News Date: 2026-09-17
Microsoft's latest email-security benchmark offers an important reminder for security leaders: successfully scanning a message at the gateway does not mean the message will remain trustworthy after it reaches an inbox.
Measuring What Defenses Miss
Microsoft's quarterly analysis covers activity observed from May through July 2026. Rather than focusing on the total number of malicious messages blocked, the company measures high-severity threats missed per 1,000 protected users. Microsoft says this approach reduces distortions caused by differences in customer size and threat volume.
According to the published results, Microsoft Defender missed 221 high-severity threats per 1,000 protected users, approximately 55 percent fewer than the next-closest secure email gateway vendor evaluated. Microsoft also reported that Defender identified 92 percent of malicious messages caught during post-delivery analysis.
These are vendor-published measurements and buyers should examine the methodology before making procurement decisions. Nevertheless, the underlying trend matters: missed threats have increased across several reporting periods, including for Microsoft. The company associates part of that increase with attackers using AI to collect public information, refine impersonation attempts and create better-written lures.
Email Security Is Becoming Continuous
A message that appears harmless at 9 a.m. may be identified as malicious later when new indicators, related domains or campaign patterns become available. Post-delivery detection allows a security platform to reassess the message and remove it after initial delivery.
Microsoft says its benchmarking has influenced several defensive changes:
- Expanded controls for promotional and bulk messages
- Redesigned machine-learning and natural-language processing models
- Continuous reevaluation and remediation of delivered email
- Prompt-injection detection for messages accessed by Copilot and other AI systems
What Security Teams Should Take Away
In my view, organizations should stop treating the email gateway as a complete security boundary. Modern email defense requires pre-delivery inspection, post-delivery reassessment, identity monitoring, endpoint visibility and rapid account containment.
Teams should measure credential submission, session compromise and reporting behavior instead of relying exclusively on click rates or blocked-message totals. They should also test how quickly malicious messages can be removed after delivery and whether compromised identities are automatically contained.
The emergence of AI agents that read and act on email adds another concern. A malicious message may target not only an employee but also an automated assistant. Email controls must therefore evaluate whether content contains instructions designed to manipulate software, trigger unsafe actions or expose data. Continuous analysis is becoming essential because both the attacker and the recipient may now be automated.
