Post-delivery detection helps, but it leaves a window where the message is already in the user’s mailbox and exposure has already occurred. For external traffic that a gateway can inspect, stopping delivery reduces dwell time and click risk more effectively than remediation alone. The gap matters most when campaigns are novel, fast-moving, and designed to bypass user judgment.
Why This Matters for Security Teams
Relying only on post-delivery detection means the organisation is accepting exposure first and trying to contain it later. That approach can work for known malware, but phishing and business email compromise campaigns often succeed without a malicious attachment or obvious payload. The real risk is not just inbox placement, but the time window in which a user can read, trust, forward, or act on a message before containment happens. NIST Cybersecurity Framework 2.0 emphasises outcomes across governance, protect, detect, and respond, which is useful here because email security cannot be treated as detection alone. NIST Cybersecurity Framework 2.0 In practice, many security teams encounter BEC only after a payment request, payroll change, or mailbox rule has already been abused, rather than through intentional prevention at the point of delivery.
How It Works in Practice
Post-delivery detection is still valuable, but it should be one layer in a broader control stack. In modern phishing and BEC campaigns, the attacker often relies on legitimacy cues, urgency, and conversation hijacking instead of malware. That means mailbox search, user reporting, sender analytics, and retroactive takedown all help, but they do not remove the initial exposure. The operational goal is to shorten the time between message receipt and containment, while also reducing the chance that a user can interact with the message at all.
A practical programme usually combines several controls:
- Pre-delivery filtering for impersonation, spoofing, and suspicious infrastructure.
- Authentication checks such as SPF, DKIM, and DMARC, with policy enforcement rather than monitoring alone.
- Mailbox-level detection for anomalous forwarding rules, impossible travel, and unusual login behaviour.
- User reporting workflows that can trigger rapid hunt and purge actions across mailboxes.
- Identity controls on high-risk actions, such as step-up approval for payment changes or account recovery.
This is especially important because BEC often uses valid accounts, compromised tenants, or subtle social engineering that bypasses traditional signatures. Detection after delivery can still find the message, but it does not prevent the first read, the first reply, or the first credential submission. Teams should also map this problem to identity governance, because mailbox compromise is frequently the opening move for broader privilege abuse. Current guidance suggests that the strongest programmes treat email as an identity attack surface, not just a content-filtering problem. These controls tend to break down in Microsoft 365 or Google Workspace environments with weak authentication policy and inconsistent alert triage because the attacker can act before the SOC has enough context.
Common Variations and Edge Cases
Tighter pre-delivery filtering often increases false positives and admin overhead, requiring organisations to balance prevention against user disruption and operational latency. That tradeoff matters because a control that blocks too much can push users toward workarounds, while a control that blocks too little leaves the inbox as the first line of defence. Best practice is evolving here, especially for executive impersonation and low-volume, high-credibility BEC messages where the content is novel and signature-based detection is weak.
There are a few edge cases to watch. Internal phishing from a compromised account may evade gateway controls because the sender is already trusted. Mailbox rules that quietly redirect messages to attacker-controlled folders can defeat post-delivery monitoring unless identity telemetry is correlated with email telemetry. Vendor invoices, legal notices, and procurement messages also create ambiguity because they often resemble legitimate business traffic, which makes user judgment an unreliable control.
For those reasons, post-delivery detection should be treated as a recovery capability, not the primary barrier. The more the campaign depends on timing, trust, and a quick business action, the more expensive every minute of inbox exposure becomes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT | User awareness and response reduce damage when phishing reaches the inbox. |
Train users to report suspicious mail fast and pair that with containment playbooks.
Related resources from NHI Mgmt Group
- Why do non-email phishing campaigns increase enterprise risk?
- Why do AI-generated phishing campaigns increase risk for public-sector agencies?
- Why do polymorphic phishing campaigns increase identity risk as well as email risk?
- Why does legitimate service abuse increase the risk of phishing and malware delivery?