Email Security for Microsoft 365 & Google Workspace in India

A Pune firm lost ₹11.4 lakh to a lookalike email their Microsoft 365 waved through. Learn why native filters miss BEC and how to build layered defence.

Meera Nair21 August 2026 12 min read
Email Security for Microsoft 365 & Google Workspace in India

Last quarter I got a panicked call from the finance head of a mid-sized auto parts distributor in Pune. Their accounts team had just wired ₹11.4 lakh to a "vendor" whose bank details had changed over email. The email looked perfect. Right signature, right logo, correct GST invoice format, even the usual spelling mistakes their real vendor always made. The catch? It came from a lookalike domain that swapped a lowercase "l" for a capital "I". Their Microsoft 365 tenant, with all its default protection turned on, let it through without a whisper.

This is the uncomfortable reality most Indian SMB owners don't want to hear: the built-in email security for Microsoft 365 and Google Workspace is designed to stop the loud, obvious spam and known malware. It does that reasonably well. But Business Email Compromise (BEC) and targeted phishing don't carry a virus payload or a known-bad link. They carry a plausible request from a plausible sender, and that's exactly what native filters wave through. According to the FBI's IC3 reporting, BEC has caused tens of billions of dollars in global losses, and Indian businesses are increasingly on that list precisely because they've moved to cloud email and assumed it's "secure by default."

In this post I'll walk through why the defaults leave gaps, what a layered defence actually looks like in practice, real rupee costs, a comparison of add-on tools, and a step-by-step implementation plan you can hand to your IT team or vendor tomorrow.

Key Takeaways
  • Native Microsoft 365 and Google Workspace filters catch spam and known malware well, but miss most targeted BEC and payment-fraud attacks that carry no malicious payload.
  • The single highest-ROI free step is enforcing SPF, DKIM and DMARC on your domain, then moving DMARC to p=reject.
  • Add a dedicated email security gateway or API-based layer (Mimecast, Proofpoint, Abnormal, or Microsoft Defender for Office 365 Plan 2) for BEC and impersonation detection.
  • Technical controls fail without a payment-verification process; a callback rule for any bank-detail change stops most losses.
  • Expect to spend roughly ₹150–₹450 per user per month for a solid add-on layer, far less than a single fraudulent transfer.
  • Train staff quarterly with simulated phishing, not once-a-year slideshows.

Why isn't native Microsoft 365 and Google Workspace email security enough?

Both platforms ship with genuinely capable filtering. Microsoft's Exchange Online Protection (EOP) and Google's built-in Gmail security block the overwhelming majority of junk. The problem is what they're optimised for: volume-based threats. A phishing campaign blasted to a million addresses gets fingerprinted fast. A single, hand-crafted email to your CFO does not.

Here's the mechanism gap. A classic BEC email has:

  • No attachment and no link (nothing to scan).
  • A "from" name that matches your MD or a known vendor.
  • Text that mimics normal business language: "Please update our account for the pending payment."
  • Often sent from a freshly registered lookalike domain or a legitimately compromised third-party mailbox.

To EOP or Gmail, this is just a plain email from an address they've never blocklisted. There's no signal to act on unless you've configured impersonation and anti-spoofing policies, and even then the default settings are conservative to avoid blocking legitimate mail.

Common mistake: Many SMBs buy Microsoft 365 Business Standard (around ₹770/user/month) assuming it includes advanced threat protection. It doesn't. Defender for Office 365 Plan 1 is a separate add-on, and the stronger Plan 2 (with attack simulation and automated investigation) needs Business Premium or an explicit add-on licence. If you're unsure which plan you're actually paying for, our team can audit your Microsoft 365 licensing and show you exactly what's active versus dormant.

What does a real BEC attack look like against an Indian SMB?

Let me go back to that Pune distributor, because the anatomy is instructive. This is how the ₹11.4 lakh walked out the door.

  1. Reconnaissance: The attacker scraped the company's website and a GST portal listing to identify the finance contact and a genuine supplier name.
  2. Domain spoof: They registered suppliercorp-india.com when the real domain was suppliercorpindia.com. Cost them under ₹800.
  3. Timing: They struck two days before a known quarterly payment cycle, referencing a real pending invoice number they'd guessed from the sequence.
  4. The ask: A polite email stating the supplier had "switched banks due to a GST audit" and providing new account details.
  5. The execution: Finance updated the payee master and released payment. By the time the real supplier chased for money three weeks later, the funds had been layered through three mule accounts.

What would have stopped it? Three things, none expensive. A DMARC policy that flagged the lookalike domain. An impersonation warning banner on external mail claiming to be a known vendor. And a simple internal rule: no bank-detail change is actioned without a phone callback to a previously known number. That last one is free and stops more fraud than any software.

What layers should Indian SMBs add on top of the defaults?

Think of email security as an onion, not a switch. Here's the stack I recommend, in order of priority and cost-effectiveness.

1. Email authentication: SPF, DKIM, DMARC (free, do this first)

These are DNS records that prove your mail is really from you and instruct receiving servers what to do with fakes.

