Email Security with Darktrace / EMAIL
Real supplier. Real account. Real email thread. Changed banking details. The most expensive email attacks on South African businesses do not look like attacks — they pass authentication, come from genuine accounts and read exactly like the last twenty messages in the thread.
Darktrace / EMAIL learns how your organisation actually communicates and stops the message that is technically legitimate and behaviourally wrong. ROI Technologies is a Premier Partner in the Darktrace Defenders Partner Program, based in Randburg, supporting organisations across South Africa.
The dangerous email is the one that looks legitimate
Spam filters solved spam. What they did not solve is the attack that has no malware, no bad link and no spoofed domain — just a real person's mailbox in the wrong hands. These are the patterns we see most often:
- Compromised supplier accounts. A supplier's mailbox is taken over, the attacker reads the thread, and the next invoice arrives from the real address with new bank details.
- Account takeover inside your own organisation. Stolen credentials, a login from an unusual location, a hidden inbox rule that forwards finance mail — weeks can pass before anyone notices.
- Executive impersonation. A short, urgent message "from" a director asking for a payment or a change to payroll, timed for when they are known to be travelling.
- Targeted phishing. One email, written for one person, referencing a real project and a real colleague. It never appears on a blocklist because it has never been sent before.
- Invoice and payment fraud. Banking details changed inside a genuine conversation, with nothing technically wrong with the message that carried them.
- Business email compromise is the fraud pattern South African banks and the legal profession actively warn their clients about, because it needs no technical exploit — only trust.
See how behavioural email security works
Under a minute: why the most dangerous email is the one that looks legitimate, and how Darktrace / EMAIL judges the message against the relationship rather than the blocklist.
Why gateways and filters let it through
A secure email gateway sits in the mail path and checks each message against what is already known to be bad: reputation lists, signatures, rules and sandboxes. That approach is effective against known and high-volume attacks, but can struggle when a message comes from a genuine account, contains clean links and makes a plausible request. Native Microsoft 365 filtering is far better than it was, but it is still judging the message, not the relationship.
Darktrace / EMAIL is not a gateway. It connects to Microsoft 365 through the API, sits alongside your mail flow rather than in it, and judges every message against what is normal for the sender, the recipient and the relationship between them. Darktrace's own positioning is that it should elevate, not duplicate, the protection you already have. Whether an existing gateway stays in place is a scoping decision, not a rule.
Darktrace / EMAIL: email security that learns your organisation
Four things Darktrace / EMAIL does differently, each drawn from how the platform is documented — not generic AI marketing:
Self-Learning AI, not threat feeds
Darktrace / EMAIL builds a behavioural profile for every user and for the organisation as a whole — who talks to whom, how, when and about what — rather than waiting for a threat to be catalogued somewhere else first.
Content, context and communication history
Each message is assessed on tone, intent, exposure and risk in the context of the actual relationship, not just its links and attachments. A supplier who has never mentioned banking details, suddenly doing so from an unusual location, stands out.
Autonomous response, proportionate to risk
Depending on context, Darktrace can take one of hundreds of actions — from rewriting or locking a link and adding a warning banner, through to holding the email entirely from the inbox — so your team is not choosing between "block everything" and "let it through".
Account takeover and internal mail
Anomalous logins, new inbox rules and unusual internal sending patterns are detected, and a compromised account can be disabled before it is used against colleagues or clients. Cyber AI Analyst produces a plain-language narrative for suspicious emails so your team understands what happened without reverse-engineering logs.
What's included in our Email Security service
Everything you need from a modern email security partner — delivered by our engineering team.
- Scoping against your actual environment: user count, Microsoft 365 configuration, existing gateway or filtering, and what has been getting through
- Darktrace / EMAIL licensing sized to your organisation
- Technical deployment and initial tuning led by Darktrace's engineers, coordinated by ROI Technologies as your local partner
- Integration with the rest of your security stack — SentinelOne on endpoints, Fortinet or Sophos at the perimeter
- DMARC and email authentication alongside, so your own domain cannot be spoofed — Darktrace / EMAIL protects what arrives; DMARC protects your name
- Local support, incident review and a single accountable contact in Randburg
Built for Microsoft 365 — no change to your mail routing
Darktrace / EMAIL integrates with Microsoft 365 and Exchange at API level. There is no MX change, no inline appliance and no interruption to mail flow during deployment. It works with the Microsoft protection you already licence rather than replacing it, and Darktrace and Microsoft work in partnership.
Is Darktrace / EMAIL right for your organisation?
