a payment-verification process for real protection.

How do I know if our email has already been compromised?

Look for auto-forwarding or filter rules you didn't create, especially ones targeting words like "invoice" or "payment." Other signs include sign-ins from unexpected locations, colleagues reporting emails you never sent, and suppliers querying payments you don't recognise. Audit forwarding rules across all accounts immediately if you suspect anything.

Should Indian SMBs move payment confirmations off email?

For high-risk transactional messages like OTPs and payment confirmations, yes, using verified channels like WhatsApp Business API or SMS reduces exposure to email spoofing. Email remains fine for general correspondence but shouldn't be the sole channel authorising fund movements. Diversifying your communication channels shrinks the attack surface.

The bottom line

Effective email security for Indian SMBs is less about buying a shiny product and more about doing the unglamorous basics properly: authenticate your domain, enforce MFA, flag external mail, and build a payment-verification habit your team actually follows. Most of that is free. The part that costs money, a phishing-simulation tool and maybe a Business Premium upgrade for finance staff, is trivial next to a single ₹6-lakh fraud.

The firms that get burned aren't the ones with small budgets. They're the ones who assumed their subscription had it handled. Spend one focused afternoon this week on the checklist above and you'll have closed the gaps that let most of these attacks through.

If you'd rather have it done right the first time, eDarpan configures Workspace and 365 security, runs email-security audits, and sets up DMARC end-to-end for SMBs across India. Get in touch with our team and we'll start with a review of where your current gaps are. You can also learn more about how we work with growing Indian businesses.

Image credit: Innovate Maryland Emerging Technology Center by MDGovpics via flickr (BY 2.0), sourced through Openverse.

M

Written by

Meera Nair

IT project manager with a decade of experience delivering custom software and mobile apps for Indian businesses. Meera writes about technology adoption, app development lifecycles, and AI integration.

Looking for a technology partner?

From IT consulting to virtual office to custom software — eDarpan can help.

Email Security for Indian SMBs 2026: Stop Phishing | eDarpan