Email security services are the same protections as email security software with the operating handed to someone else: a provider configures the filtering, tunes it as traffic changes, reviews what lands in quarantine, rolls out the sender authentication records, and answers the message that asks is this real. The distinction matters because most small organisations that buy the software configure it once and never look again, and an untuned filter drifts, catching the newsletter and missing the payroll fraud. The service model prices the ongoing attention in, per user per month, on top of or bundled with the software licence. This guide walks what a provider actually does month to month, which of those tasks you could genuinely keep in-house, and the questions that separate a provider running your mail security from one merely reselling licences with a logo on the invoice.
What the provider does month to month
Four recurring tasks: tuning the filter as false positives and new campaign styles appear; reviewing and releasing quarantine, with an agreed turnaround so held mail does not silently stall the business; keeping SPF, DKIM and DMARC records correct as you add senders like a new invoicing tool or a marketing platform; and answering user reports, the forwarded is this legitimate message, with a verdict. Incident help when an account is compromised, resetting, tracing what was sent, notifying recipients, is the fifth task and the one where having a provider already inside your mail flow pays for the year.
What you could keep in-house
Quarantine review is clerical once someone owns it, and a competent office manager can own it with an hour a week and a written procedure. Sender authentication is one-time work per sender with occasional changes, learnable from the DMARC standard's own documentation. What is hard to keep in-house is the judgement tasks at volume: distinguishing a novel impersonation from a legitimate oddity, and running a compromise response calmly. Buy the service for the judgement, not the clicking; the guides on managed email security and hosted email security on this site split those variants in detail.
Questions that separate operators from resellers
Ask who actually looks at your quarantine and how often, what the release turnaround commitment is, whether DMARC enforcement, not just monitoring, is included in the rollout, what the compromise response procedure is and who executes it at 2am, and what reporting you see monthly. A reseller answers with the software's datasheet; an operator answers with their own runbook. Either way, the payment confirmation procedure stays yours: no provider reads every message, and the free policy sheet on this site counts that procedure and the mail policy into your written set with the drafting cost priced at your own figure.
Questions people ask about email security services
What is included in email security services?
Filter tuning, quarantine review with a turnaround, sender authentication (SPF, DKIM, DMARC) rollout and upkeep, user report verdicts, and compromise response. The software is the same as the self-run category; the service is the ongoing attention.
How are email security services priced?
Per user per month on top of or bundled with the software licence. The added cost over software alone buys tuning and review time; the compare is against the in-house hour a week that quarantine review costs plus the judgement calls you would rather not make alone.
Do email security services stop payment fraud?
They reduce it: impersonation filtering and DMARC enforcement remove most of the raw material. But a well-built request can still arrive, so the written rule that no payment changes on email alone stays necessary, and it costs nothing. The free sheet counts it into your policy set.