Before delivery
MX/Inline puts Cloudflare in the SMTP path. It can block or quarantine, add headers or banners, and apply link actions before the mailbox receives the message.
Requires mail-flow and MX/connector planning.Stop phishing and BEC before the inbox, then find and retract campaigns after delivery.
Cloudflare adds inspection and response around the existing mail flow. Users keep Outlook, their mailboxes, and normal collaboration workflows.
Cloudflare Email Security was formerly Area 1.The deployment determines when Cloudflare sees a message and which actions are available. “Email Security” does not imply every customer must change MX records.
MX/Inline puts Cloudflare in the SMTP path. It can block or quarantine, add headers or banners, and apply link actions before the mailbox receives the message.
Requires mail-flow and MX/connector planning.Microsoft Graph provides rapid post-delivery deployment. Cloudflare analyzes messages and can move or delete threats after they arrive.
Google Workspace uses BCC ingestion plus a service-account integration for remediation.Combine inline prevention with provider API visibility and retraction. This gives the SOC a response path when a campaign changes after delivery.
Provider support and package determine available actions.Cloudflare evaluates who sent it, how it is written, where links lead, what attachments contain, and whether authentication agrees with the visible identity.
The value is not only the verdict. Analysts need to understand the message, find related copies, remove exposure, and retain an action trail.
Review disposition, impersonation, malicious-link, attachment, submission, and auto-move trends.
Inspect authentication, sender infrastructure, links, files, raw EML, mail trace, and safe browser views.
Use Email Detection Fingerprints and advanced search to locate related messages across inboxes.
Move or delete matching messages, release false positives, and confirm each action in the history.
This is a proposed proof path—not a configured account claim. Use a synthetic demo tenant and harmless fixtures; never send live malware or real employee data.
Connect a Microsoft 365 demo tenant and scan up to the prior 14 days to establish a safe baseline without changing MX records.
Evidence: findings reportUse read-write mode for directory context and remediation, then verify the protected domain reports Active.
Evidence: integration healthAdd fictional CEO, CFO, payroll, and help-desk identities. Start malicious auto-moves at Junk and leave Suspicious at No action.
Evidence: policy historyInvestigate a harmless BEC or QR fixture, find similar messages, bulk move them, and show the final action log.
Evidence: exposed inboxes → zeroCan prevent delivery and modify the mail flow. Best when pre-inbox enforcement, banners, or link actions are required.
Fast post-delivery deployment and remediation for Microsoft 365. It is not pre-delivery blocking.
Analyzes message copies. Provider remediation requires the corresponding API integration.
Browser Isolation, DLP, CASB, and Logpush add capabilities but may require separate seats, roles, or entitlements.