How Enterprise SOCs Correlate Email Gateway Signals With SMS Campaigns

Secure email gateways remain essential, but they do not see, filter, or block SMS and mobile messaging traffic. Email and SMS now represent two distinct high-risk attack surfaces with different observability, different attacker tactics, and different defensive requirements. Security teams need to maintain SEG controls while adding dedicated mobile messaging visibility, user reporting workflows, and cross-channel campaign correlation.
TL;DR:
- Attackers use SMS with shorter, more urgent messages that often bypass traditional security controls, making mobile threats harder to detect and block.
- Evasive techniques like QR code phishing, hosting on trusted sites, and CAPTCHA gating enable malicious messages to bypass gateways, increasing the need for user reporting and correlation.
- SMS open rates reach nearly 98 percent, which results in higher success rates for scams like impersonations, fake delivery notices, and callback frauds.
- Secure email gateways cannot inspect or block SMS traffic, making dedicated mobile messaging visibility and reporting essential for effective defense.
- Organizations should implement separate controls for email and SMS, including reporting mechanisms, endpoint defenses, and cross-channel campaign correlation to close visibility gaps.
Table of Contents
- 1. Comparing the attack surface, visibility, and controls
- 2. Modern email threats and the evasion techniques that bypass gateways
- 3. Smishing, robotexts, and mobile messaging abuse
- 4. Why SEGs cannot stop SMS threats
- 5. Detection and defense checklist for email and SMS
- 6. Operational playbook for triage and campaign correlation
- 7. How we close the visibility gap between email and SMS
- FAQ
- Sources
1. Comparing the attack surface, visibility, and controls
Email and SMS share a common goal for attackers, which is tricking a human into clicking, replying, or handing over credentials. The infrastructure behind each channel, and what defenders can actually see, differs sharply.
Email runs on SMTP, with messages passing through gateways, filters, and mail servers that security teams control or can inspect. A secure email gateway sits in that path and can analyze headers, attachments, links, and sender reputation before a message ever reaches an inbox. SMS runs on carrier signaling protocols and over-the-top messaging layers that organizations generally do not own or inspect. A text message arrives directly on a device, often through a telecom network the enterprise has no visibility into, with no equivalent inspection point before delivery.
That architectural gap shapes everything downstream:
- Metadata availability: email headers expose routing paths, originating IPs, and authentication results (SPF, DKIM, DMARC); SMS headers expose comparatively little, and sender ID spoofing is trivial on many routes.
- Content inspection: SEGs can scan links, attachments, and body text at scale before delivery; mobile carriers generally do not inspect message content for enterprise policy enforcement.
- Attacker lifecycle on email: reconnaissance, spoofed or compromised sender, payload delivery (link or attachment), and a credential harvesting or malware execution stage, often with time to detect and quarantine before the user acts.
- Attacker lifecycle on SMS: a short message with urgency and a link or callback number, delivered directly to a personal device, with no intermediate inspection layer and a much shorter window between delivery and action.
- Where SEG investment pays off: known malicious domains, attachment sandboxing, authentication enforcement, and post-delivery remediation across a controlled mail environment.
- Where SEG investment leaves a blind spot: any message, link, or impersonation attempt that reaches an employee, customer, or member through a text thread instead of an inbox.
The practical consequence is that a well-tuned SEG can meaningfully reduce email risk while doing nothing at all for the growing share of social engineering that arrives as a text message. Our own overview of phishing and smishing differences walks through how that visibility gap plays out across delivery channel, user behavior, and organizational risk in more detail.
2. Modern email threats and the evasion techniques that bypass gateways
Credential phishing remains the dominant objective behind email-based attacks. Microsoft Threat Intelligence detected approximately 8.3 billion phishing threats in the first quarter of 2026, and credential phishing accounted for more than 90% of payload-based attacks in that quarter.
Statistic: Microsoft Threat Intelligence detected roughly 8.3 billion email phishing threats in Q1 2026, with credential phishing making up the large majority of payload-based attacks. That volume alone explains why SEG tuning and authentication enforcement still matter, even as attackers increasingly route around them.
Business email compromise continues to pay off because it skips malware entirely. An attacker impersonates an executive, vendor, or partner, then asks for a wire transfer, a change in payroll banking details, or a batch of gift cards. There is no attachment to sandbox and often no malicious link, which makes BEC difficult for signature-based detection to catch. Typical indicators include a sudden change in payment instructions, urgency paired with a request to bypass normal approval, and a reply-to address that does not match the display name.
Attackers have also built an entire evasion stack specifically designed to get past SEGs:
- QR code phishing (quishing): embedding a malicious link inside an image rather than as scannable text, which defeats URL rewriting and many link-scanning engines.
- Calendar invite abuse: sending meeting invites with malicious links in the location or description field, a path many filters do not fully parse.
- Living off trusted sites (LOTS): hosting phishing content on legitimate platforms such as cloud storage or form builders, so the link itself resolves to a reputable domain.
