Email Security
Cloudflare Email Security (built on the former Area 1 platform) hunts phishing campaigns before they are launched and blocks the messages that slip past Microsoft 365 and Google Workspace defaults — including the payload-free fraud emails that cause the largest losses.
Overview
Email remains the front door of most breaches, and the most expensive attacks often contain no malware at all: business email compromise (BEC) messages impersonate an executive or supplier and simply ask an employee to pay an invoice or change bank details. Signature-based filters have nothing to detect in such messages, which is why they keep landing in inboxes protected only by platform defaults.
Cloudflare Email Security takes a preemptive approach: it continuously crawls the web and attacker infrastructure to discover phishing campaigns as they are being staged — domains registered, kits deployed — often before a single message is sent. Combined with content analysis tuned for social engineering, it functions as a second, independent layer over your existing mail platform.
Key capabilities
- Preemptive discovery of attacker infrastructure and phishing campaigns, frequently ahead of launch
- BEC and impersonation detection: display-name spoofing, lookalike domains, supplier fraud and thread hijacking
- Link protection with time-of-click evaluation, defeating URLs weaponised only after delivery
- Attachment analysis including sandbox detonation of suspicious files
- Deploys in minutes via API integration with Microsoft 365 and Google Workspace, or inline as an MX-based gateway
- Automatic retraction of messages judged malicious after delivery (API deployment)
- SPF/DKIM/DMARC evaluation and spoof protection for your own domains
- Detection analytics, phish submission workflow, and integration with your SOC tooling
How it works
The platform's distinguishing mechanism is what happens before any email arrives: crawlers and sensors map phishing kits, lookalike domains, and campaign infrastructure across the internet, feeding an intelligence base of attacks in preparation. When a message later arrives referencing that infrastructure, the verdict is already known.
Each message is then analysed on its own merits: sender authentication (SPF/DKIM/DMARC) and sending-infrastructure reputation, language patterns typical of urgency-and-payment fraud, relationship context (is this "CEO" address one your CFO has ever actually corresponded with?), links resolved through redirect chains, and attachments detonated in sandboxes where warranted.
Deployment is flexible. API mode connects to Microsoft 365 or Google Workspace and removes malicious mail from inboxes — including retroactively — without touching mail routing; it can be live in under an hour. Inline mode puts the service in the MX path so mail is filtered before your platform ever sees it. Many organisations start with API mode for a zero-risk evaluation of what their current stack misses.
Plans & licensing
Email Security is licensed per mailbox, separately from CDN/WAF zone plans — typically as part of an Enterprise agreement or a Zero Trust bundle. It is not included in Free/Pro/Business zone plans. As of 2026, subject to change — confirm current packaging and per-mailbox pricing with us.
Deployment with Integrity
As a certified Cloudflare partner for Central and Eastern Europe, Integrity delivers this product end to end — including a free pilot so you see results on your own traffic before committing. A typical rollout:
- Assessment. We review your mail platform, current filtering, DMARC posture and any recent phishing or fraud incidents.
- Free pilot. API-mode integration with Microsoft 365 or Google Workspace goes live in under a day, in detection-only mode — after two to four weeks you see exactly what your current defences missed, with zero mail-flow risk.
- Policy decisions. Based on pilot data we agree dispositions: what is quarantined, what is tagged with warning banners, what is retracted automatically.
- Enforcement. Chosen actions are enabled; SOC/helpdesk workflows for user-reported phish and false positives are set up.
- Domain hardening. In parallel we bring your own domains to DMARC enforcement so others cannot spoof you.
- Handover or managed service. Your team operates it with our documentation, or Integrity monitors and tunes detections ongoing — request the free pilot.
Ready to start? Contact us to arrange the free pilot.
FAQ
We already have Microsoft Defender for Office 365. Is this redundant?
They overlap but are not equivalent. The preemptive campaign intelligence and BEC-focused analysis regularly catch messages platform-native filtering passes — which is precisely what the detection-only pilot measures for your real traffic before you spend anything.
Does deployment risk disrupting our email?
API mode changes nothing about mail routing — messages flow exactly as today, and the service removes bad ones after arrival. Inline (MX) mode does change routing and is rolled out with staged cutover and rollback; many customers simply stay on API mode.
Can it stop invoice fraud coming from a supplier's genuinely compromised mailbox?
This is the hardest case — the sender is real and authenticated. Detection relies on content and context signals: changed bank details, unusual urgency, deviation from the historical relationship. It materially raises the catch rate, and we pair it with process controls (out-of-band verification for payment changes) in our recommendations.