Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Best Antivirus for Stopping Phishing and Email-Borne Malware at Work

12 min read Updated October 4, 2026 Antivirus Comparisons

Fix it now

Filter at the mail service first and at the endpoint second, because anything blocked before delivery never reaches a user to be clicked. If you are on Microsoft 365 you already have Exchange Online Protection, and Business Premium includes Defender for Office 365 Plan 1. Turn on what you own before you buy anything else.

  1. Establish what your Microsoft subscription includes. Microsoft describes a protection ladder: built-in security for all cloud mailboxes, then Defender for Office 365 Plan 1 for zero-day malware, phishing and business email compromise, then Plan 2 for simulations, hunting and automation.
  2. If you are on Microsoft 365 Business Premium you have Plan 1, which carries Safe Attachments in email, Safe Attachments for SharePoint, OneDrive and Teams, Safe Links in email, Office clients and Teams, impersonation protection and real-time detections.
  3. Turn on multi-factor authentication for every mailbox, without an exception for directors. It is the single highest-value control here because it defeats most credential phishing outright.
  4. Publish SPF, DKIM and DMARC. Microsoft’s documented order is an SPF record using the soft fail rule first, then DKIM, then DMARC with the action for failures and the reporting destination.
  5. Choose an endpoint product on its mail handling, not its scanner. ESET Endpoint Security scans POP3, IMAP, POP3S and IMAPS by default regardless of the port and regardless of the email client, without reconfiguring the client.
  6. Fix invoice fraud with a rule, not a product: no change of bank details without a call to a number you already held. Business email compromise carries no attachment and no link, so no scanner sees it.

The layer nobody buys is the one that catches the rest: a reporting button and short, frequent training. Measure the reporting rate rather than the click rate, because the useful signal is how quickly somebody tells you.

If the Microsoft entitlement plus multi-factor authentication is the whole answer for you, stop here. Below is what each layer can actually stop, what to ask an endpoint vendor about mail, and where to spend next.

Why it happens

Most malware still arrives by email, and most successful attacks now arrive by email with no malware in them at all. That difference decides where the money should go. An endpoint product with mail scanning is a useful last line, but it is the last line, and expecting it to solve phishing is the most common mistake in small business security buying. The controls that stop credential theft sit further upstream, and several of them cost nothing.

The mail service layer inspects messages before they land: reputation, attachment analysis, link inspection at the moment of the click rather than at delivery, and impersonation detection. Microsoft describes this as a ladder, with built-in security for all cloud mailboxes preventing broad, volume-based, known email attacks; Defender for Office 365 Plan 1 protecting email and collaboration from zero-day malware, phishing and business email compromise; and Plan 2 adding phishing simulations, post-breach investigation, hunting, response and automation. Microsoft names Microsoft 365 Business Premium among the subscriptions that include Plan 1, which is why the first job is an audit rather than a purchase.

The endpoint layer inspects what arrives on the machine: the mail traffic as it is collected, the web request when somebody clicks, and the file when it is saved and run. It is your protection when mail reaches a machine through a channel the service layer does not cover, and it is the layer that catches the payload rather than the message. Then there are two layers that are not products at all – authentication, meaning multi-factor on the mailbox, and process, meaning a rule that no bank details change without a phone call to a known number. Those two stop the attacks with nothing malicious in them, which is the category that costs businesses the most money.

You are on Microsoft 365 and have never audited it

You have this one if Nobody can say which Defender for Office 365 features are switched on, or whether every account has multi-factor authentication.

  1. Confirm which plan you hold, then confirm which Plan 1 features are actually enabled: Safe Attachments in email and for SharePoint, OneDrive and Teams; Safe Links in email, Office clients and Teams; impersonation protection; real-time detections.
  2. Enable multi-factor authentication for every account before anything else, including the ones belonging to people who will complain.
  3. Only then decide whether you need to buy anything additional, and be able to name what it does that you do not already have.

You run your own mail server

You have this one if Exchange on your own hardware, with the endpoint agent as the only thing inspecting what it delivers.

