What is anti-phishing software? How it works and what it does in 2026

What anti-phishing software does in 2026: the technical filter half, the human training half, where each fails, and what an Australian small business actually needs.

Anti-phishing software is the set of tools that catch phishing before it reaches your inbox and, increasingly, the tools that catch people after it does. This guide explains how the two halves work, where the gaps are and what a small Australian business actually needs in 2026.

TL;DR

What anti-phishing software actually does

The name covers two categories that get sold together and behave differently:

Both are anti-phishing software. Buying only the first half solves the threat that was popular in 2015; buying only the second leaves staff exposed to industrial-scale commodity spam.

How the technical half works

Modern email security layers several checks on every message:

  1. Sender authentication. SPF, DKIM and DMARC verify the mail really came from the domain it claims. This kills a large share of naive spoofing.
  2. Reputation and pattern scoring. Sending IP reputation, message similarity to known campaigns and header analysis assign a risk score before delivery.
  3. Link rewriting and detonation. URLs are wrapped so that the click goes through a security gateway, which checks the destination at click time — not just when the mail arrived.
  4. Attachment detonation. Files are opened in a sandbox; anything that drops a payload or phones home is quarantined.
  5. Impersonation detection. Look-alike domains, display-name spoofing of your executives and replies to threads the attacker never joined are flagged.

These controls are effective against bulk campaigns. They are weakest exactly where attackers invest most: personalised, low-volume lures aimed at finance staff and executives, sent from legitimately registered domains.

How the human half works

When a crafted lure passes the filter, the last control is a person. Human-layer software strengthens that control with three mechanisms:

Cyber Aware's awareness training and phishing simulations cover this half, with clickers auto-enrolled into a follow-up lesson the same day and results rolled into a per-learner score.

Where each half fails

FailureWhich half it belongs toWhat covers the gap
Bulk credential-harvest campaignTechnicalFiltering, reputation scoring
Personalised invoice fraud from a real domainTechnical (weakly)Human: finance training + verification habits
Staff click a link in a personal chat appBothHuman: channel awareness training
A report that nobody acts onProcessHuman: reporting workflow and response
Malicious attachment inside a PDFTechnicalDetonation, sandboxing

The pattern is clear: the technical half handles volume, the human half handles intent. Attackers choose the gap with the least resistance, which is why the human element still appears in roughly 60% of breaches.

What it costs

Email security typically prices per mailbox per month and often ships inside Microsoft 365 Defender or Google Workspace already — check what you own before buying. Human-layer platforms price per user per year; for a 50-person business the realistic band is a few hundred to a couple of thousand dollars annually, and a comparison of platforms shows where vendors differ on automation and reporting rather than on headline features.

The money case holds at any size: IBM's 2025 Cost of a Data Breach Report put the global average breach at USD 4.44 million (IBM's report summary), and even the ASD's small-business average of $56,600 dwarfs a year of both halves combined.

How to choose for an Australian small business

Ask four questions before you buy:

If you are unsure whether your exposure is mostly technical or mostly human, a security gap assessment tells you which control deserves the next dollar.

FAQ

What is anti-phishing software? Tools that block phishing before delivery (email security: authentication, link rewriting, detonation) plus tools that strengthen the human decision after delivery (training, simulations, report buttons).

Do I need both? Yes. The technical half stops bulk campaigns; the human half stops the crafted lures built to defeat the filter. Each covers the other's blind spot.

Does Microsoft 365 include anti-phishing? It includes solid baseline filtering through Defender for Office 365, but no meaningful training or simulation layer — the human half still needs a platform.

How much does it cost? Technical filtering is often bundled with your email platform; human-layer training commonly runs a few dollars per user per month. Verify what you already pay for before adding spend.

Will it stop business email compromise? Not entirely. BEC frequently uses legitimate infrastructure and real threads, which filters cannot safely block. Verification habits and payment controls trained into finance staff are the control that catches it.

One last thing

Before you buy any anti-phishing product, run one baseline phishing simulation. The number you get back tells you whether your spend belongs in the filter or in the people — and most teams are surprised which it is.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.