  • SPF lists which servers may send on behalf of your domain.
  • DKIM cryptographically signs your outgoing mail.
  • DMARC ties the two together and tells the world "reject anything that fails."

Most Indian SMBs I audit have SPF half-configured and DMARC sitting at p=none, which means it monitors but does nothing. Getting to p=reject is the goal. Do it in stages so you don't accidentally block your own CRM or billing tool.

2. Advanced threat protection or an API-based layer

This is where you catch what the defaults miss. Two architectural approaches:

  • Gateway model (Mimecast, Proofpoint): mail routes through their cloud before reaching your tenant.
  • API/inline model (Abnormal Security, Microsoft Defender P2, Google's built-in with add-ons): connects via API and analyses behaviour without changing your MX records.

The API model is easier to deploy and better at behavioural BEC detection because it learns your normal communication patterns. If your MD never emails at 2am asking for gift cards, it flags the anomaly.

3. User awareness and simulated phishing

Technology stops maybe 95% of attacks. The remaining 5% land in a human inbox. Quarterly simulated phishing (KnowBe4, or the built-in tools in Defender P2) turns your staff into a sensor network instead of a liability.

4. Process controls

The cheapest and most effective layer. Mandatory callbacks for payment changes, dual approval above a rupee threshold, and a clearly published internal reporting mailbox for suspicious mail.

Which email security add-on is right for your business?

Here's an honest comparison of the options I actually deploy for Indian SMBs, with indicative pricing. Prices vary by volume and reseller, so treat these as ballpark.

Solution Model BEC / impersonation strength Approx. cost (₹/user/month) Best for
Microsoft Defender for O365 Plan 1 Native add-on Moderate 150–200 M365 shops wanting safe links/attachments
Microsoft Defender for O365 Plan 2 Native add-on Good 350–450 M365 shops needing simulation + auto-remediation
Mimecast Gateway Very good 250–400 Firms wanting archiving + continuity too
Proofpoint Essentials Gateway Very good 200–350 Compliance-heavy SMBs
Abnormal Security API/behavioural Excellent (BEC) 300–450 Anyone prioritising BEC/payment fraud

Pro tip: If you're already on Microsoft 365 Business Premium, you likely already own Defender for Office 365 Plan 1 and just haven't turned on the anti-phishing and safe-links policies. Before you buy a third-party tool, audit what's included. I've seen companies pay twice for capabilities gathering dust in their existing licence. This is exactly the kind of waste our IT consulting engagements catch in the first week.

How do you actually configure this? A step-by-step walkthrough

Here's the sequence I follow when hardening a client's tenant. You can hand this to your admin or brief your managed services provider directly.

Step 1: Publish and verify SPF

Add a TXT record. For Microsoft 365 it's typically v=spf1 include:spf.protection.outlook.com -ip4:your.smtp.ip -all. For Google Workspace, v=spf1 include:_spf.google.com ~all. Include every third-party sender (Zoho Invoice, Freshdesk, your bulk mailer). Use the hard fail -all only once you're confident all senders are listed.

Step 2: Enable DKIM

In Microsoft 365, go to the Defender portal, Email & collaboration policies, DKIM, and enable signing for your domain (you'll add two CNAME records). In Google Workspace, Apps, Google Workspace, Gmail, Authenticate email, generate the DKIM key and publish it.

Step 3: Deploy DMARC in monitoring mode

Add a TXT record at _dmarc.yourdomain.com: v=DMARC1; p=none; rua=mailto:[email protected]. Collect aggregate reports for two to four weeks. A tool like the reporting features in your add-on, or a free DMARC analyser, will tell you which legitimate services are failing so you can fix SPF/DKIM before you tighten policy.

Step 4: Move DMARC to quarantine, then reject

Once reports show only your legitimate mail passing, change p=none to p=quarantine, monitor for another two weeks, then p=reject. This is the step that neutralises exact-domain spoofing.

Step 5: Configure anti-phishing and impersonation policies

In Defender, set up an anti-phishing policy protecting your named VIPs (MD, CFO, finance heads) and your top vendor domains. Enable mailbox intelligence and set the action for detected impersonation to "quarantine." In Google Workspace, enable enhanced pre-delivery message scanning and the spoofing/authentication protections under Gmail safety settings.

Step 6: Add external sender banners

Apply a mail flow rule that stamps a visible warning on any email originating outside your organisation. A simple "[EXTERNAL] This email came from outside the company" banner makes lookalike domains far more obvious to staff.

Step 7: Turn on MFA everywhere and disable legacy auth

Compromised credentials are how attackers get into a real mailbox and send from a trusted internal address. Enforce multi-factor authentication for all users and block basic/legacy authentication protocols that bypass MFA.

Step 8: Set up simulated phishing and reporting

Enable the "Report Phishing" button (native in both platforms or via KnowBe4). Run a baseline simulation, measure your click rate, then repeat quarterly. A click rate above 15% means you have training work to do.

What does this cost, and is it worth it for a small business?

Let's do the maths for a realistic 40-person firm, say a distribution business in Ahmedabad.

