Email Security

Beyond the Email Gateway: Why Your Inbox is the Wrong Place to Fight Phishing

Dec 26, 2025 10 min read Secto Research

For decades, the corporate approach to cybersecurity has relied on a simple medieval concept: the castle and moat. We build strong perimeter defenses: firewalls, antivirus, and, crucially, Secure Email Gateways (SEGs) to keep the bad things out. We assume that if we scan every incoming email for malicious attachments and known bad links, our users are safe.

That assumption is now arguably the single biggest vulnerability in modern enterprise security.

The uncomfortable reality is that while organizations have poured billions into email perimeter defenses, phishing remains the primary entry point for data breaches (accounting for nearly 90% of them by some estimates).

If the tools are so expensive and widely deployed, why are they failing? The answer lies in a fundamental shift in attacker methodology. Today's most damaging attacks don't try to smash down the castle gate. Instead, they use legitimate credentials to walk right past the guards, disguised as trusted insiders.

The Failure of the "Signature-Based" Mindset

Secure Email Gateways (SEGs) are excellent at solving yesterday's problems. They rely heavily on threat intelligence feeds, databases of known malicious IP addresses, malware signatures, and blacklisted URLs.

If an attacker sends a 2018-era piece of ransomware from a Russian IP address containing a known bad hash, the SEG will catch it every time.

But modern attackers are agile. They spin up fresh, clean infrastructure for every campaign. They use polymorphic malware that changes its signature with every iteration. Most importantly, they have shifted away from malware delivered via attachments to credential harvesting delivered via social engineering.

SEGs are designed to look for "bad things." They are functionally incapable of detecting "bad intent" hidden within "good things."

How Advanced Phishing Bypasses the Gateway

Today's sophisticated threat actors, from nation-states to financially motivated ransomware gangs, have developed a playbook specifically designed to evade automated analysis.

1. Living Off Trusted Infrastructure (LOTI)

Why would an attacker register a suspicious-looking domain like paypalsafe-support.com when they can just use the real thing?

In LOTI attacks, hackers abuse legitimate, high-reputation cloud services to deliver their payloads. An attacker will compromise a legitimate Microsoft 365 tenant, create a malicious file hosted on SharePoint or OneDrive, and send a perfectly legitimate-looking sharing notification to the target.

The Bypass: When the SEG scans the incoming email, it sees a link to microsoft.com or sharepoint.com. These domains have impeccable reputations and cannot be blocked without crippling business operations. The SEG lets the email through. The malicious action only happens after the user clicks the link and interacts with the file on the legitimate platform.

2. The Adversary-in-the-Middle (AiTM) Attack

This is currently the most dangerous technique in the phishing landscape because it renders standard Multi-Factor Authentication (MFA) useless.

In an AiTM attack, the hacker uses tools like Evilginx to set up a transparent reverse proxy server. They send a phishing email directing the user to this proxy. The proxy displays the real, live login page of the target organization (e.g., their actual Microsoft 365 login screen).

As the user enters their credentials and their MFA code, the proxy sits in the middle, forwarding those details to the real website in real-time.

The Bypass: The SEG sees a link that doesn't match known blacklists. Crucially, the attack doesn't steal just a password; it steals the session cookie generated after a successful MFA check. The attacker replays this cookie into their own browser and instantly gains access to the victim's account, bypassing the need for a password or MFA. SEGs cannot inspect real-time web traffic flows occurring outside the email itself.

3. "Quishing" (QR Code Phishing)

Attackers are embedding malicious links inside QR codes in emails, often disguised as mandatory HR policy updates or 2FA reset requests.

The Bypass: Most email security tools are designed to scan text and analyze hyperlinks in the body of an email. They often lack the Optical Character Recognition (OCR) capabilities to scan images for QR codes and unfurl the embedded URLs. Furthermore, when a user scans a QR code, they almost always do it with a personal mobile device, moving the attack entirely outside the protected corporate network and onto an unmanaged, unsecured device.

4. Pure Social Engineering (BEC)

Business Email Compromise (BEC) attacks often contain zero payload: no links, no attachments. They are simply text messages using urgency, authority, and psychological manipulation to trick an employee into rerouting a wire transfer or buying gift cards.

The Bypass: Without a malicious link or attachment to signature, there is nothing for a traditional SEG to flag. While some advanced gateways use Natural Language Processing (NLP) to detect urgent requests related to finance, attackers easily circumvent this by moving the conversation out of email immediately (e.g., "I'm in a meeting, send me your cell number so I can text you the details").

Example of phishing email bypassing email gateway

The Solution: Secto's In-Browser Defense

This is where Secto.io changes the game. Recognizing that the email gateway is no longer sufficient, Secto moves the defensive line to the only place where the attack can be truly analyzed: the user's browser.

When a user clicks a link in a phishing email, even one that slipped past their email filter, the Secto browser extension springs into action. It analyzes the destination page in real-time, looking for tell-tale signs of advanced phishing, such as Adversary-in-the-Middle (AiTM) proxying. Before the malicious page can even load or capture any data, Secto blocks access and displays a clear warning to the user.

Secto blocking AiTM phishing attempt with warning

The Result: A Secure and Resilient Workspace

By shifting the focus from perimeter defense to point-of-click protection, Secto provides a critical layer of security against the most dangerous modern threats. It doesn't matter if a phishing email bypasses your gateway; Secto ensures that the attack is stopped at the browser, the very moment it matters most.

Secto secure workspace dashboard

This approach provides organizations with the peace of mind that comes from knowing their users are protected against advanced attacks like AiTM, credential harvesting, and zero-day phishing campaigns.

In a world where email security is no longer enough, Secto.io offers the intelligent, browser-based protection your organization needs to stay ahead of the attackers. Don't just filter your email. Secure your browser.