Deployment Wizard â protect your organization from phishing, malware, and email threats.
This wizard will guide you through deploying Cloudflare Email Security (formerly Area 1) for your organization. By the end you'll have active email threat scanning and the appropriate delivery controls for your chosen deployment method.
What this wizard covers
This determines which prerequisites you need to complete before deploying Email Security.
Exchange Online / Outlook. Most common enterprise setup. Supports all deployment modes.
Each method has different tradeoffs between protection level, speed of deployment, and mail-flow impact.
Email Flow Overview
Pre-delivery: Email Security sits in front of your mail server as the MX record
Pre-delivery. Highest protection. Blocks threats before they reach the inbox. Requires MX record changes.
Post-delivery. Scans after delivery via Microsoft Graph API. No MX changes needed. M365 only.
Post-delivery. Emails copied to Cloudflare via BCC. No MX changes. Supports M365, Gmail, Exchange.
Follow these steps in the Cloudflare Zero Trust dashboard.
Tell Email Security what to do with each threat disposition. This step is optional but strongly recommended.
Email Threat Dispositions Docs
| Disposition | Description | Recommended Action |
|---|---|---|
| MALICIOUS | Confirmed active threat campaign. Multiple phishing indicators triggered. | đ´ Admin Quarantine (block from inbox) |
| SUSPICIOUS | Likely phishing, under further automated analysis. | đ Admin Quarantine or Junk Folder |
| SPOOF | Fails SPF/DKIM/DMARC or has mismatching Envelope/Header From. | đĄ Admin Quarantine or Junk Folder |
| SPAM / UCE | Unsolicited commercial email / spam. | đĄ User-Managed Quarantine or Junk |
| BULK | Mass commercial mail (newsletters, marketing). | đĸ Junk Email Folder |
| CLEAN | No threats detected. | â Deliver to Inbox |
Almost done! Complete these final checks to confirm Email Security is active and scanning.
In Cloudflare Zero Trust, go to Email Security â Settings â Domain Management â Domains. Select View next to your domain. Confirm the Status shows Active.
Use an online DNS lookup tool (e.g., dig yourdomain.com MX or MXToolbox) to confirm your MX records now point to Cloudflare Email Security servers. DNS propagation can take up to 24â72 hours.
In Cloudflare Zero Trust, go to Email Security â Phishing Risk Assessment. You can trigger a test message or send a benign test email to confirm it appears in the Email Security dashboard with a disposition.
Navigate to Email Security â Overview. After emails begin flowing, you'll see metrics for detected threats, dispositions, and top targeted users. A live email stream can take 15â30 minutes to appear after setup.
Useful next steps