5 min read
Microsoft Licensing Update: New Defender Suite for Business Premium
Small and midsize businesses are increasingly targeted by sophisticated cyber threats, yet many advanced security solutions have historically been...
3 min read
Nicole Walker
:
Jun 12, 2025 9:00:00 AM
Microsoft 365 has introduced a new generation of email security capabilities designed to address modern threats like phishing, spoofing, and business email compromise.
Defender for Office 365 now includes AI-driven threat detection, real-time scanning of links and attachments, and integration with Microsoft’s broader security stack. These protections are supported by authentication protocols such as SPF, DKIM, and DMARC, along with DNSSEC, MTA-STS, and TLS-RPT for encrypted delivery and domain validation. The recent shift to mx.microsoft.com records further strengthens trust signals and improves deliverability across Microsoft-hosted environments.
\
In this episode of the Demystifying Microsoft podcast, Nathan Taylor (SVP, Global Microsoft Practice Leader at Sourcepass MCOE) outlines how Microsoft’s email security architecture is adapting to stricter validation requirements and increasingly sophisticated attack patterns.
Defender for Office 365 now applies AI models to analyze message intent, scan payloads at time-of-click, and correlate threat signals across endpoints. Protocols like SPF, DKIM, DMARC, DNSSEC, and MTA-STS work in tandem to authenticate senders and enforce encrypted delivery. Legacy filtering setups that reroute mail can interfere with these signals, making direct integration with Microsoft’s stack essential for maintaining trust and deliverability.
Microsoft Defender for Office 365 is the integrated security solution for Microsoft 365, providing protection against phishing, malware, and business email compromise. It uses AI-driven threat detection, real-time reporting, and automated investigation to safeguard email, Teams, SharePoint, and OneDrive. Plan 1 covers essential protections and is included in Business Premium; Plan 2 adds advanced features like attack simulation, threat intelligence, and automated response, available in E5 and as an add-on.
SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting & Conformance) are the core standards for authenticating email sources and preventing spoofing. SPF validates sending servers, DKIM cryptographically signs emails, and DMARC enforces alignment and reporting. Microsoft 365 requires these records for trusted delivery, especially for bulk senders. Without proper configuration, emails may be rejected or sent to spam by major providers like Microsoft, Google, and Yahoo.
Microsoft is transitioning from protection.outlook.com to mx.microsoft.com for MX records, enabling DNSSEC and SMTP DANE for enhanced security. DNSSEC cryptographically signs DNS records, preventing spoofing and man-in-the-middle attacks. SMTP DANE ensures encrypted, authenticated connections between mail servers. These changes improve both inbound and outbound mail validation and are critical for organizations seeking to meet modern security standards.
MTA-STS (Mail Transfer Agent Strict Transport Security) enforces TLS encryption for SMTP connections, ensuring emails are only delivered to servers with valid certificates. TLS-RPT (TLS Reporting) provides diagnostic reports on TLS connectivity issues, helping admins identify and fix problems with secure mail delivery. Both are now supported in Exchange Online and should be configured for maximum protection.
Tools like EasyDMARC and Microsoft Secure Score help IT teams monitor DMARC alignment, receive reports on authentication failures, and benchmark security posture. Regular assessments, configuration reviews, and automated reporting are essential for maintaining compliance and defending against evolving threats.
Plan 1 is included in Business Premium and covers email, Teams, SharePoint, and OneDrive. Plan 2 is available in E5 and E5 Security add-ons, offering advanced threat protection and attack simulation.
SPF validates sending servers, DKIM signs emails with cryptographic keys, and DMARC enforces alignment and reporting. Together, they prevent spoofing and improve deliverability.
Switching to mx.microsoft.com enables DNSSEC and SMTP DANE, improving trust signals and encrypted delivery for inbound and outbound mail.
DNSSEC ensures DNS records are signed and tamper-proof, supporting secure mail transport and protecting against domain spoofing.
Yes, but API-based integration is recommended. Routing mail through external servers can interfere with authentication protocols and reduce deliverability.
Tools like EasyDMARC provide visibility into authentication failures, helping you align third-party senders and maintain compliance with bulk email standards.
Publish DNS records and policy files for your domain. These protocols enforce TLS encryption and provide reporting on mail transport security.
Sourcepass MCOE offers a free Office 365 security assessment and guided deployment of SPF, DKIM, DMARC, DNSSEC, and Defender for Office 365.
Microsoft 365 offers built-in protections that help organizations defend against phishing, spoofing, and business email compromise. With Defender for Office 365, authentication protocols like SPF, DKIM, and DMARC, and encryption layers such as DNSSEC and MTA-STS, businesses can improve deliverability and reduce risk without relying on third-party filtering.
For ongoing updates and practical insights on Microsoft 365 email security, subscribe to the Demystifying Microsoft podcast.
If you have questions about how these changes could impact your organization or want to discuss options for deploying Microsoft 365’s built-in email security features, connect with a Sourcepass MCOE expert today for a free Office 365 security assessment.
5 min read
Small and midsize businesses are increasingly targeted by sophisticated cyber threats, yet many advanced security solutions have historically been...
5 min read
Small and medium-sized businesses often face the same security and compliance requirements as large enterprises, but until now, many advanced tools...
4 min read
Microsoft has announced a major change to its Enterprise Agreement pricing model, effective November 1st, 2025. Discount pricing for online services...
Ensuring email deliverability and security requires a layered approach built on DNS, SPF, DKIM, and DMARC. These technologies work together to...
Email continues to be one of the most exploited entry points for cyberattacks, including phishing, spoofing, and business email compromise (BEC)....
Small and medium-sized businesses often face the same security and compliance requirements as large enterprises, but until now, many advanced tools...