Skip to content

Security1 publisher2 min readPublished

Defender missed 221 high-severity emails per 1,000 users in Microsoft's own benchmark

The May to July figures come from Microsoft and the competing vendors are unnamed. Miss counts are rising across reporting periods, Defender's included, and the third-party layer caught 0.30% of malicious mail.

The Watch · Security desk

Illustration accompanying Defender missed 221 high-severity emails per 1,000 users in Microsoft's own benchmark

What happened

  • Microsoft's fifth consecutive quarterly email security benchmark, covering May through July 2026, puts Defender at 221 missed high-severity threats per 1,000 protected users, 55.4% fewer than the next-closest secure email gateway.
  • The report states that missed threats have increased across multiple reporting periods, Microsoft's own included, and Microsoft attributes the trend to attackers using AI to tailor messages and impersonate more convincingly.
  • Integrated cloud email security vendors caught 0.30% of malicious mail this period, up from 0.13%, with spam catch rising to 0.52% from 0.28%.
  • Microsoft says Defender does not treat post-delivery remediation as a one-time action, and reevaluates already delivered messages as new indicators and campaign intelligence arrive.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision A third-party layer measured at a fraction of a percent on malicious mail has to be defended at renewal on what it does for bulk and promotional traffic, or on numbers the SEG vendor publishes itself.
  • constraint With only Defender identified in the comparison, the 55.4% figure can be quoted in a procurement meeting but not checked by the buyer it is aimed at.
  • exposure Once Copilot and agents read mailboxes, a missed message is a candidate instruction to an automated system, not only something a person might click.
  • precedent Five straight quarters of vendor-run comparative numbers, including periods where its own miss count worsened, sets the expectation that rivals answer with normalized miss rates of their own.

A 55.4% lead means the next-closest gateway missed about 496 high-severity threats per 1,000 users, since 221 divided by 0.446 comes to 495.5 [17]. First to second place is a spread of roughly 275 missed high-severity messages per 1,000 users across the three months [18]. Microsoft identifies that competitor only as "the next-closest SEG vendor" [16].

Microsoft counts misses instead of catches, on the argument that catch totals reflect differences in threat volume and exposure across vendor environments [4]. The absolute figure is the one a mail administrator has to staff for. At 221 per 1,000, a 10,000-seat tenant took 2,210 missed high-severity messages [19]. May through July is 92 days, so that is about 24 a day from the product that scored best in the comparison [20]. Defender caught 92% of post-delivery malicious messages on average during the period, so 8% of that category stayed put [10][21]. The two percentages use different denominators and do not multiply.

On layering, the report says: "Layered security adds the most value in promotional and bulk filtering and works; gains for spam and malicious email remain comparatively modest" [12]. The malicious catch credited to third-party tools more than doubled quarter on quarter and remains under a third of a percent [23]. Microsoft gives those figures as bare percentages and does not say what population they are drawn from [22].

The vendor that sells the pre-delivery layer is the one reporting that the added layer contributes little against malicious mail. Microsoft has already built product on it: the new Promotions folder in Outlook comes from the observation, across multiple benchmarking periods, that third-party tools delivered their greatest incremental benefit in promotional and bulk email [13]. A buyer can take the 0.30% into a renewal conversation, and the SEG vendor across the table can point out that Microsoft ran the test and sells the alternative [24].

Microsoft research reports a roughly two-thirds reduction in false negatives and a nearly one-fifth reduction in false positives for Defender customers over four consecutive weeks, from a redesigned machine learning and AI model stack; that measurement sits outside the quarterly benchmark [14]. The company also shipped prompt injection protection that detects and isolates malicious AI instructions in email before delivery, aimed at Copilot, agents and other AI systems that read and act on inbox content [15].

What to watch

  • Whether the sixth quarterly report shows Defender's 221 per 1,000 climbing again, and whether Microsoft publishes it when it does.
  • Any SEG or ICES vendor publishing its own missed-threats-per-1,000-users figure on a comparable normalization.
  • Independent testing of the pre-delivery prompt injection filter against inbox-borne instructions aimed at Copilot and agents.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories