SUPPORTING BUSINESSES · MON–FRI 9:00AM–6:00PM
Managed IT & Business Support · Phoenix, AZ ☎ (866) 504-9998

Blog / Phishing & Email Security

How phishing emails get past the spam filter — and what stops them

July 10, 2026 · ioLogik Team

"But we have a spam filter." We hear it every time we clean up after a phishing incident. And it's true — Microsoft 365 and Google Workspace both filter enormous amounts of junk before it ever reaches an inbox. So why does the fake invoice, the "your password expires today" notice, or the email from the "CEO" still land? Because modern phishing is engineered, specifically and skillfully, to beat that filter.

Why the filter misses

Spam filters are largely reputation and pattern machines: they block senders, domains, and content that look like known junk. Phishers know this, so they avoid looking like known junk:

  • Clean, brand-new domains. A domain registered last week has no bad reputation yet. Attackers burn through fresh domains faster than blocklists can catch up.
  • Real services as the delivery vehicle. The link points to a file on a legitimate cloud service — a shared document, a form, an e-sign request. The domain in the link is genuinely trustworthy; the trap is on the page behind it. Filters that judge links by domain reputation wave it through.
  • Compromised real mailboxes. The most convincing phish comes from an actual vendor or colleague whose account was taken over. It passes every authenticity check — because it is authentic. Only the intent is fake.
  • No link, no attachment, no payload. Business email compromise (BEC) messages — "Are you at your desk? I need you to handle a payment" — contain nothing a filter can detonate or scan. Just text and social pressure. These plain-looking emails drive some of the largest business losses of any cybercrime.
  • Low volume, high targeting. Mass spam gets caught because millions of copies create a pattern. A phish crafted for five people at one Phoenix company — using names and details from LinkedIn or a hacked vendor thread — has no pattern to match.

None of this means your filter is broken. It means the filter is one wall, and attackers have learned to walk around it rather than through it.

What actually stops modern phishing

No single product stops it. A short stack of overlapping layers does — each one catching what the previous layer missed:

1. Email security beyond the built-in filter

Dedicated email protection goes past sender reputation into behavior: does this message ask for credentials or payment? Does the display name match the real sender history? Is this the first time your organization has ever received mail from this domain? Modern tools flag look-alike senders, banner-warn on unusual requests, rewrite and re-check links at click time (not just at delivery), and let employees report a suspicious message in one click — pulling identical copies out of everyone else's inbox at the same time. We deploy and manage this as part of our managed cybersecurity service, alongside Microsoft 365 tenant protection that watches for the account-takeover half of the problem.

2. DNS filtering — neutralizing the click

Some phish will always get through to an inbox, and someone will eventually click. Protective DNS turns many of those clicks into dead ends: the look-alike login page never loads because the lookup for the malicious domain simply gets no answer. We wrote a full explainer on how DNS filtering works — it's the cheapest layer in the stack and the perfect complement to email security.

3. MFA — devaluing the stolen password

The goal of most phishing is a password. Multi-factor authentication means a phished password alone doesn't open the door. It isn't bulletproof — attackers increasingly phish the MFA prompt too — but paired with the layers above, it turns most successful phishes into non-events.

4. Trained, unembarrassed humans

Technology reduces the flood to a trickle; people handle the trickle. Two habits matter more than any training video: verify unusual requests through a second channel (a payment-detail change gets a phone call to a known number — every time, no exceptions), and make reporting safe. An employee who clicked and says so within five minutes is your best security asset; one who stays quiet out of embarrassment is how incidents become breaches.

5. EDR — the layer behind the layers

If a phish delivers malware instead of harvesting a password, endpoint detection and response catches the behavior on the machine itself. That's a bigger topic — see why your business needs EDR and MDR.

The takeaway

If your email defense is "the spam filter that came with Microsoft 365," you're defending against the phishing of ten years ago. The current version is targeted, patient, and filter-aware — and stopping it takes layers: smarter email security, DNS filtering, MFA, reporting culture, and EDR behind it all.

Every layer above is included in our managed cybersecurity service and our managed IT plans. Talk to ioLogik — we'll tell you honestly which layers you're missing.