- CAPTCHA gating: placing a human-verification step in front of the phishing page specifically to block automated SEG crawlers from seeing the final malicious content.
Industry reporting has tracked a rise in malicious emails that bypass SEGs entirely, reinforcing that gateway technology alone is insufficient against evolving phishing techniques, particularly as QR code phishing and LOTS-style hosting have grown. CISA’s phishing guidance specifically flags calendar invite abuse and cross-channel attack patterns as reasons to layer defenses rather than rely on a single control point.
For detection teams, the operational signals worth instrumenting include thread anomalies (a reply chain that suddenly changes tone or payment details), unusual sending infrastructure for an otherwise known domain, and spikes in zero-hour auto-purge (ZAP) activity, which can indicate a wave of messages that initially passed filtering and were later recalled once reputation data caught up.

3. Smishing, robotexts, and mobile messaging abuse
SMS-based social engineering, commonly called smishing, now functions as a parallel attack channel with its own tactics, its own infrastructure, and a notably higher success rate per message sent.
Statistic: Consumers reported $470 million in losses to scams that started with a text message in 2024, a five-fold increase since 2020. That trajectory signals a channel attackers are actively shifting resources toward, not a stable or declining risk.
The same FTC data spotlight notes that SMS open rates are estimated as high as 98%, far above typical email open rates, which helps explain why a short, urgent text so often outperforms a polished phishing email. People are conditioned to treat texts as personal and time-sensitive, and the compressed format leaves little room for the hover-over-the-link scrutiny that email training tries to instill.
Common smishing patterns include:
- Brand and delivery impersonation: fake package delivery or toll payment notices with a malicious link, often the single most reported scam category.
- One-time passcode interception: a message urging the recipient to forward a verification code, which attackers then use to complete an account takeover in progress.
- Callback scams: a text that asks the recipient to call a number rather than click a link, shifting the social engineering into a live phone conversation that bypasses link scanning entirely.
- Payroll and executive impersonation: a text appearing to come from a CEO or finance leader, requesting an urgent gift card purchase or a wire transfer, mirroring BEC but delivered to a personal device outside corporate email controls.
Several technical enablers make these campaigns cheap and hard to trace. Email-to-text gateways let anyone send an SMS from an email address, often without the sender needing a real phone number. SIM swapping and number spoofing let attackers impersonate a trusted contact’s number outright. Academic research on the SMS ecosystem documents how public SMS gateways are abused as an easy, low-cost distribution mechanism for malicious messages at scale, a structural openness that email, with its mature authentication standards, does not share to the same degree.
Multi-channel campaigns increasingly treat email and SMS as complementary stages rather than separate problems. An attacker may send a low-key phishing email first, then follow up with a text that references the same fake invoice or account alert to add urgency and legitimacy, exploiting the fact that most organizations monitor one channel closely and the other not at all.
4. Why SEGs cannot stop SMS threats
A secure email gateway inspects SMTP traffic: headers, envelope data, attachments, and links, all before a message reaches a mailbox. That inspection point exists because email infrastructure is built around store-and-forward routing that a gateway can sit inside. SMS has no equivalent architecture from an enterprise’s point of view. A text travels from sender to carrier to recipient device with no mail-server-like checkpoint that a company’s security stack can plug into.
This is not a configuration gap that a better SEG rule set fixes. It is a protocol-level boundary. Email-to-text gateways compound the problem by letting a message originate from an email address and terminate as an SMS, which means the sending infrastructure an SEG might otherwise flag is invisible by the time the message becomes a text. The gateway provider in the middle of that transaction, not the enterprise, is the only party positioned to see both ends of the trip.
Regulators have acknowledged this gap at the carrier level. The FCC’s Second Report and Order on targeting and eliminating unlawful text messages requires mobile carriers to block illegal texts once notified, extends Do Not Call protections to text messages, and places new obligations on gateway providers to block and trace unlawful traffic. Those are meaningful network-level controls, but they operate upstream of any individual organization and are reactive to notification, not continuous organizational monitoring. A carrier blocking a known spam campaign days after notification does not help a security team that needs to know whether its own executives or customers were targeted last week.
The practical result: carrier-level blocking reduces some volume, but it provides no substitute for an organization’s own visibility into which of its employees, customers, or members actually received a targeted message, what it said, and whether it is part of a broader campaign.
5. Detection and defense checklist for email and SMS
Email controls and SMS controls are not interchangeable, and a checklist that treats them as one list misses the point. They need to run in parallel.
For email, the baseline has not changed, it has just become more urgent to enforce completely:
- Enforce SPF, DKIM, and DMARC at the domain level, moving DMARC to a reject or quarantine policy rather than monitor-only.
- Keep SEGs tuned for zero-hour auto-purge (ZAP) and automatic retraction of messages that are reclassified as malicious after delivery.
- Instrument URL and attachment telemetry so analysts can see what a sandboxed link or file actually did, not just that it was blocked.
