Spam, Virus, Malware & Ransomware Protection
GravIT filters your business email with MailGuard, the Australian cloud email security service, before anything reaches your staff, blocking spam, viruses, malware and ransomware, with redundant mail infrastructure and outbound monitoring so your own domain never ends up blacklisted. Set up and managed by our Geelong team.
What actually turns up in your inbox
Not one problem but eight, each stopped by different things, which is why “we have a spam filter” is not the same as being protected.
Phishing
A convincing request for a login. Usually your own Microsoft 365 sign-in page, copied well enough that nobody looks twice at the address bar.
Invoice fraud
A real supplier, a real invoice, and new bank details. The most expensive thing on this list, and the hardest to catch (see below).
Ransomware
An attachment or a link that starts the sequence. By the time anything is encrypted the intruder has usually been in for weeks.
Someone sending as you
Your domain used to invoice your own customers. You find out when they ring, angry, about an email you never sent.
Malicious links
The message is clean on arrival and the link is armed later, which is why scanning once at delivery is not enough on its own.
QR codes in attachments
A code in a PDF instead of a link. There is no URL for a scanner to check, and the victim finishes the journey on a phone that your controls never see.
Callback scams
An invoice with a phone number and no link at all. Nothing to scan, because the actual attack happens once somebody rings the number.
Ordinary spam
Not dangerous, just relentless. The real cost is the genuine email that gets missed in the noise.
Notice how many of the recent ones carry nothing to scan. That is deliberate on their part, and it is why the answer has to be layers plus people rather than one clever filter.
What happens to a message before you see it
Filtering sits in front of Microsoft 365 or whatever you use, rather than replacing it. Every inbound message goes through this before it reaches anyone.
Where did it come from?
Sender and source reputation is checked against real-time blocklists (RBLs) before the content is even considered, and we tune the rules ourselves for what is actually landing on Australian businesses, rather than raising a ticket offshore and waiting.
More than one opinion
Several detection methods look at the same message rather than one: reputation, heuristics, machine learning, and dedicated engines hunting the malicious links inside it. One method's blind spot is another's catch, which is the whole argument for layering.
What is attached to it?
Executables and the file types that carry ransomware are stopped outright. Archives are unpacked and inspected recursively, because “a zip inside a zip inside a zip” is a very old trick that still works on filters which only look at the outside.
Delivered, or held
Clean mail goes through untouched. Anything questionable is held rather than silently binned, so it can be released if we got it wrong.
And if something breaks
The filtering runs on a geographically dispersed, load-balanced mesh rather than a single point of failure, and it is backed by a 100% delivery and uptime service level with rebates if it is ever missed. If something upstream is unavailable, mail waits and delivers when service resumes. It does not bounce and it is not lost.
There is a sixth step running the other way. Outbound mail is scanned too, for viruses, for spam coming from a compromised account, and against content rules about what is allowed to leave. If one of your mailboxes is taken over and starts sending, it is caught before your domain lands on a blocklist and your legitimate email quietly stops arriving anywhere.
What's included
- Multi-engine inbound scanning
- Reputation, heuristics and ML
- Rules we tune ourselves
- 100% delivery SLA
- Suspicious attachment detection
- Held, not silently deleted
- Redundant, queuing mail servers
- Outbound monitoring
- SPF, DKIM and DMARC set up properly
Stopping people sending as you
Filtering protects what arrives. None of it stops somebody putting your business name on an email to your customers. That is a different problem with a different fix, and it is three DNS records rather than a product.
SPF
A published list of who is allowed to send email on your behalf. Anyone else is an impostor, and receiving mail servers can see that.
DKIM
A cryptographic signature on every message you send, so the receiver can confirm it really came from you and was not altered on the way.
DMARC
Your instruction for what to do when a message fails those checks, plus reports telling you who is trying. This is the one most businesses have never set.
Worth doing carefully, not quickly
These three are free, and they are also the fastest way to stop your own invoices reaching your customers if you get them wrong. Every legitimate sender needs to be accounted for first: your mail platform, your accounting package, your booking system, the mailing list nobody remembers signing up for. We inventory what actually sends as you, then tighten the policy in stages and watch the reports, rather than switching on enforcement and finding out from an angry client.
