Email security usually has three layers: stopping threats before delivery, removing malicious messages that already reached the mailbox, and protecting the account and OAuth access around the mailbox. Some products are mail gateways, some connect through Microsoft 365 or Google Workspace APIs, and some combine both approaches. Payload-free BEC is a mailbox-after problem. Native Microsoft or Google controls still do the commodity work. The products below cover the gap those miss.
Start with your mail architecture. If you already use a secure email gateway, post-delivery API protection may be the missing layer. If you want to replace the gateway, compare products that can inspect mail before delivery. If account takeover and malicious OAuth apps are the bigger concern, make sure identity and mailbox controls are part of the product you are evaluating.
If mail flow is messy and you want gateway plus post-delivery, start with Proofpoint, and write which deployment path the quote covers, because the July 2026 API path is no longer “gateway only.” If the tenant is Microsoft 365 or Google Workspace and you will not cut MX, IRONSCALES is the API-speed option. If the real incident is someone already in the mailbox, Material Security is the data-store product. If you still need an appliance, a VM, or Fabric correlation with FortiGate, FortiMail is the hybrid path. If the job is API BEC without changing MX, Abnormal. If you already run a gateway plus archive, Mimecast. If the tenant is Microsoft 365 and you want the published Plan 1 / Plan 2 rate first, Defender for Office 365. If you want an API layer from Check Point, Harmony Email. The method is on How we review tools.
What usually goes wrong when buying email security
Most quotes in this category fail for the same few reasons. The fix is operational, not a new acronym.
| Problem | Solution |
|---|---|
| The product uses a different deployment model from the one your mail environment needs | Confirm whether the product is gateway-based, API-based, or supports both |
| Nothing remediates the inbox after delivery | Ask whether post-delivery remediation is named |
| OAuth and data-at-rest get mixed on one line | Separate the mailbox API from the gateway |
| The public rate is for a different email product | Budget from the vendor’s email-security page |
How we evaluated email security platforms
We compared the platforms on whether deploy is a gateway or an API, whether post-delivery remediation is named, whether the product talks about OAuth or data at rest, and whether any price is public. Gartner placements did not move a ranking. Neighbor products sit under What we left out.
TL;DR: The 8 Compared
| Service | Best for | What to check |
|---|---|---|
| Proofpoint | Complex mail flow when you want gateway depth plus a mailbox-after path |
DeployCloud or gateway. Core Email Protection also via API for Microsoft 365 (17 Jul 2026)
JobInbound policy, click-time URLs, impostor detection, user-report pull-back
PriceQuote-only. Pricing is custom. Hornetsecurity is the MSP / SMB line
|
| IRONSCALES | API-first Microsoft 365 or Google Workspace with user-report triage |
DeployAPI consent. No gateway product. No MX cutover
JobMailbox pull-back, simulation, Winter 2026 agents. ATO and Teams on Complete
PriceAWS, 50-user minimum: Protect $3,600, Email Protect $4,200, Complete Protect $6,000 per year
|
| Material Security | When the mailbox is a data store: OAuth, archive, a stolen session |
DeployAPI on Google Workspace and Microsoft 365. Shared or dedicated tenancy
JobPost-delivery plus OAuth inventory. Agentic grant work on Advanced
PriceEssentials $4 / user / month annual. Advanced $6. ATO Resilience +$3, or $5 stand-alone
|
| FortiMail | Hybrid or on-prem mail, or a Fortinet estate that wants email next to FortiGate |
DeployAppliance, VM, or FortiMail Cloud. Workspace Security is the ICES layer
JobInbound gateway plus Fabric correlation. Cloud clawback for M365 / Workspace
Watch-outQuote-only. Scope the quote to gateway, Workspace Security, or both
|
| Abnormal AI | Microsoft 365 shops that want API BEC detection and will pay enterprise. |
DeployAPI. No MX for the core path
JobBehavioral BEC / inbound API
PriceQuote-only
|
| Mimecast | Shops that already run Mimecast, or want a gateway plus archive from one vendor. |
DeployGateway or API
JobInbound plus archive / continuity family
PriceQuote-only
|
| Microsoft Defender for Office 365 | Microsoft 365 tenants that want the published Plan 1 / Plan 2 rate before they buy a third-party API. |
DeployMicrosoft 365 native / API
JobEmail + collaboration security
PricePlan 1 $2.00. Plan 2 $5.00 yearly
|
| Check Point Harmony Email | Microsoft 365 or Google Workspace shops that want an API email layer from Check Point. |
DeployAPI
JobInbound / mailbox-after API
PriceQuote-only
|
The table is the decision; the sections are the proof.
