Back

What Dungeons & Dragons Can Teach Us About Zero Trust Email Security – by Mailprotector

By Christopher Hall, Partner Success Specialist at Mailprotector

You and your party are on a quest.

The king has tasked you with escorting a few golden geese from one city to another. Halfway through the journey, three guards stop you on the road.

Orders of the king, they say. Hand over the geese and they’ll make sure they’re delivered safely.

Do you trust them?

Rolling for Insight

That was the scenario I posed to the room during my lightning talk at MSPGeekCon 2026 in Orlando this May.

The Dungeons and Dragons setup wasn’t just for fun. It’s a dead-on illustration of the exact decisions that play out in email security every single day.

In the game, we have three options:

  1. Trust the guards are who they say they are and hand over the geese.
  2. Negotiate and see if we can accompany them on the delivery.
  3. Fight them and take the flock to the city ourselves.

You roll an insight check and get what we call in Dungeons and Dragons a Natural 1, which means we had to trust the guards. But of course, they’re only posing as guards. They’re actually hackers—er, I mean, bandits.

They take our geese, and suddenly everyone’s dealing with a big mess and a whole lot of cleanup.

Sound familiar?

It’s the Dungeons and Dragons equivalent of Business Email Compromise (BEC). You trust the wrong person one time and suddenly you’ve lost your livestock and the king’s trust.

Why the Current Defenses Don’t Actually Defend

How did we get here? Back in the dark ages when email was first introduced, it was designed for a select group of users who knew and trusted each other.

Things have changed. What was once used by a closed network is now open to the entire world. The only thing a bad actor needs to connect with you is your email address.

Until now, MSPs have had two options for protecting their clients from bandits and hackers:

Gateway solutions. These sit between the internet and the client’s email server. They scan messages before they reach the inbox and can block threats at the perimeter, but once an email gets through, you lose visibility and control.

API-based solutions. These connect directly to a client’s email provider and scan messages after they’ve landed in the inbox. They let everything in—good and bad—and then try to clean things up from there.

But by the time they detect a threat, it might be too late. All it takes is 26 seconds for the average person to click a malicious link after it hits their inbox. If one user falls for one well-crafted phishing email, all your proverbial geese are gone.

Some MSPs combine the two, which should make life easier but often leads to bigger problems.
The tools don’t talk to each other. There are two dashboards and two sets of rules to manage. The systems blame each other when something goes wrong.

It’s more complexity, but the same exposure.

The industry responded with a flood of end-user training and warning “solutions.” But when users are bombarded with banners about unknown senders and potential phishing scams every hour of every day, they tune them out.

What a Natural 20 Roll Looks Like in Email Security

Now, let’s go back to our Dungeons and Dragons table. Say I had rolled a Natural 20, which means automatic, perfect success, often with a fun little dramatic flair.

So we’re on the same road. Dealing with the same problem. But this time, before anyone can respond to the demand for the geese, a knight in shining armor appears and asks a simple question about your relationship to the “guards”:

Do you know them?

verify everything

You take a closer look and realize you’ve never met these people before in your life. And that’s all it takes. The knight searches the bad guys, finds regalia linking them to a local bandit crew, and the threat is handled before a single golden goose changes hands.

It’s the Dungeons and Dragons equivalent of zero trust email security.

You don’t assume anything is safe by default. And the threat is stopped before it ever reaches the inbox.

That’s the foundation of Shield, our zero trust email security product for Microsoft 365.

Unlike traditional email security tools, which ask, “Is this message a threat?” Shield asks a different question, “What messages does this user actually want to receive?” Everything else— threats, junk, noise—is untrusted by default.

Shield starts by building an initial trust network for each user based on their contacts and communication history. Every new sender outside that initial trust network must earn their place. Shield continues to learn and adapt and, eventually, fades into the background. The system gets more accurate over time without any admin intervention.

Instead of clobbing together a gateway and API integration, Shield offers the best of both worlds in one single system. The gateway stops threats before they reach Microsoft 365. The API acts on messages that make it to the mailbox.

Both layers share context in real time. Competitors who combine a third-party gateway with a third-party API can’t offer the same protection. Those systems don’t talk to each other, which creates gaps and conflicts Shield doesn’t have.

Want to Talk About Email Security? Or D&D?

MSPGeek Con 2026 was a great reminder of why we love this community. At the board game night, the lightning talks, and networking events we met so many great MSPs who care about their clients and want to get email security right.

If you want to talk more about Shield, visit mailprotector.com to request a demo. You can also find us in the MSPGeek Discord. Bring your questions to #v-mailprotector—we’re here to help.

Leave A Reply