The one filtering cannot catch
Here is the uncomfortable part, and you will not often see a provider lead with it.
Your supplier's mailbox gets compromised. The attacker reads their sent items for a fortnight, learns how they write, waits for a real job to reach invoicing, and then replies on the genuine thread, from the genuine address, attaching a genuine-looking invoice with different bank details.
That one is close to unstoppable by content filtering alone, because there is nothing wrong with the email. No malware, no dodgy link, no spoofed domain, no reputation problem, just a real message from a real account that a criminal happens to be sitting in. Good filtering catches a great deal of business email compromise, and ours does: the impersonated domains, the lookalike addresses, the newly registered sender pretending to be your director. What it cannot reliably catch is the version where the account is genuinely theirs and genuinely compromised. Treat any vendor promising to stop all of it with suspicion.
What actually stops it
- A rule about bank details, not a judgement call. Any change to payment details gets verified by phone, on the number you already had for them, never the one in the email. Every time, no exceptions, regardless of how well you know them.
- Staff who have seen it before. The people in accounts are the target, and the ones who need to have met this scenario in training rather than for the first time on a Friday afternoon. That is what awareness training is actually for.
- MFA everywhere, so your mailbox is not the one being read for a fortnight in somebody else's version of this story.
Filtering removes the noise and stops the technical attacks, which is most of the volume and nearly all of the malware. The fraud that is left is a people-and-process problem, and pretending otherwise is how businesses get caught.
The rule worth writing down
Bank details never change on the strength of an email. Ring the number you already had.
Awareness trainingWhy email is still the biggest risk
Because it is where work arrives. Most ransomware and fraud starts as a convincing message, and it only takes one tired click on a Friday afternoon. The fix is not hoping staff never get a judgement call wrong. It is making sure far less ever reaches them, and that the few things which do are the ones a person is equipped to question.
We run this on MailGuard, which we recommend as part of a cyber security suite rather than as a standalone fix. It is Australian, it has done nothing but this since 2001, and we can tune the lists ourselves instead of raising a ticket offshore. It pairs with cyber security and Microsoft 365, with one team looking after the whole picture, so nobody gets to say the problem is somebody else’s layer.
Frequently asked questions
How does GravIT filter spam and malware?
We use MailGuard, an Australian cloud email security service that has specialised in this since 2001. Every message is assessed on sender reputation and then by several detection methods (heuristics, machine learning and engines that hunt malicious links) before it reaches your inbox, with executables blocked and archives unpacked and inspected recursively. GravIT sets it up, tunes the rules and manages it for you, so you deal with our Geelong team rather than an overseas vendor.
What happens to our email if a mail server goes down?
Nothing is lost. The filtering runs across a geographically dispersed, load-balanced mesh rather than a single point of failure, backed by a 100% delivery and uptime service level. If something upstream is unavailable, mail waits and delivers when service resumes rather than bouncing.
Can you stop our own domain being blacklisted?
Yes. We monitor outgoing mail too. If a compromised account or infected machine starts sending spam, we catch it before your domain lands on blocklists and your legitimate email stops being delivered.
Does this work with Microsoft 365?
Yes. It layers in front of Microsoft 365 rather than replacing it, and equally in front of Google Workspace, Exchange or Zimbra, adding filtering, redundancy and outbound scanning on top of what is built in.
What email security product do you use?
MailGuard, which we recommend as part of a cyber security suite rather than as a standalone fix. It is an Australian cloud email security service, operating since 2001, and it sits in front of your mail platform rather than replacing it. We chose it because it is proven, Australian, and we can tune the lists ourselves instead of raising a ticket offshore.
Will legitimate email get caught in the filter?
Occasionally, because no filter is perfect. Quarantined mail is easy to review and release, and locally managed lists mean we can whitelist a sender for you in minutes, not after a support ticket to an overseas vendor.
Email protection for your business inbox
We'll have filtering in front of your mail quickly, without changing how your staff work.