---
title: "If You Want to Get Phished Use Microsoft | DuoCircle"
description: "If you subscribe to the notion that hackers go where the users are, it’s not surprising that Microsoft Remains the #1 Impersonated Brand in Phishing Attacks."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/email-security/if-you-want-to-get-phished-use-microsoft/"
---

Quick Answer

Microsoft is the most-impersonated brand in phishing, and Office 365 mailboxes receive a disproportionate share of phishing attempts. The Avanan 2019 Global Phish Report found that 30% of phishing emails sent to Office 365 mailboxes were delivered to the inbox by Exchange Online Protection (EOP), and Microsoft's own 2018 data showed Office 365 phishing rose 250% year over year. The main bypass technique is URL obfuscation through link shorteners, lookalike domains, and redirect chains that EOP fails to flag. Protection that works regardless of mail provider: real-time link-click protection (cloud-based interception that loads the page on a server, inspects it, and blocks if malicious before the user sees it), so the URL's appearance at delivery time does not matter.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Femail-security%2Fif-you-want-to-get-phished-use-microsoft%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=If%20You%20Want%20to%20Get%20Phished%20Use%20Microsoft&url=undefined%2Fblog%2Femail-security%2Fif-you-want-to-get-phished-use-microsoft%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Femail-security%2Fif-you-want-to-get-phished-use-microsoft%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Femail-security%2Fif-you-want-to-get-phished-use-microsoft%2F&title=If%20You%20Want%20to%20Get%20Phished%20Use%20Microsoft "Share on Reddit") [ ](mailto:?subject=If%20You%20Want%20to%20Get%20Phished%20Use%20Microsoft&body=Check out this article: undefined%2Fblog%2Femail-security%2Fif-you-want-to-get-phished-use-microsoft%2F "Share via Email") 

![Phished](https://media.mailhop.org/duocircle/images/2019/06/spf-validator-6632.jpg) 

If you subscribe to the notion that hackers go where the users are, it’s not surprising that [Microsoft Remains the #1 Impersonated Brand in Phishing Attacks](https://www.vadesecure.com/en/phishers-favorites-q1-2019/). Others making up the top five include PayPal, Netflix, Facebook and Bank of America, which confirms the theory.

The real problem with Microsoft though isn’t how often they get targeted by **phishing emails**. The real problem is how many get through. According to Avanan’s [2019 Global Phish Report](https://www.avanan.com/hubfs/2019-Global-Phish-Report.pdf), “30% of phishing emails sent to organizations using Office 365 Exchange Online Protection (EOP) were delivered to the inbox.” [EOP](https://en.wikipedia.org/wiki/Exchange%5FOnline%5FProtection) is a “[hosted email security](/email/hosted-email) service, owned by Microsoft, that _filters spam and removes computer viruses from e-mail messages_.”

“[Microsoft’s own research](https://www.microsoft.com/security/blog/2019/02/28/microsoft-security-intelligence-report-volume-24-is-now-available/) estimates that **Office 365 phishing** increased 250% from Jan, Dec 2018.” Apparently EOP isn’t very good at doing its job when you consider letting just one email through can be enough to infect an entire company. The real problem is something called URL obfuscation.

According to Techopedia, “An obfuscated URL is a web address that has been obscured or concealed and has been made to imitate the original URL of a legitimate website. It is done to make users access a spoof website rather than the intended destination.”

[![phishing attacks](https://media.mailhop.org/duocircle/images/2019/06/spf-record-generator-5301.jpg)](https://media.mailhop.org/duocircle/images/2019/06/spf-record-generator-5301.jpg)

From the Global Phish Report, “Obfuscation methods are the most advanced **phishing attacks**, leveraging specific vulnerabilities in Office 365 security layers. Hackers obfuscate the URL, making it unrecognizable to Office 365 security, which fails to blacklist the malicious content. With this strategy, _hackers can use URLs that are even known to be malicious, because Microsoft won’t recognize the format of the URL_.”

There are actually three ways to enact URL obfuscation:

1. link shorteners,
2. URL lookalikes and
3. URL redirects.

It’s hard to imagine that users will be keen to spot all of these, and if Microsoft can’t stop them, that leaves users pretty vulnerable.

What users need to protect themselves, regardless of whether their email service is Office 365, Google’s G-Suite or something else, is **email security** with real-time link click protection. Real-time link click protection doesn’t care if the URL is obfuscated or not because it waits until after the link is clicked to see if it’s malicious.

