ActiScan

Industry News

AI Is Now Fighting AI in the Inbox — Here's What That Means for MSPs

September 17, 2026

Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Two monitors on a dark desk showing email traffic on one screen and a filtering dashboard on the other

The inbox has quietly become a battlefield where both sides are running the same class of technology. Attackers use large language models to draft phishing lures with no typos and no awkward phrasing. Mailbox providers use their own machine learning models to catch those lures before a human ever sees them. Neither side invented this dynamic on purpose, but MSPs now have to operate inside it every day.

What does "AI vs AI in the inbox" actually mean?

It means the traditional cues security awareness training relied on, bad grammar, generic greetings, obvious spelling mistakes, no longer reliably separate real mail from fake mail. Attackers generate polished, personalized messages at scale using generative AI, while providers like Microsoft and Google now run their own AI models against every message to catch what the old rule-based filters miss. The contest has moved from text quality to metadata, behavior, and infrastructure.

That shift is not theoretical. Hoxhunt's threat detection network, which analyzes phishing samples reported across more than 2.5 million users, found that AI-generated phishing in its network surged roughly 14 times at the end of 2025, climbing from under 5% to 56% of detected attacks in a single month. Earlier in 2025 that same research group had measured AI-crafted phishing at only a small single-digit share of the traffic it observed, so the jump was sharp rather than gradual.

Why grammar checks stopped working

For years, email security guidance told users to watch for misspellings and stilted phrasing as a first line of defense. That advice is losing relevance because the generation side of the equation changed faster than the training side did. A large language model does not make the mistakes a non-native speaker under time pressure used to make, and it can localize a lure into dozens of languages in seconds.

Security teams that fail to retire red-flag training risk leaving their organizations exposed. CISA's own phishing guidance now acknowledges as much, noting that poor grammar "used to be" a reliable tell, an implicit admission that the signal has faded. The FBI has separately warned that criminals are exploiting generative AI tools to make fraud attempts more convincing and harder for victims to detect, a point it has reinforced through updated public alerts on impersonation campaigns targeting officials and executives, as documented in the FBI's ongoing guidance on spoofing and phishing.

How the major providers are actually fighting back

The response from the largest mailbox providers has been to stop treating email text as the primary signal and start treating behavior, infrastructure, and context as the primary signal instead. Microsoft has published a detailed account of exactly this shift after its Defender for Office 365 team caught a phishing campaign that used AI to obfuscate a malicious SVG attachment. The campaign was blocked through a combination of infrastructure analysis, behavioral indicators, and message context, none of which were affected by the attacker's use of AI, as Microsoft explained in its writeup of the incident, where it noted the detection relied on signals such as self-addressed email with BCCed recipients and suspicious file naming that resembled legitimate document types.

Microsoft has since built dedicated language models specifically for phishing detection. Its Language AI for Phish model has been running in production since April 2025 and, according to Microsoft's own reporting, has been achieving over 99.99% accuracy while blocking roughly a million phishing emails daily, learning progressively from real-world phishing attempts submitted for review, as Microsoft's Defender for Office 365 team described in a technical community post.

Google has taken a parallel path on the spam and phishing side of Gmail. Its RETVec text vectorizer was built to catch adversarial manipulations that older classifiers missed, things like character substitutions and homoglyphs designed to slip past keyword filters. Google's own security researchers reported that swapping RETVec into Gmail's spam classifier improved the spam detection rate over the prior baseline by 38% while cutting the false positive rate by 19.4%, a result the team called one of the largest defense upgrades in recent years.

Does this mean phishing filters have solved the problem?

No, and no vendor claims otherwise. The improvements are real, but attackers are adapting their generation techniques in response, and the volume of AI-assisted phishing keeps climbing even as detection accuracy improves. Both dynamics are true at once, which is exactly what an arms race looks like.