For SMS and mobile messaging, the controls look different because the inspection point moves from the network to the endpoint and the reporting pipeline:
- Stand up a reporting collection mechanism so employees, customers, or members can forward a suspicious text in seconds, without installing a heavyweight app.
- Deploy on-device filtering or mobile threat detection where feasible, particularly for executives and high-risk roles who are disproportionately targeted.
- Treat every reported message as a data point, not an isolated ticket, feeding it into a pipeline built for correlation rather than one-off triage.
Cross-channel work ties the two together: campaign correlation across reported messages, SIEM enrichment so a phishing indicator from email and a smishing indicator from SMS can be matched against the same infrastructure, and SOAR playbooks that automate containment once a pattern is confirmed. Set internal service-level targets for each stage, such as time to correlate a new report against existing campaigns, time to contain (blocking a domain or number internally), and time to notify a carrier or file a regulatory report.
Pro Tip: Treat a single smishing report as a sensor reading, not a closed ticket; the real value shows up only after a dozen reports from different users line up against the same URL or sender pattern.
6. Operational playbook for triage and campaign correlation
Turning scattered user reports into actionable intelligence requires a consistent collection and correlation process, not ad hoc review.
What to collect from every reported message, email or SMS, includes a full screenshot, the raw message text or headers, the sending number or address, any URLs exactly as written, and basic device context (platform, carrier where known, timestamp). Partial screenshots that crop out the sender field are a common and avoidable gap.
Correlation logic should look for shared infrastructure across reports:
- Shared URLs or redirect chains reused across multiple reported messages, even when the display text differs.
- Domain registration patterns, such as newly registered lookalike domains clustered around a date range.
- Timing clusters, where a burst of reports across unrelated users in a short window points to a coordinated send.
- Sender infrastructure reuse, including the same email-to-text gateway or spoofed number appearing across separate incidents.
When a pattern is confirmed, escalation has two tracks. Internally, that means SIEM ingestion of the indicators, a SOAR playbook to block the domain or number across managed devices, and threat intelligence sharing with peer organizations or an ISAC where relevant. Externally, that means filing a carrier traceback request for persistent SMS campaigns, reporting to the FTC through ReportFraud.ftc.gov or by forwarding the text to 7726, and looping in legal or communications teams when a campaign impersonates the organization’s own brand or executives at scale.
Pro Tip: A single reported text rarely justifies a carrier traceback request on its own; wait for the correlation step to confirm a pattern before escalating externally, so the request carries enough evidence to act on.
7. How we close the visibility gap between email and SMS
We built a platform recognizing that email security investments, however well tuned, provide no lateral protection against SMS-based attacks. Organizations need a dedicated channel for mobile messaging visibility, and that is the gap we close.
Security teams need a way to collect reported messages from employees, customers, members, or students, whether or not they have an app installed, and run that reporting through automated threat analysis. Reports can be correlated across the user population to surface coordinated campaigns, such as executive impersonation attempts, payroll or payment fraud, and waves of robotexts hitting a customer base at once, rather than leaving each report as an isolated ticket. Integrations with SIEM and API tooling can let that correlation feed into existing security operations workflows, and audit-ready reporting supports documentation that regulated industries need to demonstrate oversight.
Deployment models vary by who is being protected. Organizations can roll reporting and mobile threat protection out to employees and high-risk executives directly, or enable customers, members, and students to report suspicious texts without an app install. Managed security providers can extend similar correlation and reporting capability across multiple client environments. Our live threat intelligence feed shows current campaign examples drawn from reported messages, illustrating how correlation across many small reports turns into usable threat intelligence for a security team.
FAQ
Is email more secure than SMS?
Email generally offers more defensive tooling, including authentication standards like SPF, DKIM, and DMARC, and gateway-level inspection that SMS lacks entirely. That does not make SMS inherently less risky. SMS open rates run as high as 98%, which often makes a text more effective at prompting action than an equivalent email.
What are the different types of email threats?
The main categories are credential phishing, business email compromise (BEC), malware or ransomware delivery through attachments or links, and spoofing or domain impersonation. Credential phishing is currently the dominant objective, accounting for more than 90% of payload-based email attacks in Q1 2026.
What are the four types of security threats?
Security threats are commonly grouped into malware, phishing or social engineering, insider threats, and denial-of-service or infrastructure attacks. Messaging-based social engineering, including both email phishing and SMS smishing, falls under the social engineering category but increasingly spans multiple channels in a single coordinated campaign.
Why should you never delete spam emails?
Deleting a suspicious message without reporting it removes a data point that could help correlate a broader campaign targeting other employees or customers. Forwarding or reporting it instead, through an internal phishing report button or to the FTC and 7726 for text messages, keeps that evidence available for pattern analysis.
Sources
- Microsoft: Email threat landscape Q2 2026 — trends and insights
- FTC Data spotlight: top text scams 2024
- FCC: Targeting and Eliminating Unlawful Text Messages, Second Report and Order
- CISA: Phishing guidance — stopping the attack cycle at phase one