Darktrace / EMAIL is typically best suited to organisations with approximately 150 users or more, although suitability depends on the environment and security requirements. It is a strong fit where email fraud has already cost money or nearly did, where a legacy gateway contract is up for renewal, where an internal IT or security team is overloaded by alerts, or where auditors, a board or a cyber-insurer are asking what stands between your finance team and a convincing fake invoice.
For smaller organisations we will usually recommend a different starting point: Microsoft 365 security hardening, multi-factor authentication, DMARC and email authentication, and staff security awareness training — as part of a layered cybersecurity service. That is not a lesser answer; at that size it is usually the right one, and we will say so on the call.
Why organisations choose ROI Technologies for Darktrace
Darktrace is sold by a number of partners in South Africa. Here is why organisations choose to buy it through us:
Premier Partner, local team
ROI Technologies is a Premier Partner in the Darktrace Defenders Partner Program, based in Randburg — vendor-backed deployment with a partner you can actually reach.
Honest about fit
If Darktrace / EMAIL is not the right answer for your size or budget, we will say so and point you to what is.
Layered, not bolted on
Email security only works as part of a defence that also covers endpoints, identity, perimeter and people. We already run those layers for South African businesses.
Established 2001. Rated 5.0 on Google.
A security-focused IT company with a track record, not a reseller that appeared last year.
Frequently asked questions
Is Darktrace / EMAIL a secure email gateway?
No. A gateway sits in the mail path and checks messages against known threats. Darktrace / EMAIL connects to Microsoft 365 through the API, sits alongside mail flow, and evaluates each message against learned behaviour for your users and their relationships. Whether an existing gateway stays in place is a scoping decision, not a rule.
Does it replace Microsoft Defender for Office 365?
Darktrace positions Darktrace / EMAIL as a behavioural layer that elevates rather than duplicates native Microsoft protection. Most deployments keep Microsoft's built-in security and add Darktrace for the targeted, novel and account-based attacks that reputation and signature filtering miss.
Is ROI Technologies a Darktrace partner in South Africa?
Yes. ROI Technologies is a Premier Partner in the Darktrace Defenders Partner Program. We scope, supply, coordinate deployment and support Darktrace / EMAIL for organisations across South Africa, working directly with Darktrace.
How is this different from DMARC?
DMARC and email authentication stop other people sending email that pretends to come from your domain. Darktrace / EMAIL protects your people from malicious email arriving in their inboxes — including mail from genuine, compromised accounts that DMARC will pass. They address different risks and belong together; one is not a substitute for the other.
Is Darktrace / EMAIL for small businesses?
It is typically best suited to organisations with approximately 150 users or more, although suitability depends on the environment and security requirements. Below that we usually recommend Microsoft 365 hardening, MFA, DMARC and awareness training first, and we will tell you so on the call.
How long does deployment take and will email be interrupted?
Because Darktrace / EMAIL integrates through the Microsoft 365 API, there is no change to mail routing and no interruption to mail flow. Darktrace's engineers lead the technical deployment and initial tuning, and the AI spends an initial period learning your organisation's normal patterns before response actions are tuned. We agree the exact timeline in scoping.
What does Darktrace / EMAIL cost?
It is licensed per user and scoped to your environment, so there is no honest list price to publish. Book a qualifying call and we will confirm fit, size the deployment and give you a clear written proposal.
Trusted by South African businesses
"Lamia is highly knowledgeable in cybersecurity, very professional, and always goes the extra mile to ensure systems are safe and secure. Highly recommend."
"A very professional outfit. They know everything about networks, security, printing, servers. A fine bunch of experts in everything IT."
"Great company with excellent service and a friendly team. Decide is especially reliable, easy to work, and quick to resolve issues."
"Tatenda and ROI team provides outstanding IT support and is an essential contributor to our workplace productivity."
"Great professional service from Lami and Zain..keep it up"
Other IT services
Cybersecurity Services
ROI Technologies delivers end-to-end cybersecurity services including EDR/XDR endpoint protection, vulnerability scanning, network security and compliance. We support SentinelOne and Sophos Intercept X for endpoint protection.
Learn moreDMARC & Email Authentication
DMARC implementation and email authentication for South African businesses — powered by Sendmarc. SPF, DKIM and DMARC enforcement from setup to full p=reject.
Learn moreMicrosoft 365
ROI Technologies manages your Microsoft 365 environment end-to-end — from initial tenant setup and licensing to Exchange Online, SharePoint, Teams, OneDrive and Entra ID (Azure AD) configuration and ongoing support.
Learn moreFind out whether Darktrace / EMAIL is the right fit
A 20-minute qualifying call. We will ask about your user count, your Microsoft 365 setup, what email security you have today and what has been getting through. If Darktrace / EMAIL is the right answer we will scope it; if it is not, we will tell you what is.
Book a qualifying call