Stop email threats before they become breaches.
MER stops the phishing and BEC your gateway was never built to catch, and triages what gets through — so your team is not the first line of defence.
90 secondsNo signup to startRead-only, no agents
The problem
Everyone breached by email already owned an email security tool.
The gap is almost never detection capability. It is authentication left half-finished, a triage queue nobody owns, and takeover discovered days late.
// p=none
DMARC configured to watch spoofing, not stop it
Below p=reject, anyone can send mail that appears to come from your domain — to your staff, customers and suppliers. Parked and secondary domains are the ones always forgotten, and the ones attackers pick.
// the queue
Quarantine releases and phishing reports eating the week
Slow releases train users to route around security. Unread phishing reports mean live campaigns sit in a queue while they are still running. This is the workload that quietly consumes a small security team.
// hours, not minutes
Account takeover found after the inbox rules were created
A compromised mailbox becomes an internal phishing platform within hours, and internal mail never passes your gateway. Containment measured in hours instead of minutes is the difference between one victim and a supplier-wide incident.
The programme
What MER actually does
Six capabilities delivered as one managed outcome.
Email threat protection
AI-driven detection in front of and inside the mailbox — phishing, business email compromise, spoofing, malicious links and attachments.
- Phishing, BEC and spoofing prevention
- Safe links and safe attachments
- AI-driven detection across internal and inbound mail
- Hybrid support for cloud and on-premises Exchange
Identity protection at the email layer
Account compromise detected and contained without waiting for an analyst.
- Account takeover detection
- Automatic containment of compromised accounts
- Impossible-travel, forwarding-rule and OAuth-grant signals
Email data protection
Data loss prevention enforced where data actually leaves — the outbound message.
- DLP policy enforcement
- Encryption and sensitivity handling
- Outbound anomaly detection
Email posture management
The configuration layer that most organisations never finish.
- SPF, DKIM and DMARC lifecycle — p=none → quarantine → reject
- Anti-phishing and anti-malware policy hardening
- Continuous misconfiguration audit via SaaS security posture management
- Sending-source validation and forensic DMARC reporting
Threat monitoring & response
Visibility plus the operational work, not just the dashboard.
- Consolidated quarantine view
- Monthly threat and posture reporting
- Threat triage and incident visibility
SaaS & collaboration security
Protection extended past the inbox to where payloads are actually shared.
- Teams, SharePoint and OneDrive coverage
- Detection of compromised users and business partners
- Collaboration-layer file and link inspection
Add-ons
Extend MER where it matters most to you
Added to the core programme, priced separately, and only worth taking if they solve something you actually have.
Incident Response as a Service (IRaaS)
Vendor analysts handle every end-user quarantine restore request and phishing report on your behalf, 24/7. This exists specifically to remove the ticket queue from your team.
Security awareness assessment & training
AI-driven realistic phishing simulation with training targeted by measured user risk — who clicks, who reports, who is high-risk — rather than distributed evenly across a population where risk is not.
Threat intelligence — credentials & domains
Dark-web and breach-database monitoring for exposed emails, passwords and tokens, plus lookalike domain detection and alerting on newly registered suspicious domains.
Email archiving (up to 10 years)
Business continuity, regulatory records management, legal discovery and chain-of-custody — plus recovery of mail deleted by users or lost to technical failure.
At a glance
What’s included
The commercial and technical shape of the programme, before you talk to anyone.
| Platform coverage | Microsoft 365, Google Workspace, hybrid and on-premises Exchange |
| Deployment | API-based. No MX record change, no mail-flow cutover |
| Baseline | Email Exposure Assessment — scored report within 48 hours of access |
| Trial path | 30-Day Email Protection Activation with before/after scoring |
| Cadence | Continuous protection, monthly reporting, monthly posture improvement |
| Ideal size | 100–1,000 users on Microsoft 365 or Google Workspace |
| Guarantee | 90% reduction in measured email exposure score in 90 days — see terms |
This is a good fit if…
- 100–1,000 users on Microsoft 365 or Google Workspace
- Phishing or BEC attempts already reaching people
- A security or IT team absorbing quarantine and phishing-report triage manually
- DMARC stuck at p=none, or configured on the primary domain only
If none of these describe you, MER probably is not your priority — and we would rather tell you that than sell it. Run the free assessment on a different surface and see where your score is actually worst.
The fair questions
No. MER deploys through API integration with Microsoft Graph or the Google API using read and enforcement permissions. There is no mail-flow cutover, which means no delivery risk during rollout and no rollback plan required.
E5 gives you capable filtering. MER adds three things E5 does not: internal mail visibility for already-compromised mailboxes, completed authentication posture across every sending domain including parked ones, and the human operational work — triage, releases, containment — that consumes your team’s week.
Read-only API access for a scored review of your email security configuration, anti-phishing policy strength, authentication records across all domains, data-protection controls and high-level audit signals. Data collection takes 0–4 hours, analysis 24–36 hours, and findings are delivered within 48 hours as a 45–60 minute executive session — risk, impact, fix. Not a technical dump.
Find out where you stand on email — in 90 seconds.
Eight questions, a score, and your top three exposure factors. If you want the real number, the full assessment reads your actual environment: read-only, no agents, 48 hours to a report.
90 secondsNo signup to startNo agents, read-onlyNo obligation