
An independent test measured what email security products add on top of Microsoft 365’s native filtering. Coro was certified with zero false positives and a 100% detection rate against residual malware.
In June 2026, the independent security testing organization Virus Bulletin published the results of its inaugural VB ESA – M365 comparative test, a new program built to evaluate email security products that supplement Microsoft 365’s native protection. Coro Email Security earned VB ESA – M365 certification in this first test period, with zero false positives against legitimate mail and a perfect score against the malware that reached it. The results independently validated Coro’s ability to stop the threats Microsoft 365 missed without disrupting legitimate business communications.
What separates this certification from most is the scoring. Products earned credit only for catching messages that Microsoft 365 had already allowed through, the mail that would otherwise have landed in an inbox.
Most organizations evaluating an email security product are not starting from zero. They run Microsoft 365, which ships with its own filtering layer, Exchange Online Protection. They’re less concerned about how a product performs in isolation. Instead, they care about how much protection the product adds on top of what they already have.
VB ESA – M365 was built to answer that question. Over a 17-day period in May 2026, Virus Bulletin ran a continuous stream of live email through a Microsoft 365 tenant: 25,610 spam messages, 3,704 phishing messages, 234 malware-bearing messages, and 376 legitimate messages. None of these were constructed for the test. Every sample came from the wild.
Nearly 30,000 live email messages over 17 days. None constructed for the test.
The key difference from a typical benchmark is what Virus Bulletin excluded from scoring. Rather than measuring every email processed, the test focused only on messages that Microsoft’s native filtering allowed through. Everything Microsoft 365’s native filtering stopped was removed from scoring entirely. Products were measured only on the residual set, the messages that passed through native filtering and would have landed in a user’s inbox.
In practical terms, the methodology answers the question most IT teams actually care about: How much additional protection does an email security solution provide beyond Microsoft 365 alone?
That residual set is exactly what an add-on security layer is meant to handle: messages that had already passed through one filtering layer.
Virus Bulletin calls the resulting metric the incremental detection rate, or IDR. In other words, the score reflects what the add-on product caught after Microsoft 365 had already done its filtering.
The test conditions mirror common deployments in another way. The Microsoft 365 tenant ran Exchange Online Protection alone, with no Defender for Office 365 overlay, so that measured results could be attributed to the tested products rather than to a richer native stack. Products connected the way they would in production; Coro Email Security was tested as an integrated cloud email security solution, connecting via API with no changes to mail routing. This approach closely reflects how many organizations deploy layered email security today, making the results more representative of real-world environments rather than lab conditions.
 All six malware-bearing messages that evaded Microsoft 365’s filtering were blocked, earning the Malware 100 badge.
Certification requires a spam IDR of at least 80%, with no more than one false positive. Coro Email Security cleared that bar with a spam IDR of 91.7%, catching 99 of the 108 spam messages that made it past native filtering.
Beyond meeting Virus Bulletin’s certification requirements, two results stand out for organizations evaluating layered email security solutions.
First, malware. Six malware-bearing messages passed through Microsoft 365’s filtering during the test period. Coro Email Security blocked all six, earning the Malware 100 badge, awarded for zero malware misses combined with zero false positives. For security teams, that means every malware message that bypassed Microsoft’s native protection was stopped before reaching end users.
Second, legitimate mail. Coro Email Security recorded zero false positives across the 371 legitimate messages that reached it. That balance – strong threat detection without disrupting legitimate communication – is critical for organizations that can’t afford unnecessary business interruptions.
Zero false positives across all 371 legitimate messages that reached Coro Email Security.
Detection rates matter, but minimizing false positives is equally important because it’s what IT teams experience every day. A wrongly quarantined message can become a support ticket, a missed invoice, or a delayed customer response. A filter that blocks aggressively while flagging legitimate mail has not reduced the workload for the team running it. It has shifted the work to quarantine review and support.
For lean IT teams, that distinction matters more than for anyone else. There is no dedicated staffer reviewing quarantine queues. Every legitimate message that is incorrectly blocked creates additional work, delays business operations and erodes confidence in the security platform. For smaller teams, catching threats without creating another queue to manage is what makes the result useful. For lean IT teams, effective security should reduce operational burden, not create more of it.
Vendor-run benchmarks are useful, but independent testing provides an additional level of confidence because every participating product is evaluated using the same published methodology and under identical conditions. VB ESA – M365 limits that discretion by using a published methodology and the same conditions for each participant. The methodology is public, the email corpus is live and uncontrolled, and the same conditions apply to every participant. Virus Bulletin also runs the program continuously, with results published on an ongoing schedule, so certification reflects sustained performance rather than a single favorable snapshot.
That is the value of this certification for anyone evaluating email security for a Microsoft 365 environment: Virus Bulletin measured what Coro Email Security contributes under published test conditions, in a Microsoft 365 environment running native filtering alone, and certified the result.
Coro Email Security operates within the Coro platform, which consolidates endpoint, email, network, and cloud security in one place. The platform is designed for teams managing multiple security areas with limited staff. This certification independently validates one of the platform’s core strengths: delivering meaningful protection against the threats that evade Microsoft 365’s native defenses without adding unnecessary operational overhead. For organizations evaluating layered email security, the results demonstrate Coro’s ability to strengthen existing Microsoft 365 protection while maintaining the uninterrupted flow of legitimate business communications.
The full report, including the complete methodology and detailed results tables, is available from Virus Bulletin.