Proofpoint

Proofpoint combines predelivery controls with post-delivery detection and remediation across phishing, BEC, ransomware, and impersonation. You can deploy it as a cloud service or a gateway. Targeted Attack Protection rewrites links at click time and sandboxes files. Impostor detection uses identity and behavior, not payload inspection alone. User-reported phish can be clustered and pulled back across mailboxes. The company states more than 80 of the Fortune 100 and over 10,000 large enterprises.
On 17 Jul 2026 Proofpoint put Core Email Protection API into Threat Protection Workbench for Microsoft 365. That is a mailbox-after path from a vendor most shortlists still treat as inbound-gateway only. If you were skipping Proofpoint because you would not cut MX, that reason aged out in July. Hornetsecurity, acquired for $1.8 billion and closed in December 2025, now runs as the MSP and SMB unit. The vendor offers both its traditional gateway products and an API-based Microsoft 365 option. Make sure the contract names the deployment path you actually plan to use.
Best for: Large enterprises that need granular policy, layered URL and attachment analysis, and quarantine workflows across messy mail flow.
What you get:
- Click-time URL rewriting and sandbox analysis for links and files.
- BEC and impostor detection on identity and behavioral signals.
- Automated user-report triage with post-delivery mailbox remediation.
- An API deploy for Microsoft 365 that does not require an MX cutover, plus a Hornetsecurity path for MSPs and smaller tenants.
Why we like it: Depth of policy is what lets a large team tune without breaking mail. The July API path is the other option: mailbox-after without changing MX.
Limits:
- Admin complexity and tuning effort are the consistent review themes.
- Cost is premium. The enterprise product is not sized for a 50-mailbox shop.
- Support response during heavy incidents varies in public reviews. Ask for the escalation path.
Price: Quote-only. Contact Proofpoint on mailbox count and modules, or a Hornetsecurity partner for MSP packaging. Pricing is custom on the email protection page.
IRONSCALES

IRONSCALES is API-based email security: adaptive detection, mailbox-level remediation, phishing simulation, and user engagement. The AWS listing puts the estate at more than 15,000 organizations and a network of 20,000-plus analysts. Setup is a Microsoft 365 or Google Workspace consent, not an MX cutover. Most customers, the listing says, spend under 12 minutes a day remediating.
Winter 2026 added three agents: Red Teaming, Phishing SOC, and Phishing Simulation. Complete Protect adds account-takeover detection, Microsoft Teams protection, outbound encryption, and awareness training. QR-code (quishing) detection is on the current product. There is no gateway product. Hybrid or on-prem mail needs a different tool.
Best for: Cloud-mailbox teams that want API deploy, automated cleanup, and a user-report loop that trains the model.
What you get:
- Mailbox-level pull of phishing, BEC, and ATO messages across affected inboxes.
- Red team, SOC, and simulation agents from the Winter 2026 release.
- Themis Co-Pilot as a gen-AI inbox assistant, a separate AWS dimension.
- Dynamic banners and campaign clustering so one report cleans a wave.
Why we like it: API setup is minutes. The 2026 agents target the two jobs that eat analyst time: triage and writing the next simulation.
Limits:
- API-only. No SEG for hybrid or regulated on-prem flows.
- Reviewers still note false positives and feature gaps on lower tiers.
- Modules stack. Price Complete if ATO and Teams are in scope.
Price: On the AWS Marketplace listing, 12-month dimensions at a 50-user minimum: Starter (phishing simulation) $0, IRONSCALES Protect $3,600, Email Protect $4,200, Complete Protect $6,000. Add-ons at $1,200 each: Security Training, Incident Management, Account Takeover Protection, Themis Co-Pilot. That is $6 / $7 / $10 per user per month at the 50-seat floor for the three paid bundles. A 20-mailbox shop is not buying that listing at list.
Material Security

Material Security is detection and response for Google Workspace and Microsoft 365 that treats the mailbox as a data store. Post-delivery email security sits next to file sharing, OAuth grants, and account-takeover controls. Shared and dedicated (single-tenant) deployments are both offered.
