Microsoft 365

Email security in front of Microsoft 365

MailThreatZero sits at your MX record and scans inbound mail before Exchange Online accepts it. Your tenant, your mailboxes and your licensing stay exactly as they are. Defender stays on.

Priced per protected domain, not per mailbox. A tenant with 4 users and a tenant with 400 cost the same to protect.

What actually changes

Three things, and only three.

  1. Your MX record points at mt0.mailthreatzero.com instead of at your-domain.mail.protection.outlook.com. Mail arrives here first.
  2. An inbound connector in Exchange Online accepts mail from the gateway, so filtered mail lands in the right mailboxes.
  3. Your tenant is locked to that path, so mail cannot be delivered straight to Microsoft around the filter.

Nothing is installed, no mailbox is migrated, and no Microsoft license changes. Mail delivery to your users looks the same to them on the day of the switch.

The two settings most gateway deployments get wrong

Both of these are invisible until after cutover, and both make a gateway look like it is working while it quietly is not. The console generates the exact steps for your tenant, with the values filled in, at the point you connect a domain.

Enhanced Filtering for Connectors

Put any gateway in front of Exchange Online and Microsoft starts seeing every message as coming from the gateway rather than from the real sender. SPF is then evaluated against us, so it fails for almost everything, and DMARC fails with it. Enhanced Filtering tells Microsoft to look past the gateway to the true source.

Skip this and your authentication results become noise — on both sides of the handover.

Locking out direct delivery

Pointing MX at a gateway does not stop anyone delivering straight to your-domain.mail.protection.outlook.com, and your published MX history tells an attacker exactly where to aim. Until the tenant is told to accept inbound mail only from the gateway's addresses, filtering is optional for anyone who knows to skip it.

The setup guide includes the connector restriction and the gateway addresses to allow.

Keep Defender

We do not ask anyone to turn Microsoft off. Defender is already paid for inside your subscription and telling you to stop using it would be a poor argument.

The case for a second layer is not that the first one is bad. It is that two engines built by different people, on different data, disagree — and the disagreement is where you learn something. A message Microsoft delivered and this gateway would have held is a data point about your own mail, not a marketing claim about ours.

We do not claim to catch what Microsoft misses. We have not measured that, and neither has anyone who tells you otherwise without showing you the sample. The longer version of this argument is on the comparison page.

Why per-domain matters on Microsoft 365

Microsoft licenses per user, and so does almost every add-on sold alongside it. A customer who hires ten people gets ten more bills. MailThreatZero charges for the domain: $39 per protected domain per month for partners, for every account, with up to 250 mailboxes on every protected domain.

For an MSP that is the difference between a margin you can predict and a margin that moves every time a customer's headcount does. Rates and a calculator.

What we use the Microsoft API for — and what we do not

Mail does not travel through Microsoft Graph. It arrives over SMTP and it leaves over SMTP. Graph is used for three things, each one separately authorized by you:

Verifying your tenant before cutover
Confirming the connector, the accepted domain and the routing are right, so the switch is not the moment you find out they are not.
Finding and removing delivered copies
When a message turns out to be malicious after it was delivered, searching the tenant for every copy and moving them out. This needs a write permission that is granted separately from read, and it is never granted by an upgrade.
Account risk telemetry
Sign-in logs, Entra's own risky-user verdicts, and inbox rules quietly forwarding mail to an outside address. Read-only, off until you switch it on per domain, and the console shows you which sources answered rather than presenting an empty result as an all-clear.

Post-delivery removal against a live Microsoft 365 tenant is implemented and tested against the API, but has not yet been exercised on a production customer tenant. We would rather tell you that than let you find out.

Trying it without switching anything

Monitor Mode runs the full pipeline on one domain's real traffic and records what it would have done, without changing a single delivery. After a couple of weeks you are comparing verdicts on your own mail rather than reading anyone's numbers.

Talk to us about a trial domain See how a message is scored