Watch supported Microsoft 365 and Google Workspace audit signals for mailbox takeover — then get a plain-English alert. An alarm, not a staffed SOC.
Section 01
Account takeover (ATO) detection for email means watching supported Microsoft 365 and Google Workspace audit records for signals that someone else may control a mailbox — unexpected sign-ins, new forwarding, inbox-rule changes, and similar events — then alerting you in plain English.
InboxGuards is an alarm on those records, not a staffed SOC and not a guarantee that every takeover is visible before fraud. Provider APIs, licenses, retention, and timing still limit what shows up.
Section 02
Account takeover is when an attacker uses valid credentials (or a token/session) to operate a real mailbox. Business email compromise (BEC) is the fraud that often follows: changed bank details, fake invoice threads, or executive payment requests sent from that access — or from a convincing lookalike.
Detection work starts with the takeover signals in audit data. Stopping every BEC payment still depends on how your team verifies money moves.
Section 03
After a customer admin grants read-only access, InboxGuards checks supported audit records at the fastest cadence available on standard Microsoft 365 and Google Workspace plans — no premium security licensing required — and emails an alert when a configured rule matches.
Section 04
Some takeover techniques leave little or no trail in the audit records InboxGuards can read. Google Gmail filter changes are one known blind spot. Delays in provider ingestion mean an alert can arrive after an event, not before.
Use monitoring next to MFA, admin hygiene, and a habit of verifying payment changes out-of-band — not instead of them.
Section 05
Practice spotting scam mail with the free email scam simulator (no login). Read the BEC explainer if you want the fraud pattern in plain terms.
FAQ