The pricing page is public. Essentials is $4 per user per month billed annually, plus a Shared Drive size fee (the minimum annual covers up to 1 TB). It includes inbound threat detection, an automated agent for user-reported phish, an OAuth app inventory, Shared Drive metadata, and workspace posture. Advanced is $6 and adds agentic investigation and remediation of OAuth grants, sensitive content in drives and email, and stronger identity detections. ATO Resilience is +$3 on a package, or $5 stand-alone: message-level MFA on historical sensitive mail and on password-reset / magic-link messages, so a stolen session does not become a searchable archive.
Best for: Teams whose real incident is someone already in the mailbox.
What you get:
- Post-delivery detection and flexible remediations (banner, speedbump, spam, delete).
- OAuth inventory on Essentials. Agentic classify-and-revoke on Advanced.
- Sensitive content and sharing controls on email and Shared Drives (Advanced).
- ATO Resilience: message-level locks on the mail an attacker would read first.
Why we like it: Every other tool here asks whether the message is malicious. Material also asks what the attacker reaches if they get in. No inbound filter sees an OAuth grant.
Limits:
- Navigation is dense. Budget policy time per business unit.
- Shared Drive storage is a second bill. Size it on the discovery call.
- Smaller public review base than Proofpoint or IRONSCALES.
Price: Published on material.security/pricing. Essentials $4 per user per month, billed annually. Advanced $6. ATO Resilience +$3, or $5 stand-alone. Volume discounts and dedicated tenancy are sales conversations.
FortiMail

FortiMail Email and Workspace Security is two products under one portfolio. The secure email gateway still ships as a physical appliance, a VM, or FortiMail Cloud. FortiMail Workspace Security is the former Perception Point ICES layer for cloud mailboxes, browsers, and collaboration apps. FortiGuard intelligence, DLP, identity-based encryption, and FortiSandbox sit on the gateway side. Fabric integration means an indicator seen in mail can inform FortiGate without a SIEM project.
Gartner placed Fortinet as a Challenger in the 2025 Magic Quadrant for Email Security. That is a useful reminder: you buy this for deployment flexibility and Fabric, not for a public seat price. The product page maps DLP and encryption language to SOX, GLBA, HIPAA, and PCI DSS. That mapping is theirs. Confirm the control on the quote, not on a compliance slide.
Best for: Hybrid and on-prem environments, regulated isolation, and existing Fortinet estates that want email in the same policy domain as the firewall.
What you get:
- Anti-spam, phishing, malware, and ransomware with outbreak detection.
- DLP and encryption the vendor maps to common regulated-data regimes.
- FortiMail Cloud scanning for Microsoft 365 and Google Workspace, with or without the gateway.
- Workspace Security for browser and collaboration beyond the inbox.
Why we like it: The API-native tools on this page cannot serve an isolated mail flow. FortiMail can. Fabric correlation is the bonus if FortiGate is already the edge.
Limits:
- Learning curve, dated UI, and more tuning than newer API tools show up in reviews.
- Cloud feature parity has lagged the appliance on some options. Check the product line.
- SEG and ICES names overlap. Scope the quote to gateway, Workspace Security, or both.
Price: Quote-only. The product page lists appliances, VMs, and cloud subscriptions (per mailbox or per user per year) without a public dollar. BYOL and PAYG images sit on public cloud. Partners quote the rest.
Abnormal AI

Abnormal AI is an API email-security product built around behavioral BEC and other payload-free attacks on Microsoft 365 and listed cloud mail. You do not change MX for the core API path. Detection sits after delivery: identity and behavior, not a link rewrite or a file sandbox. Pricing is custom. There is no public per-user rate.
That is the same deploy shape as IRONSCALES, with a different commercial path. IRONSCALES prints AWS bundles at a 50-user floor. Abnormal is an enterprise quote. If the tenant is already Microsoft 365 and the hole is lookalike threads that pass inbound, this is the API BEC row, not a training module and not a gateway appliance.
Best for: Microsoft 365 shops that want API BEC detection and will pay enterprise.
What you get:
- API deployment for cloud mail. No MX cutover on the core path.
- Behavioral detection aimed at BEC and other payload-free attacks.
- Mailbox-after remediation on the same API path.
- Quote-only commercial path. Pricing is custom.
Why we like it: Payload-free BEC is the job. Abnormal stays in the tenant via API, so you can add behavioral detection without moving MX, which is why it sits next to IRONSCALES as the enterprise alternative to a printed 50-user bundle.
Limits:
- Quote-only. There is no public per-user rate to model this week.
- Not a gateway appliance. Hybrid or isolated mail still needs a different door.
- Enterprise sales cycle. This is not a 20-mailbox self-serve buy.
