Why the Secure Email Gateway no longer fits
Email security teams face a familiar set of daily realities. Their mail is cloud-delivered, with some native protection that handles basic spam and commodity malware. They have likely invested heavily in a Secure Email Gateway (SEG) to catch phishing and other email-borne threats. Yet email remains the top source of internet-borne attacks, with Deloitte research showing that 91% of all cyber attacks begin with phishing.
The persistence of these problems points to a structural issue: the SEG was built for an email environment that no longer exists. Cloud-native email services have become the default, with Gartner projecting that over 85% of organizations will embrace a cloud-first strategy by 2025. Organizations expecting cloud-scale resiliency and flexibility from their security controls will not find it in legacy gateway appliances.
Gartner has noted that advanced email security capabilities are increasingly delivered as integrated cloud solutions rather than as gateways, predicting that by 2023 at least 40% of organizations will rely on built-in protections from their cloud email providers instead of a SEG. Email now flows everywhere, to mobile and remote users, making a gateway positioned in front of an on-premises Exchange server both anachronistic and impractical. Effective email security today must follow the user and sit close to the inbox.
The detection philosophy of the SEG is equally dated. Built originally to stop high-volume spam using large attack samples, it struggles with modern phishing—low-volume, highly targeted attacks that exploit trust in email communications. These attacks require compute-intensive analysis and advanced threat detection that a gateway cannot perform at scale. Admins are left managing a growing pile of email threat policies, while attackers rapidly adapt to bypass the rules. Relying on SEG tuning to stop phishing is a losing game of whack-a-mole.
Looking ahead to stop attacks early
Traditional defenses rely on knowledge of yesterday's attack characteristics—reputation data and threat signatures—to catch the next attack. That approach cannot reliably stop phishing that continually evolves. Forward-looking security must understand not just active payloads and techniques, but also attacker infrastructure under construction: which sites and accounts are being compromised for tomorrow's campaigns, and where attackers are probing before they strike.
Cloudflare Area 1 is designed to address these gaps. Its threat-focused crawlers proactively scan the internet for attacker infrastructure and phishing campaigns in development, dynamically analyzing suspicious pages and payloads while continuously updating detection models as tactics evolve. This allows threats to be stopped days before they reach the inbox.
Combined with the more than one trillion daily DNS requests observed by Cloudflare Gateway, this threat intelligence corpus enables early-stage detection of phishing. Deep contextual analytics—examining message sentiment, tone, tenor, and thread variations—help distinguish legitimate business processes from sophisticated impersonation campaigns. Area 1 is built to enhance, not duplicate, native email security, catching what slips past initial layers of defense.
Planning the replacement project
Start by deciding whether the goal is a straight replacement or an eventual one that begins with augmentation. Many Cloudflare Area 1 customers have fully replaced their SEG, but others prefer to run Area 1 downstream of the SEG initially, assessing both services before making a final determination.
Involve the right stakeholders from the start. At minimum, include an IT admin to protect email delivery and productivity, and a security admin to monitor detection efficacy. A channel partner may be relevant if that is your procurement route, and privacy or compliance team input ensures proper data handling.
Next, choose the deployment architecture. Cloudflare Area 1 can be deployed as the MX record, over APIs, or in a multi-mode configuration. For the strongest protection against external threats, deploying as the MX record is recommended, though the service adapts to your business logic and needs.
Map out your email flow before implementation. If you have multiple domains, identify where inbound messages route for each. Check intermediate routing layers, such as MTAs that relay messages. A clear picture of the logical and physical SMTP layers ensures proper message routing and clarifies which traffic Area 1 should scan—north/south, east/west, or both—and where it fits within existing email policies.
Executing the transition
Step 1: Implement email protection
If Cloudflare Area 1 is configured as the MX record, the process takes about 30 minutes:
- Configure the downstream service to accept mail from Cloudflare Area 1.
- Ensure Cloudflare Area 1's egress IPs are not rate limited or blocked.
- For on-premises email servers, update firewall rules to allow delivery from Cloudflare Area 1.
- Configure remediation rules (e.g., quarantine, subject or body prefix).
- Test message flow by injecting messages into Cloudflare Area 1.
- Update MX records to point to Cloudflare Area 1.
For deployment downstream of an existing email security solution (also about 30 minutes):
- Configure look-back hops on Cloudflare Area 1 so the original sender IP is detected.
- Update firewall rules for on-premises delivery to the email server.
- Configure remediation rules.
- Test message flow by injecting messages.
- Update delivery routes on your SEG to forward all mail to Cloudflare Area 1.
Step 2: Integrate DNS
A common next step is DNS integration. For Cloudflare Gateway customers, Cloudflare Area 1 uses Gateway as its recursive DNS, protecting end users from accessing phishing or malicious sites via email links or web browsing.
Step 3: Integrate with monitoring and remediation tools
Cloudflare Area 1 provides detailed, customizable reporting for at-a-glance threat visibility. SIEM integration via robust APIs allows correlation of detections with events from network, endpoint, and other security tools, simplifying incident management. While built-in remediation and message retraction handle responses directly in the dashboard, many organizations also use API hooks to integrate with SOAR services for custom response playbooks.
Measuring success
Track metrics covering both detection efficacy and operational simplicity. On detection, measure the number and nature of phishing attacks blocked before and after the project. Look for new attack types being caught that weren't before, and visibility into campaigns hitting multiple mailboxes. False positive rates are equally important.
On operations, email productivity must remain unaffected. The number of IT tickets related to email delivery is a good proxy, as is the availability and uptime of the email security service. Most importantly, measure the time your security team spends on email security. A SEG demands heavy lifting from deployment through ongoing maintenance. If Cloudflare Area 1 frees up that time for other security priorities, that is as meaningful as stopping the phish itself.
Real-world replacement in action
Many customers have already made the transition. One Fortune 50 global insurance provider serving 90 million customers across 60 countries found its SEG insufficient for stopping phishing—and searching for missed phish once they reached the inbox was onerous. They needed a service that could catch these attacks and support a hybrid architecture of cloud and on-premises mailboxes.
After deploying Cloudflare Area 1 downstream of their Microsoft 365 and SEG layers, the provider was protected against more than 14,000 phishing threats in the first month, with none reaching a user's inbox. The one-step integration meant minimal maintenance and operational overhead. Automated message retraction and post-delivery protection also enabled easy search and remediation of any missed phish.
Replacing a SEG fits naturally into a broader Zero Trust roadmap. For teams weighing the move, assessing the new service's efficacy before a full cutover remains a straightforward path.