  • SPF/DKIM/DMARC configuration: ₹0 in licensing, a few hours of admin time.
  • Behavioural add-on at ₹350/user/month × 40 users: ₹14,000/month, or ₹1.68 lakh a year.
  • Quarterly phishing simulation and training: roughly ₹40,000–₹60,000/year depending on tool.

Total: under ₹2.3 lakh a year. Now weigh that against a single successful BEC transfer. The Pune company lost ₹11.4 lakh in one email, and recovered nothing. When I frame it that way for owners, the decision makes itself. The layered defence pays for itself if it stops even one attack every five years, and the actual attack frequency is far higher than that.

There's also a compliance dimension. If you handle customer data or operate in a regulated sector, CERT-In's directions require timely incident reporting and reasonable security practices. A documented email security posture is part of demonstrating that. We covered the broader regulatory picture in our piece on what RBI and CERT-In require for cloud data localization, which is worth reading alongside this if you're in fintech, lending, or handle sensitive personal data.

How does this fit into your broader IT and communication stack?

Email is one channel, but Indian SMBs increasingly run customer communication across WhatsApp, SMS, and voice too. Each of those needs its own trust controls. If you're moving transactional alerts to WhatsApp, verified business numbers and template approval reduce the impersonation surface, which is one reason we help clients set up the WhatsApp Business API properly rather than relying on unverified numbers. Similarly, if you send OTPs or payment confirmations by SMS, using a registered DLT sender ID through a proper bulk SMS service prevents smishing lookalikes.

If you're still deciding between platforms entirely, our comparison of Zoho vs Google Workspace vs Microsoft 365 for Indian SMBs breaks down the licensing and security trade-offs. And for firms building customer-facing systems, remember that security decisions in email spill over into how you design your custom software and mobile apps, especially around login flows and notification integrity.

Frequently asked questions

Does Microsoft 365 include phishing protection by default?

It includes baseline anti-spam and anti-malware through Exchange Online Protection on every plan. Advanced anti-phishing with impersonation detection, safe links, and attack simulation requires Defender for Office 365 (Plan 1 or Plan 2), which comes bundled with Business Premium but not with Business Basic or Standard.

Is DMARC mandatory in India?

It's not a legal mandate for most Indian businesses yet, but major mailbox providers like Google and Yahoo now require it for bulk senders, and it's strongly recommended as reasonable security practice under CERT-In guidance. Practically, without DMARC at p=reject, anyone can spoof your exact domain.

Can attackers still get through even with all these controls?

Yes, no control is 100%. Lookalike domains (as opposed to exact spoofs) can bypass DMARC because they're technically different domains. That's why behavioural detection plus a human callback process for payments remains essential. Layering is the point; each control catches what the previous one misses.

What is the fastest thing I can do today to reduce risk?

Two things, both free. Turn on multi-factor authentication for every account, and implement a rule that no vendor bank-detail change is actioned without a phone call to a known number. Those two steps alone block the majority of successful BEC losses.

How much does email security cost for a small Indian business?

Authentication (SPF/DKIM/DMARC) costs nothing but admin time. A solid behavioural or gateway add-on runs roughly ₹150–₹450 per user per month depending on the tool and features. For a 40-person firm, budget around ₹2–2.5 lakh a year including training, which is trivial next to a single fraudulent transfer.

Do I need a third-party tool if I already use Google Workspace?

Google Workspace's built-in security is strong, especially on the Business Plus and Enterprise tiers with enhanced pre-delivery scanning. Many small businesses can start by fully enabling those native controls plus DMARC. Add a behavioural layer if you handle high-value payments or have been targeted before.

Who should manage all this if I don't have an in-house IT team?

A managed services partner can own the configuration, monitoring, and quarterly training so it doesn't fall through the cracks. That's precisely the kind of ongoing work eDarpan handles for SMBs across India, from initial audit through to running the DMARC reports every month.

The bottom line

Native email security for Microsoft 365 and Google Workspace is a solid foundation, not a finished building. It stops the noise, but the attacks that actually drain Indian bank accounts, the quiet, targeted BEC and payment-fraud emails, slip through the gaps by design. The fix isn't expensive or exotic. It's authentication done properly, one behavioural detection layer, MFA everywhere, staff who know how to spot a lookalike, and a payment process that assumes email can lie.

If you'd like a straight audit of what your current tenant is actually protecting against, and what it's quietly missing, that's a good place to start. Explore our full range of services or get in touch with the eDarpan team for a no-obligation review of your Microsoft 365 or Google Workspace setup. We'll tell you what to fix first, what you already own, and where you're overspending. You can also learn more about how we work with Indian SMBs.

Image credit: Innovate Maryland Emerging Technology Center by MDGovpics via flickr (BY 2.0), sourced through Openverse.

M

Written by

Meera Nair

IT project manager with a decade of experience delivering custom software and mobile apps for Indian businesses. Meera writes about technology adoption, app development lifecycles, and AI integration.

Looking for a technology partner?

From IT consulting to virtual office to custom software — eDarpan can help.

Email Security for Microsoft 365 & Google Workspace | eDarpan