Price: Quote-only. Pricing is custom on abnormal.ai.
Mimecast

Mimecast is the incumbent email-security suite that still sells a gateway and an API path. You can change MX, or you can stay on a mailbox-after API. Archive and continuity sit next to the secure-email product, which is why shops that already live here rarely rip it out for inbound-only. Pricing is custom. Make sure the order form names MX versus API, and whether archive or continuity is in the same line.
Switching cost is real. That is also the product advantage: inbound plus archive plus continuity from one vendor, instead of a new API on top of a mailbox you already pay Mimecast to hold.
Best for: Shops that already run Mimecast, or want a gateway plus archive from one vendor.
What you get:
- Gateway deploy when you will change MX, or an API path when you will not.
- Archive and continuity on the same product family as inbound email security.
- Impersonation and phishing controls next to the archive, not in a second vendor.
- Quote-only commercial path. Pricing is custom.
Why we like it: If you already run Mimecast, the suite is inbound plus archive plus continuity, not a training LMS. Replacing it for a new API often means moving the archive too.
Limits:
- Quote-only. There is no public per-user rate.
- Switching cost is real if you already live here. Confirm MX versus API on the order form.
- A new API-only shop may get to first pull-back faster on IRONSCALES or Abnormal.
Price: Quote-only. Pricing is custom on mimecast.com.
Microsoft Defender for Office 365

Microsoft Defender for Office 365 is the Microsoft 365 email and collaboration security product. Plan 1 is $2.00 per user per month paid yearly. Plan 2 is $5.00. Microsoft pricing, 25 Aug 2026. Plan 1 covers email and collaboration threats on Exchange Online, Teams, SharePoint, and OneDrive. Plan 2 adds hunting, automation, attack simulation, and XDR. You do not change MX to turn this on. It is the printed Microsoft baseline most third-party API quotes have to beat.
Tessian is not a ninth logo. It closed into Proofpoint Core Email Protection API in December 2023. Proofpoint is already on this list. Do not pay a retired brand.
Best for: Microsoft 365 tenants that want the published Plan 1 / Plan 2 rate before they buy a third-party API.
What you get:
- Plan 1 at $2.00 per user per month paid yearly for email and collaboration security on the Microsoft 365 workloads.
- Plan 2 at $5.00 per user per month paid yearly, adding hunting, automation, attack simulation, and XDR.
- Native deploy in the tenant. No MX cutover to start.
- A published list rate you can put next to Material’s $4 / $6 plans and the IRONSCALES AWS floor.
Why we like it: If the tenant is already Microsoft 365, Defender for Office 365 sits in the same bill at a printed Plan 1 / Plan 2 rate, so you can price the baseline before you add a third-party API for payload-free BEC.
Limits:
- It is still the baseline. Payload-free BEC is why the other rows exist.
- Plan 2 is the hunting and XDR plan. Plan 1 is not that product.
- OAuth inventory and mailbox-as-data-store controls are Material’s job, not this product.
Price: Plan 1 $2.00 / user / month yearly. Plan 2 $5.00. First-party Microsoft Defender for Office 365 (25 Aug 2026).
Check Point Harmony Email

Check Point Harmony Email is Check Point’s API email-security layer for Microsoft 365 and Google Workspace, the product formerly sold as Avanan. You consent to the tenant. You do not change MX for the core path. Inbound and mailbox-after sit on that API. Pricing is custom. There is no public per-user rate on the product page.
If Check Point is already the security stack, this is the email door that stays in that bill, next to IRONSCALES and Abnormal on the API side of the grid. It is not a FortiMail appliance and it is not a Mimecast archive suite.
Best for: Microsoft 365 or Google Workspace shops that want an API email layer from Check Point.
What you get:
- API email security on Microsoft 365 and Google Workspace. No MX cutover on the core path.
- Inbound and mailbox-after controls in the Harmony Email product.
- A Check Point-branded path if that vendor is already the stack.
- Quote-only commercial path. Pricing is custom.
Why we like it: If Check Point is already on the estate, Harmony Email is the API mailbox-after product that stays in that stack, so you are not adding a second security vendor just to stop changing MX.
Limits:
- Quote-only. There is no public per-user rate.
- Not a FortiMail appliance. Isolated or on-prem mail still needs a gateway.
- Avanan is the older brand. The 2026 product page is Harmony Email.
Price: Quote-only. Product page: checkpoint.com/harmony/email-security.
