Email Security Strategy
AI Is Rewriting Both Sides of the Email Threat Equation
September 17, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Every few years a technology arrives that resets the baseline for email fraud. Spam filters forced attackers to get creative with spelling and formatting. Cloud mail forced them to industrialize credential phishing. Generative AI is the latest reset, and unlike previous shifts, it is improving the tools on both sides of the fight at the same time.
The core question for MSPs is whether AI has made email attacks fundamentally harder to stop, or whether it has simply sped up a contest that authentication and monitoring can still win. The honest answer is both: AI is making individual phishing messages measurably more convincing, while also giving defenders new detection signals that do not depend on catching bad grammar or broken logos.
How Much More Effective Is AI-Written Phishing?
Microsoft's 2025 Digital Defense Report found that AI-generated phishing messages are now dramatically more likely to succeed than traditional ones. The report measured click-through rates climbing from roughly 12 percent for conventional phishing to 54 percent for AI-generated lures, a 4.5x jump in effectiveness collected across Microsoft's fiscal year 2025 telemetry.
That gain does not come from novelty alone. Attackers are using large language models to remove the language errors, awkward phrasing, and generic greetings that used to be reliable tells, then pairing that polish with automation that scales personalized targeting across thousands of recipients at once. CrowdStrike's 2025 Global Threat Report documented the same shift from the threat-actor side, describing a broad surge in GenAI-powered social engineering alongside accelerating nation-state cyber operations.
The financial impact is no longer theoretical. The FBI's Internet Crime Complaint Center included a dedicated artificial intelligence section in its 2025 annual report for the first time in the center's history, tallying more than 22,000 AI-related complaints and nearly $893 million in reported losses. Cyber-enabled fraud overall accounted for close to $21 billion in losses reported to the FBI last year, a figure that puts the AI slice in context rather than isolation.
What Does an AI-Assisted Attack Actually Look Like?
It rarely looks like the classic phishing template anymore. Microsoft's threat intelligence team recently published an account of a credential phishing campaign that used AI-generated code to obfuscate its payload inside an SVG file, disguising malicious intent behind business terminology and a synthetic structure built to evade traditional defenses. The message was not sloppy. It was engineered to look routine.
Phishing-as-a-service kits have absorbed the same capability. Campaigns tied to networks like RaccoonO365, which Microsoft and Cloudflare dismantled in late 2025, packaged AI-powered modules for subscribers with little technical skill, effectively renting out sophistication that used to require a skilled operator. That commoditization is arguably the more consequential change than any single clever email, because it lowers the floor for who can run a convincing business email compromise attempt.
Can Email Defenses Keep Pace With AI Attacks?
Yes, but only where detection has shifted away from surface-level pattern matching. Microsoft's own defense against the SVG-based campaign worked because Defender for Office 365 analyzed infrastructure, sender behavior, and message context rather than looking for linguistic tells that AI has already learned to erase. That is the direction every serious email security stack now has to move.
This is also where domain authentication earns its keep, because it does not care how well-written the email is. SPF, DKIM, and DMARC evaluate where a message actually came from and whether it is authorized to claim a given domain, a mechanism defined in RFC 7489 that has not needed to change even as the messages riding on top of it have gotten more convincing. An AI model can write a flawless spoofed invoice email, but it cannot forge a DKIM signature it does not hold the key for.
Mailbox providers have leaned into this reality rather than away from it. Google and Yahoo's bulk sender requirements, which took effect in 2024 and moved into stricter rejection-based enforcement through 2025, require senders exceeding 5,000 messages a day to publish DMARC records and keep SPF and DKIM aligned with their From domain, with Gmail describing quarantine enforcement for messages that fail to align. That policy tightening happened independent of the AI conversation, but it now functions as a direct counterweight to AI-scaled spoofing, because a domain without enforced DMARC is exactly the kind of target that automated impersonation exploits first.
The practical gap between defended and undefended domains looks like this:
| Domain posture | Exposure to AI-scaled spoofing |
|---|---|
| No SPF/DKIM/DMARC record | Fully exploitable, any sender can claim the domain |
| SPF and DKIM only, no DMARC policy | Authentication exists but failures are not enforced |
| DMARC at p=quarantine or p=reject | Spoofed mail is filtered or blocked before inboxing |
| DMARC plus continuous monitoring | Policy drift and new attacker infrastructure caught early |
For MSPs managing dozens or hundreds of client domains, that table is really a workload problem disguised as a security one. Manually checking DNS records for correct SPF syntax, valid DKIM selectors, and an enforced DMARC policy across a large client book does not scale, especially as attackers use AI to probe for exactly the misconfigurations that manual reviews tend to miss.
Where This Leaves the MSP Playbook
None of this changes the fundamentals of what needs to be in place, it changes how urgently it needs to be verified. A domain sitting at DMARC p=none, or with an SPF record that has quietly broken after a vendor migration, is now a softer target than it was two years ago because the attackers probing for it are faster and better resourced.
The response is not exotic. It is disciplined domain hygiene applied consistently, which is the same guidance security researchers have offered for years, just with less room for error. Teams building out that discipline from scratch can work through the fundamentals in ActiScan's getting-started guide, which walks through the authentication checks that matter most before layering on anything more advanced.
For MSPs already running client domains, the value is in catching drift before an attacker does. A domain that passed a DMARC audit six months ago is not guaranteed to still be aligned today, particularly if a client has added a new marketing platform or CRM that sends on their behalf without updating SPF. Continuous scanning closes that gap in a way that point-in-time audits cannot, and it is worth comparing options on the pricing page against what a single missed spoofing incident would cost a client in remediation and trust.
The Bottom Line
AI has not broken email security, it has raised the cost of neglecting it. Attackers get more convincing lures and more automation, while defenders get better anomaly detection and the same enforcement mechanisms that have protected domains since RFC 7489 was published a decade ago. The domains that stay safe through this shift will be the ones where authentication is enforced and monitored continuously, not the ones hoping their filters catch a well-written email that no longer looks fake. MSPs who want to see where their client domains currently stand against that bar can start with a scan through signup rather than waiting for an incident to surface the gap.