When it comes to email security software, the cybersecurity industry has become very good at one thing: scoring the message that's already in the inbox. We've gone from blocklists to signature matching to behavioral ML, and each generation of email security innovation was a genuine improvement over the last.

But the losses keep climbing anyway. The median time it takes someone to click a phishing link is just 21 seconds after opening the email, and another 28 seconds to hand over credentials or payment data. That's under a minute start to finish. That number hasn't moved much in years despite everything we've thrown at the problem.

It's time for a different approach. But first, we need to understand modern challenges.

We're filtering messages, but attackers are running campaigns

By the time a phishing email actually lands in someone's inbox, the attacker has usually finished the hard part. They've registered a lookalike domain and gotten it a valid SSL cert. They've built out a fake executive profile on LinkedIn. They've warmed up a sending domain so it clears SPF and DKIM without issue. In a lot of the more sophisticated cases I've seen, they've also got a vishing script or an SMS gateway ready to go as a backup channel, in case the email doesn't land.

None of that shows up when a filter inspects a single message. Traditional tools (e.g., gateways, API-based filters) look at word choice, headers, maybe a risk score, and then quarantine or don't. But the domain stays live, the fake profile stays up, and the sending server keeps running.

The same campaign just pivots to the next employee, or the next department, or a vendor down your supply chain. At best, you've neutralized the endpoint, but the threat actor is still active.

Generative AI didn't create this problem, but it made it a lot worse

The rise of AI has only exacerbated the structural vulnerabilities of traditional email security. I'd like to examine three ways things have changed, in my view.

First, the behavioral tells are gone. Organizations used to catch a lot of phishing on tone: awkward phrasing, weird formatting, a request that just felt off. Current-generation LLMs write in an organization's voice convincingly enough that those tells mostly don't exist anymore.

Next, the timeline compressed. Research that used to take a human attacker days can now be done by an agent in seconds, which means hundreds of personalized lures targeted at specific roles across a company, generated essentially on demand.

And nothing stays static long enough to fingerprint. Domains, lure text, sending infrastructure—attackers can rotate all of it between sends. Signature-based detection was built for a world where indicators of compromise stay put for a while. That world is mostly gone. It tracks with what's showing up in the 2026 DBIR, where analysts are flagging that different attack techniques are increasingly being bolstered by generative AI at nearly every stage — from finding gaps to writing the malware itself.

The other major shift is the imbalance between attackers and defenders. Attackers can automate research, infrastructure setup, lure creation, and campaign execution, while security teams are still investigating threats and maintaining detection policies largely by hand. Engineers spend hours debugging and deconflicting rules while adversaries freely generate new variations. That's not a sustainable operating model.

The dollar figures back this up, too. Business email compromise alone accounted for roughly 14.6% of all reported cybercrime losses in 2025, north of $3 billion, and that's a single category within a broader losses number that's grown sharply year over year.

This isn't a niche problem anymore. It's one of the more expensive categories of crime the FBI tracks.

What can actually break the cycle?

I don't think the fix is a smarter filter. A better classifier just makes security teams marginally faster at doing the same limited thing: reacting to a message after the infrastructure behind it is already built and running.

We need to break the cycle and make social engineering unprofitable. Here are three shifts that need to happen:

First, connect inbox signals to what's happening outside the inbox. When a message comes in, the system should be able to check the sending domain's registration history, hosting patterns, and other infrastructure signals (not just the words in the body) before it ever accomplishes its goal.

Second, get out of the rule-maintenance business. Analysts shouldn't be spending their week debugging YARA rules or trying to figure out why a blackbox model flagged something. That labor scales linearly with attack volume, and attack volume is not scaling linearly anymore. Automation broke that assumption. Systems that can explain their reasoning in plain language and adjust that reasoning as tactics shift take a lot of that grind off a team's plate.

Third, and this is the one most vendors skip, actually go after the infrastructure. Detecting a bad domain and doing nothing about it just means the next target gets hit with the same asset five minutes later. The goal should be affecting the economics of an attack, and that means taking down the sending server, the lookalike domain, and the malicious link. Everything short of that is just triage.

Multichannel protection, starting with email

None of this means email filtering stops mattering. It's still the front door. But treating the inbox as the whole battlefield, instead of one touchpoint in a longer attack chain, is how you end up permanently one step behind.

Modern social engineering is inherently multichannel. When a phishing email fails or is ignored, threat actors pivot. The lookalike domain registered last week suddenly becomes the destination for a scam SMS (smishing), an urgent Slack or Teams message, or a vishing call to a helpdesk agent.

This is why taking down attacker infrastructure at the email stage matters. When you dismantle a sending domain, neutralize a malicious link, or pull down an impersonation kit, you degrade the operational assets an attacker relies on across every other channel. Striking the infrastructure at the email stage hampers the smishing and vishing campaigns queued up right behind it.

This is the bet we made in building Doppel Email Security. Instead of scoring a message and stopping there, the system uses agentic AI to trace an email back to the infrastructure behind it, correlating sender signals against a live threat graph of domains, hosting patterns, and impersonation activity. This is the same context you'd want a human analyst pulling if they had unlimited time.

When a threat is verified, it helps security teams coordinate machine-speed takedowns across the domains, fake profiles, and malicious URLs the broader campaign depends on. Detection logic runs on natural-language policies instead of opaque blackbox scores or hand-maintained YARA rules, providing analysts with human-readable reasoning rather than arbitrary risk numbers.

The underlying thesis is that countering AI-driven social engineering requires an AI-native architecture with agents that adapt in real time, built on external attacker infrastructure intelligence rather than inbox content alone.

For teams evaluating where to invest next, I'd start by asking a blunt question: When your tools flag something today, does anything happen to the attacker's infrastructure, or does the campaign just move to the next inbox?

If it's the latter, you already know where the gap is.

About the author: Rahul Madduluri is the co-founder and CTO of Doppel, where he leads product, engineering, IT, and security. Rahul started his career as a software engineer at Uber, using machine learning to predict arrival time estimates. He later started a company that aggregates Shopify stores and joined South Park Commons as a Founder Fellow. Rahul holds a Bachelor of Science (BS) degree in Computer Science & Computer Engineering from the University of Southern California.

Rahul Madduluri — CTO and Co-Founder at Doppel https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwFx0yehdljt-HI98YCYhEmvl7UfNNhXGuCRpM6kM1tjo0CYe3DHUCEeDTP8QP7nKqfhAZ77BZ1Q_wIbZV365OFBrYd_q_QPWl10Y8BMO-EoM-aw3CVO2_TvpteFM2pSeHUihmr9-IsVWOmZ_ySKRF0DsMhDpD2hgCUfEnIx6i76SyC7H2t-uaP3KxCig/s1700-e365/rahul.png
Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter and LinkedIn to read more exclusive content we post.