Secure email gateways see only traffic that reaches them
A mail filter inspects what routes through it, and there are usually paths that do not.
Internal mail between colleagues, messages delivered directly to the mail platform, calendar invitations, and anything arriving through another channel entirely. An attacker inside one mailbox sending to another may never cross the gateway at all, which is why internal messages deserve suspicion they rarely get.
More on Email security
- DKIM protects signed content against later modificationChange one word, break the seal
- DMARC depends on alignmentBoth names, or neither
- Forwarding can break email authentication assumptionsIt was re-posted on the way
- A display name is not an email addressThey wrote that name themselves
- Reply-chain hijacking borrows existing trustTrust borrowed from the thread
- Quarantine creates a second security decisionHeld is not decided
