How Phishing Bypasses Email Filters and How to Protect Your Organisation

A new phishing campaign in 2026 is bypassing traditional email security systems by mimicking real quarantine alerts sent from compromised business accounts. These emails are tricking users into clicking on malicious links and entering login credentials. Unlike typical spam, this attack uses trusted sources, urgency-based messaging, and clever social engineering to appear completely legitimate. Organizations need to act fast by enabling MFA, training employees, updating email filters, and verifying internal communication requests to stay protected.

Jul 05, 2025 - 15:00
Updated: 7 days ago
105.5k
How Phishing Bypasses Email Filters and How to Protect Your Organisation

Quick answer: Phishing bypasses email filters when it is sent from a real, compromised business account, has a clean domain reputation, and carries no malware, only a link to a fake login page that activates later. SPF, DKIM and DMARC pass because the sender is genuine. Defend with phishing-resistant MFA, link rewriting at click time, conditional access, reporting buttons and quick account takeover response.

Key takeaways

  • Filters judge sender reputation, authentication and known-bad content. A hijacked real account passes all three.
  • The usual lure is a fake quarantine, password-expiry or shared-document alert that links to a credential-harvesting page.
  • Delayed or conditional activation lets the page look clean when scanned and malicious when a person clicks.
  • Phishing-resistant MFA (passkeys, FIDO2 keys) is the strongest single control, because a stolen password alone is no longer enough.
  • Treat every reported phish as a possible compromised partner and tell them quickly.

How does this kind of phishing work?

The attacker first takes over a genuine mailbox at one organisation, often through an earlier phishing success. From that account they email that company's contacts: customers, vendors, colleagues. The message looks like a Microsoft 365 or Google Workspace notice such as "You have 5 messages in quarantine" or "Your password expires today". The button opens a page that copies the real sign-in screen and passes the credentials to the attacker.

We are describing a pattern that security vendors and CERTs have reported repeatedly, not one named campaign. We have not tied this page to a single sample or actor, so treat the details as typical behaviour to test against your own mail logs.

Why do email filters miss it?

ControlWhat it checksWhy a hijacked account passes
SPF, DKIM, DMARCWhether the sending server and domain are authorisedThe mail really comes from that domain's own mail system
Reputation filtersHistory of the domain and IPA trusted business domain has a clean record
Attachment sandboxingMalicious filesThere is no attachment, only a link
URL scanningWhether a link is known bad at deliveryThe page is new, hosted on a legitimate service, or switched on later
Awareness trainingWhether the user spots odd wordingThe wording copies the real vendor notice and the thread may be genuine

What are the warning signs?

  • A "system" notice that arrives from an external person's address, not from your own IT tool.
  • Urgency about a deadline, quarantine or account closure.
  • A link whose real destination, shown when you hover, is not your sign-in domain.
  • A sign-in page that appears after a redirect, or asks for your password again right after you just signed in.
  • A reply-chain email that suddenly changes tone or asks for credentials or payment details.

How to protect your organisation

  1. Use phishing-resistant MFA. Passkeys and FIDO2 security keys bind the login to the real website, so a fake page cannot reuse them. SMS codes and push approvals can be relayed by attacker proxies.
  2. Add conditional access. Require managed or compliant devices and block risky sign-ins from unusual locations.
  3. Rewrite and re-scan links at click time, not only at delivery.
  4. Publish DMARC at enforcement for your own domain so attackers cannot spoof you, and add external sender banners.
  5. Give staff a one-click report button and thank them for using it, even for false alarms.
  6. Hunt for sign-ins and inbox rules. Attackers often create hidden forwarding or delete rules. Alert on new rules and impossible-travel logins.
  7. Prepare a takeover playbook: reset the password, revoke sessions and tokens, remove rogue rules, check sent items and notify the affected partners.
  8. Train with realistic exercises built from your own incidents, and measure reporting speed, not only click rate.

What if someone already entered their password?

Act within minutes. Reset the password from a clean device, revoke all active sessions and refresh tokens, and check the mailbox for new forwarding rules and sent items. Review audit logs for the hours after the click. In India, serious incidents can be reported to CERT-In. The MITRE ATT&CK framework lists phishing and valid-account techniques that help you map detections.

Common mistakes

  • Believing a passing SPF, DKIM and DMARC result means an email is safe. It only proves who sent it, not whether they are trustworthy.
  • Training users to "check the sender" when the sender is real.
  • Relying on SMS or push MFA for high-risk accounts.
  • Not warning the compromised partner, which lets the same account keep phishing others.

Related reading: spear phishing examples and prevention, AI-generated phishing emails and social engineering countermeasures.

Next steps

Next steps: to learn how defenders detect and respond to this, see our SOC Analyst course, and read about spear phishing prevention.

Frequently Asked Questions

It usually comes from a real, compromised account on a trusted domain, so SPF, DKIM, DMARC and reputation checks pass. There is no malware to detect, only a link, and the fake login page may activate only after delivery scanning.

They prove the message was sent by an authorised server for that domain. They do not prove the mailbox owner is honest. If an attacker controls a real mailbox, authentication results all pass.

It is a phishing message posing as a Microsoft 365 or Google Workspace alert, claiming messages are held or an account will be disabled. The link opens a fake sign-in page that steals your username and password.

Phishing-resistant MFA such as passkeys and FIDO2 keys does. SMS codes and push approvals are weaker because attacker proxy pages can capture or relay them in real time. Use strong MFA for admins and finance staff first.

Do not enter more details. Report it to your security team, change the password from a clean device, sign out all sessions and check for new mailbox rules. Time matters, so do this within minutes.

Check the full address in the browser bar before typing. Real sign-in happens on the vendor domain. Be wary if you arrived via an email button, a redirect or a page that asks for credentials again. Use a password manager, which will not autofill on a fake domain.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.