Do you change MX, and what do you treat the inbox as?
This grid plots two questions. Across is how the product lands: a gateway that wants MX on the left, an API that leaves MX alone on the right. Up is the job: the mailbox as a data store at the top, inbound message security at the bottom.
Placement follows product language: gateway versus API, and message security versus mailbox-as-data-store. Proofpoint now also sells a Microsoft 365 API path (17 Jul 2026); it still sits on the gateway side because that is the enterprise policy purchase most quotes still describe. We mapped products, we did not score them.
What the published dollar actually covers
| Service | Published rate | What the line leaves out |
|---|---|---|
| Proofpoint | None. Quote-only | Enterprise versus Hornetsecurity versus the API product. Modules stack |
| IRONSCALES | AWS: Protect $3,600, Email Protect $4,200, Complete Protect $6,000 / year at 50 users | Whether Email Protect includes mailbox pull-back. Add-ons $1,200 each |
| Material Security | Essentials $4 / user / month annual. Advanced $6. ATO +$3 or $5 stand-alone | Shared Drive size fee. Minimum annual covers up to 1 TB |
| FortiMail | None. Quote-only | Appliance versus Cloud Hosted versus Cloud SaaS versus Workspace Security |
| Abnormal AI | Quote-only | API path. Not an MX cutover |
| Mimecast | Quote-only | Confirm MX vs API on the order form |
| Microsoft Defender for Office 365 | Plan 1 $2.00 / user / month yearly. Plan 2 $5.00 | Still the baseline the third-party rows exist to beat |
| Check Point Harmony Email | Quote-only | API path. Confirm Microsoft 365 versus Google Workspace on the quote |
What we left out
Mailbox neighbors that sit next door: a training LMS, a retired brand, or a gateway you already run under another logo.
- KnowBe4 - Training. Simulation is a module on some of the tools above. It is not a gateway and it is not a mailbox-after API.
- Tessian - Closed into Proofpoint Core Email Protection API in December 2023. Proofpoint is already on this list. Do not send a PO to a retired brand.
- Cisco Secure Email / ESA - Right if the gateway is already Cisco. Not a reason to reopen this eight.
- Barracuda Email Protection - Living gateway. Adjacent. Not a ninth logo here.
Questions before you change MX or grant an API
A quote that cannot answer these three is still a demo that scores mail.
- Do you need a gateway at all? Pure Microsoft 365 or Workspace can stay on an API. Hybrid, internal mail, or an isolated network still wants a gateway. Most migrations run both for a while.
- What happens after the message lands? Payload-free BEC routinely passes inbound. If pull-back is manual search-and-delete, you do not have post-delivery.
- Can it see OAuth? An inventory of grants is a different product from a message filter. Pair a message tool with identity governance if app-consent is in scope and the email product will not name grants.
Which email security platform should you pick
Complex mail flow, gateway plus a mailbox-after path: Proofpoint, and write which line the quote covers. Cloud mailbox, API, no MX: IRONSCALES. Someone already in the mailbox: Material Security, $4 / $6 on the public page. Hybrid, appliance, or Fabric: FortiMail, quote. API BEC: Abnormal, quote. Incumbent gateway: Mimecast, quote. Microsoft 365 baseline: Defender for Office 365, Plan 1 $2.00 / Plan 2 $5.00 yearly. Check Point API: Harmony Email, quote. Then put the pricing page next to a trace of a phish that already landed.
Frequently asked questions
Is an API email-security product the same purchase as a gateway?
No. A gateway sees the message before the inbox and usually wants MX. An API consents to the tenant and works after delivery. Proofpoint now sells both. IRONSCALES and Material are API-first. FortiMail is still the appliance and cloud-gateway buy.
Which email security platforms publish pricing?
Three print a number you can model this week. Material Security: Essentials $4 per user per month billed annually, Advanced $6, ATO Resilience +$3 or $5 stand-alone. Microsoft Defender for Office 365: Plan 1 $2.00 per user per month paid yearly, Plan 2 $5.00. IRONSCALES publishes AWS bundles at a 50-user minimum: Protect $3,600, Email Protect $4,200, and Complete Protect $6,000 per year. Proofpoint, FortiMail, Abnormal, Mimecast, and Harmony Email are quote-only.
Does a gateway miss mean the product failed?
Not by itself. Payload-free BEC is built to look like a real thread. The buy is whether you can still pull the message back, banner it, or lock the archive - and whether OAuth grants are in scope at all.