For **real-time link click protection** to work though, it must be deployed in the cloud, where it sits between the user and potentially malicious sites. That way, if a user does click on a link leading to a malicious site, the page gets loaded not on the user’s computer, but on a server in the cloud where it gets examined. _If it’s found to be malicious, it gets blocked and the user never sees it_. A set up like that would certainly protect the hundreds of thousands of Office 365 users who received a phishing email in their inbox.

If you use Office 365 or G-Suite for your email, you’ll want to consider augmenting their native security with [cloud-based email security](/) with real-time link click protection.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Fif-you-want-to-get-phished-use-microsoft%2F) [ ](https://twitter.com/intent/tweet?text=If%20You%20Want%20to%20Get%20Phished%20Use%20Microsoft&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Fif-you-want-to-get-phished-use-microsoft%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Femail-security%2Fif-you-want-to-get-phished-use-microsoft%2F) Copy 

Related Articles

- [  BIMI in 2026: What the Certificate Authority Does, and What Your DMARC Tool Does Email Security ](/blog/bimi-2026-what-the-ca-does-what-your-dmarc-tool-does/)
- [ ![Designing A Custom Dkim Architecture For High-Volume Email Senders](https://media.mailhop.org/duocircle/images/2026/04/buy-smtp-1290.jpg)  Designing A Custom Dkim Architecture For High-Volume Email Senders Email Security ](/blog/designing-custom-dkim-architecture-for-high-volume-email-senders/)
- [ ![DMARC, SPF, and DKIM](https://media.mailhop.org/duocircle/images/2026/04/spf-record-4526.jpg)  DMARC, SPF, and DKIM in 2026: Why Email Authentication Is Now a Regulatory Requirement, Not Just a Best Practice Email Security ](/blog/dmarc-spf-dkim-2026-email-authentication-regulatory-requirement-best-practice/)
- [ ![Email Monitoring Tools](https://media.mailhop.org/duocircle/images/2026/05/spf-validator-6720.jpg)  Email Monitoring Tools: A Complete Guide to Protecting Your Email Ecosystem Email Security ](/blog/email-monitoring-tools-guide-protecting-your-email-ecosystem-security/)

## Related Articles

[  Email Security 8m  BIMI in 2026: What the Certificate Authority Does, and What Your DMARC Tool Does  May 5, 2026 ](/blog/bimi-2026-what-the-ca-does-what-your-dmarc-tool-does/)[  Email Security 8m  Designing A Custom Dkim Architecture For High-Volume Email Senders  Apr 28, 2026 ](/blog/designing-custom-dkim-architecture-for-high-volume-email-senders/)[  Email Security 12m  DMARC, SPF, and DKIM in 2026: Why Email Authentication Is Now a Regulatory Requirement, Not Just a Best Practice  Apr 29, 2026 ](/blog/dmarc-spf-dkim-2026-email-authentication-regulatory-requirement-best-practice/)[  Email Security 5m  Email Monitoring Tools: A Complete Guide to Protecting Your Email Ecosystem  May 7, 2026 ](/blog/email-monitoring-tools-guide-protecting-your-email-ecosystem-security/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"If You Want to Get Phished Use Microsoft","description":"If you subscribe to the notion that hackers go where the users are, it’s not surprising that Microsoft Remains the #1 Impersonated Brand in Phishing Attacks.","url":"https://www.duocircle.com/blog/email-security/if-you-want-to-get-phished-use-microsoft/","datePublished":"2019-06-18T14:54:24.000Z","dateModified":"2025-05-13T12:49:56.000Z","dateCreated":"2019-06-18T14:54:24.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/if-you-want-to-get-phished-use-microsoft/"},"articleSection":"email-security","keywords":"","wordCount":489,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/06/spf-validator-6632.jpg","caption":"Phished","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Email Security"},{"@type":"ListItem","position":3,"name":"If You Want to Get Phished Use Microsoft","item":"https://www.duocircle.com/blog/email-security/if-you-want-to-get-phished-use-microsoft/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Email Security","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"If You Want to Get Phished Use Microsoft","item":"https://www.duocircle.com/blog/email-security/if-you-want-to-get-phished-use-microsoft/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"If You Want to Get Phished Use Microsoft","description":"If you subscribe to the notion that hackers go where the users are, it’s not surprising that Microsoft Remains the #1 Impersonated Brand in Phishing Attacks.","url":"https://www.duocircle.com/blog/email-security/if-you-want-to-get-phished-use-microsoft/","datePublished":"2019-06-18T14:54:24.000Z","dateModified":"2025-05-13T12:49:56.000Z","dateCreated":"2019-06-18T14:54:24.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/if-you-want-to-get-phished-use-microsoft/"},"articleSection":"email-security","keywords":"","wordCount":489,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/06/spf-validator-6632.jpg","caption":"Phished","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