This is worth sitting with for a moment. Detection getting better does not mean the threat is shrinking, because the two sides are scaling in parallel. What it does mean is that the specific failure mode changes: fewer attacks succeed because a user spotted a typo, and more attacks succeed or fail based on infrastructure hygiene, authentication posture, and whether unusual sending behavior gets flagged at all.

Where MSPs still have leverage

None of this changes what actually stops a spoofed email from landing in a client's inbox in the first place, and that part of the defense is not an AI problem at all. It is a protocol problem, and the protocols have not changed. SPF, DKIM, and DMARC remain the mechanism by which a receiving server decides whether a message claiming to be from a domain is actually authorized to come from that domain.

What has changed is enforcement. Google and Yahoo began requiring DMARC for bulk senders in February 2024, and Microsoft followed with its own enforcement deadline of May 5, 2025 for consumer mailbox properties including Outlook.com, Hotmail, and Live.com, as detailed in dmarcian's tracking of the rollout. Google tightened further in November 2025, moving from soft enforcement to actual rejection of non-compliant bulk traffic at the server level.

That enforcement matters more, not less, in an AI-vs-AI environment. A phishing email that perfectly mimics a client's tone and formatting is far less dangerous if it cannot pass DMARC alignment for that client's domain in the first place. Authentication does not care whether the lure text was written by a human or a model. It checks whether the sending infrastructure was authorized, which is precisely the kind of signal AI-generated wording cannot fake on its own.

For MSPs managing dozens or hundreds of client domains, this creates a clear division of labor:

  • AI-side detection at the mailbox provider layer catches behavioral and content anomalies after a message is composed, which is largely out of the MSP's direct control.
  • Domain authentication and monitoring is squarely inside the MSP's control, and it is the layer that determines whether a client's own domain can be weaponized against their customers and partners.

Neither layer replaces the other. A client can have flawless DMARC alignment and still receive a convincing lure sent from a different, unrelated domain. A client can also have excellent AI-based filtering from their mailbox provider and still get spoofed if their own domain has no enforced DMARC policy, leaving it open for someone else to impersonate.

What this looks like in practice

Where things stand today, the practical audit an MSP should run for a client looks less like a single yes/no check and more like a short scorecard.

LayerWhat it catchesWho controls it
SPF / DKIM / DMARCDomain spoofing and unauthorized sending infrastructureThe MSP, via DNS and policy configuration
Provider-side AI filtering (Microsoft, Google)Behavioral anomalies, obfuscated payloads, suspicious content patternsThe mailbox provider, largely opaque to the MSP
User awareness trainingRecognizing urgency, unusual requests, and out-of-band verification needsShared between MSP guidance and client staff

The first row is the one most within reach for a services business to verify quickly across an entire client base, and it is also the one most exposed by the DMARC enforcement deadlines that have already passed. Running that check across a book of domains, rather than one at a time, is the difference between reacting to a client's spoofing incident and catching the gap before it becomes one. ActiScan's scanning platform is built around that kind of portfolio-wide visibility, and MSPs who want to see how it fits their existing workflow can review the pricing page before rolling it out to a client list, walk through the getting-started guide to connect the first batch of domains, or go straight to the signup page to start a scan.

The bottom line for MSPs

The inbox will keep getting harder to reason about using text alone, because both attackers and defenders are going to keep investing in generative and detection models. That is not a reason for MSPs to panic, and it is not a reason to assume the problem is solved either. It is a reason to make sure the layer that does not depend on AI, domain authentication, is locked down for every client before worrying about which side of the arms race is currently ahead.

Security awareness training still has a role, particularly for catching requests that ask someone to act outside normal process, but it can no longer be the primary control against a well-crafted lure. The FBI and CISA have both effectively said as much in their own guidance. For MSPs, the actionable takeaway is narrower and more concrete than "AI is changing everything": verify authentication posture across the client base, understand what the mailbox providers are and are not catching on the content side, and treat DMARC enforcement dates as deadlines that already passed rather than ones still coming.

← Back to all posts
AI vs AI in the Inbox: A Guide for MSPs — ActiScan Blog