  1. A mail server security product is the highest-value addition, because the endpoint cannot filter what the server has already delivered.
  2. ESET publishes ESET Mail Security for Microsoft Exchange as on-premises protection with anti-spam, anti-phishing and anti-malware, and ESET PROTECT Mail Plus for cloud mailboxes.
  3. Buying the mail layer from the same vendor as the endpoint means it can be added as a licence change later rather than a fresh procurement exercise.

Somebody keeps trying to change your bank details

You have this one if Plausible messages about updated payment information, with no attachment and no link to block.

  1. This is a process problem and no product line item will fix it. Write the rule: no change to bank details is actioned without a call to a number you already held, not a number in the message.
  2. Publish SPF, DKIM and DMARC so that other people cannot send mail appearing to come from your domain. Microsoft’s order is SPF with soft fail first, then DKIM, then DMARC.
  3. Make the rule apply to directors in a hurry, because that is the exact scenario it exists for.

The endpoint layer is still worth choosing carefully, because products differ more here than they do on detection. What separates them is whether mail scanning is a component you can enforce by policy or a browser extension a user can switch off, and whether the same vendor sells the upstream layer you may want later.

Full reference

Four layers, and what each one can actually stop

Layer Stops Misses Where it comes from
Mail service filtering Broad, volume-based known email attacks; with Plan 1, zero-day malware, phishing and business email compromise Anything sent from a genuinely compromised partner account Built in to Microsoft 365 mailboxes; Plan 1 included with Business Premium
Endpoint mail and web protection Malicious attachments once saved, and pages known to distribute phishing content when clicked The message itself, and any site not yet categorised Part of the endpoint licence you already need
Domain authentication (SPF, DKIM, DMARC) Other people sending mail as your domain Mail sent to you from lookalike domains DNS records and attention; no licence
Multi-factor authentication Credential phishing, because the password alone is no longer enough Session token theft and consent-grant attacks Included with most mail platforms
Payment verification process Invoice fraud and business email compromise Nothing technical; it is a human control Nothing but discipline
Reporting button and short training Repeat clicks, and it shortens time to detection The first person targeted with something genuinely new Modest, and worth it

What to ask about an endpoint product’s email handling

Four questions separate products meaningfully, and the answers are usually in the vendor’s own documentation rather than on the datasheet.

  1. Does it scan the mail protocols themselves rather than only the saved attachment? ESET, for example, documents that all communication over POP3 and IMAP is scanned by default regardless of the port, that IMAPS on 585 and 993 and POP3S on 995 are supported, and that this happens regardless of the email client used and without reconfiguring it.
  2. Is anti-phishing a policy-enforced component or a browser extension the user can disable? ESET publishes Anti-Phishing protection as a Web and email component that blocks web pages known to distribute phishing content, alongside Web access protection and Web control.
  3. Does it also filter mail in the client itself, and can antispam be managed centrally rather than per machine?
  4. Does the vendor sell a mail server or cloud mailbox product you could add later without changing endpoint vendor?

That last question is the one worth planning around. ESET publishes ESET Mail Security for on-premises Microsoft Exchange and ESET PROTECT Mail Plus for cloud mailboxes, so the upstream layer can be added as a licence change rather than a fresh procurement exercise, and the two report into a related place. It is not a reason to accept a worse endpoint product, but between two comparable ones it is a genuine tiebreaker.

Getting the domain records right, in Microsoft’s order

Microsoft publishes a sequence rather than a set, and following it avoids the usual outcome where DMARC is published before the legitimate senders pass and somebody’s newsletter stops arriving. Start by publishing an SPF record containing all the email sources you know about, particularly where your corporate traffic originates, using the soft fail enforcement rule. Then set up DKIM to digitally sign messages. Then set up DMARC to validate that the domains in the MAIL FROM and From addresses match, to specify what happens to messages that fail, and to identify the reporting services that will monitor the results.

The reason to do this is not your own inbox. Domain authentication stops other people sending mail that appears to come from you, which protects your customers, your suppliers and your reputation. It costs DNS changes and attention, and it is the cheapest thing on this page.

