Pillar
Email security is what you do when the payload is a message: spoofing, lookalike domains, the HTML the client will happily run, and the link that is not the URL it showed.
Refuse the lookalike domain
Open the listFilter the inbox you already run
Open the listQuestions about Email Security
Not first. A gateway list that only repeats ‘AI phishing’ is a brochure. We will start with the records and controls you own on the domain, then the clients, then the gateways if we can tell them apart on a job.
It is email security. Your app may send the mail, but the check lives on the domain and the receiving server. That is why this category exists instead of folding it into AppSec.
Publish SPF, DKIM, and a DMARC policy you actually monitor. Treat HTML email as untrusted input. If your product sends mail, the From domain is part of the security design, not a marketing setting.