Use Case10 min read

Sophos Email Security for Google Workspace & Microsoft 365 — India Guide

Sophos Email Security for Google Workspace & Microsoft 365 — India Guide

Google Workspace and Microsoft 365 both include email filtering. So why do Indian businesses running these platforms still get phished, still fall victim to BEC fraud, and still deal with zero-day malware delivered via email?

Because the built-in filters are designed for volume threats — mass spam campaigns, known malware signatures, broadly circulated phishing links. They are not designed for targeted attacks against your specific company, your CEO's identity, or your finance team's workflows.

Sophos Email Security fills that gap. This guide explains exactly what it adds, how it deploys in front of GWS and M365, and why it's particularly relevant for Indian businesses.


What Google Workspace and Microsoft 365 Already Do

Before covering what's missing, it's worth crediting what both platforms include:

Google Workspace (Gmail):

  • Anti-spam filtering (very effective for mass spam)
  • Basic antivirus scanning on attachments
  • Safe Browsing link checks at delivery time
  • DMARC enforcement (if configured)

Microsoft 365 (Exchange Online Protection — EOP):

  • Anti-spam and anti-malware filtering
  • Known phishing site blocking
  • Basic spoofing detection
  • Microsoft Defender for Office 365 (P1/P2) available as a paid add-on

Both are genuinely good at what they do. The problem is what they don't do.


What Neither Platform Catches Well

1. Business Email Compromise (BEC) — The Biggest Financial Threat

BEC doesn't use malware. There's no link to click, no attachment to scan. A criminal impersonates your CEO, your CFO, or a supplier, and sends a plain-text email asking your accounts team to transfer funds or change a payment account.

Both Google and Microsoft apply display-name spoofing checks — but they look for exact matches against your own domain. A sophisticated BEC attack uses a lookalike domain (c1oudfysystems.com instead of cloudfysystems.com), a personal Gmail account with your CEO's name, or a compromised third-party vendor account.

Sophos Email Advanced uses ML models trained specifically on BEC patterns — not just domain matching but writing style analysis, sender behaviour baselines, and lookalike domain detection against your registered domain variants.

2. Zero-Day Malware in Attachments

Google and Microsoft scan attachments against known malware signatures. Sophisticated threat actors generate new variants for every campaign specifically to avoid signature detection.

Sophos Sandstorm (included in Sophos Email Advanced) opens every suspicious attachment in an isolated cloud sandbox and executes it — watching for malicious behaviour like registry changes, network callbacks, or process injection — before deciding whether to deliver it.

3. Delayed-Activation URLs

Phishing URLs are often clean at the time the email arrives — hosted on legitimate services like Google Docs, SharePoint, or newly registered domains with no malware history. Google and Microsoft scan at delivery time. If the URL is clean when it arrives, it passes.

The malicious content activates 2–6 hours later, after delivery. Users click the link the next morning, and it now leads to a credential harvesting page.

Sophos Email Advanced rewrites every URL in every email and re-scans at the moment of click — not at delivery. A URL that became malicious overnight is blocked when your user tries to open it.

4. Targeted Polymorphic Malware

Mass malware campaigns are detectable by signature. Targeted campaigns use polymorphic packers that change the file signature on every send. A malware file sent to your finance director looks completely different from the one sent to your IT manager — both undetectable by signature databases.

Sophos Sandstorm's behavioural sandbox catches polymorphic threats because it doesn't compare signatures — it watches what the file does when it runs.


How Sophos Email Deploys in Front of GWS / M365

Sophos Email Security is a cloud MX gateway. This means:

  1. Your domain's MX records are changed to point to Sophos Email servers (e.g. mx1.sophos.com)
  2. All inbound email arrives at Sophos's cloud infrastructure first
  3. Sophos scans, filters and inspects each message
  4. Clean messages are delivered to Google Workspace or Microsoft 365 via a separate inbound connector
  5. Rejected messages are quarantined in Sophos Central

Your existing mail platform is unchanged. Users keep using Gmail or Outlook exactly as before. The protection is invisible until it blocks something.

MX Record Change — What It Looks Like

Before:

yourdomain.com    MX  10  aspmx.l.google.com      (for GWS)
yourdomain.com    MX  10  yourdomain-com.mail.protection.outlook.com  (for M365)

After:

yourdomain.com    MX  10  mx1.sophos.com
yourdomain.com    MX  20  mx2.sophos.com

The Sophos gateway receives mail, scans it, then forwards clean messages to Google or Microsoft using a locked inbound connector.

SPF Update Required

Your SPF record must be updated to include Sophos's sending infrastructure alongside Google's or Microsoft's, so that outbound mail passes SPF when Sophos sends it on your behalf:

v=spf1 include:_spf.google.com include:sophos.com ~all

Cloudfy handles this update as part of deployment and verifies it post-change.


Deployment Steps — With Cloudfy Systems

Cloudfy Systems manages the full Sophos Email deployment alongside your Google Workspace or Microsoft 365 account:

  1. Sophos Central setup — your Sophos Email account is created and your domain is verified
  2. Policy configuration — inbound spam threshold, quarantine release settings, allow/block lists
  3. MX record change — coordinated with your DNS provider; old MX records kept as lower-priority backups during transition
  4. SPF / DKIM / DMARC update — Sophos sending IP ranges added to SPF; DMARC policy verified
  5. Outbound relay setup — outbound mail from GWS/M365 routed through Sophos for DLP scanning
  6. User quarantine training — your team learns to manage the Sophos quarantine digest
  7. Handover and monitoring — Cloudfy reviews threat reports for the first 2 weeks and tunes policies

Full deployment for up to 100 users typically takes 2–4 hours of technical work, plus up to 48 hours for DNS propagation to complete globally.


Sophos Email + Sophos Firewall — The Full Stack

If your organisation also uses Sophos XGS Firewall, Sophos Email and the firewall share threat intelligence through Sophos Central. This is Sophos's Synchronized Security model:

  • If Sophos Email detects a malicious attachment and identifies the sender's infrastructure
  • That IP / domain data is automatically shared with the XGS Firewall
  • The firewall updates its threat intelligence and blocks traffic to/from that infrastructure

For organisations that have deployed both Sophos Email and Sophos Firewall through Cloudfy, both products are managed from a single Sophos Central account — one console for your full Sophos stack.


Is Sophos Email Right for Your GWS or M365 Deployment?

Sophos Email Advanced makes sense when:

  • You handle B2B financial transactions (invoices, payment details, bank account changes) — high BEC risk
  • You operate in healthcare, legal, CA/CS, manufacturing, or government sectors where sensitive data is emailed
  • You've experienced phishing attempts or suspicious emails in the last 6 months
  • You're already using or planning Sophos Firewall and want unified management
  • Your team regularly receives email from suppliers, contractors or external parties (not just internal)

Sophos Email Standard is sufficient when:

  • You primarily deal with internal mail flow
  • Your biggest concern is spam volume, not targeted attacks
  • You have a small team (under 25 users) with limited external exposure

Frequently Asked Questions

Does adding Sophos Email in front of Gmail slow down email delivery? No. Sophos Email's cloud infrastructure is globally distributed. Typical additional latency is under 1 second. Users notice no difference in delivery speed.

Will Sophos Email break our existing email integrations (CRM, billing software, etc.)? Transactional mail from known good senders is whitelisted during deployment. Cloudfy audits your existing mail flows before making MX changes and adds appropriate allowlist entries to ensure no legitimate business mail is quarantined.

Do we need to change anything inside Google Workspace or Microsoft 365? For M365: you create a Connector that only accepts mail from Sophos IPs, preventing bypass of the gateway. For GWS: a similar inbound routing rule is configured. Cloudfy handles both as part of the deployment.

What happens to outbound mail? For outbound DLP, your GWS or M365 is configured to route outgoing mail through Sophos for inspection before it leaves your organisation. This catches data leakage and applies encryption policies. It is optional but recommended for regulated sectors.


Cloudfy Systems is an authorised Sophos Email partner in India with experience deploying Sophos Email alongside Google Workspace and Microsoft 365. Contact us for a free consultation and same-day pricing.

Free Consultation

Talk to a Cloud Expert

Tell us about your team and stack — we'll recommend the right cloud and SaaS setup with transparent pricing in INR.

Google Cloud PartnerMicrosoft PartnerZoho Authorised
Already decided? Submit your details to start provisioning

Request a Callback

Fill the form — we'll get back within one business day.

We respond within one business day · No spam, ever.