Where to spend, by situation

  • On Microsoft 365 already: enable and configure what you own before buying anything. Confirm which Defender for Office 365 features your subscription includes, turn on Safe Links and Safe Attachments, and switch on multi-factor authentication for every account.
  • Running your own Exchange server: a mail server security product is the highest-value addition, because the endpoint cannot filter what the server has already delivered.
  • Small business, mixed mail arrangements, no dedicated IT: an endpoint suite with policy-enforced mail and web filtering, plus multi-factor authentication, plus the domain records.
  • Repeated invoice fraud attempts: this is a process problem. Fix the payment verification rule first; no product line item will help.
  • Users clicking things regularly: add a reporting button and short, frequent training, and measure the reporting rate rather than the click rate.

What an endpoint agent will never do

It will not stop a well-written message asking somebody to log in somewhere. There is no attachment to scan and, if the page is new, nothing yet categorised to block. That is not a criticism of the product category, it is a description of where the control has to live: mail-service filtering, multi-factor authentication so the harvested password is insufficient, and a reporting habit so you find out in minutes rather than weeks. Buy the endpoint layer for what it is genuinely good at – the payload, the saved file, the known-bad destination – and put the phishing budget upstream.

When a licence is the actual fix

ESET PROTECT Entry is a sensible endpoint choice when email is your main concern, because the mail handling is part of the endpoint agent rather than an upsell: ESET documents POP3, IMAP, POP3S and IMAPS scanning that works regardless of the email client and without reconfiguring it, alongside Anti-Phishing protection, Web access protection and Web control as policy components. ESET also publishes Mail Security for on-premises Exchange and PROTECT Mail Plus for cloud mailboxes, so the upstream layer can be added later without changing vendor. Arco can supply and size it – and will say the unglamorous part plainly: if you are on Microsoft 365, audit what your subscription already includes and turn on multi-factor authentication before you spend anything, because those two steps stop more of this than any endpoint agent will.

Questions people ask about this

Will antivirus stop phishing emails reaching my staff?

Partly, and less than you would like. Endpoint anti-phishing blocks pages known to distribute phishing content at the moment somebody clicks, and mail protocol scanning catches malicious attachments. Neither stops a well-written message asking somebody to log in somewhere. That is what mail-service filtering, multi-factor authentication and a reporting habit are for.

We are on Microsoft 365. Do we still need endpoint mail protection?

You need endpoint protection regardless, because attachments get saved, files arrive on USB sticks and websites deliver payloads that never touched email. Whether you need additional mail-specific licensing depends on what your subscription already includes – Microsoft names Business Premium among the plans that include Defender for Office 365 Plan 1 – so establish that before buying anything extra.

What is the difference between Exchange Online Protection and Defender for Office 365?

Microsoft describes it as a ladder. The built-in protection for all cloud mailboxes prevents broad, volume-based, known email attacks. Plan 1 adds protection against zero-day malware, phishing and business email compromise, with Safe Links, Safe Attachments, impersonation protection and real-time detections. Plan 2 adds phishing simulations, post-breach investigation, hunting, response and automation.

Is DMARC worth the effort for a small company?

Yes, and it costs nothing but DNS records and care. It stops other people sending mail that appears to come from your domain, which protects your customers and your reputation rather than your own inbox. Follow Microsoft’s published order: SPF with the soft fail rule first, then DKIM, then DMARC with the failure action and the reporting destination.

What actually stops invoice fraud?

A rule, followed without exception: no change to bank details is actioned without a call to a number you already held, not a number in the message. Every technical control can be worked around by a message that contains nothing malicious. This one cannot, provided nobody makes an exception for a director in a hurry.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Free vs Paid Antivirus: What the Free Tier Quietly Leaves Out Review F-Secure Total vs Bitdefender Total Security: Privacy Tools Head-to-Head Review ESET vs Kaspersky for Business Endpoints: The Management Console Decides Review G DATA Internet Security vs Total Security: Is the Backup Worth It?
โ† Back to Knowledge Base