The job to be done
Interrupt a deceptive conversation before it becomes credential theft, a fraudulent payment, or a compromised account.
Email security helps a team distinguish trusted communication from impersonation, malicious content and account abuse, then contain messages that should not remain accessible. Start with how mail reaches a person: a gateway can inspect before delivery; an API integration can inspect and remediate mailbox content; native controls operate inside the email service. These deployment choices change permissions, latency, recovery and failure behavior. None can authorize a bank-account change on its own. Keep payment verification, identity protection and incident handling in the operating process.
What goes in
- Messages, attachments and links
- Sender authentication and conversation context
- Mailbox activity and user reports
What should come out
- Delivery decisions and reviewable detections
- Message investigation and controlled remediation
- Evidence for account and payment-response workflows
Inside the segment
These capabilities answer different questions. Use the distinction to define the work before assembling a shortlist.
Secure email gateways
Inspect routed messages before delivery using configured sender, content and threat policies.
Boundary: MX records, routing, allowlists and continuity matter. Internal messages may not cross the gateway.
API and integrated mailbox protection
Use cloud-mail permissions to inspect messages and take supported mailbox actions.
Boundary: API does not mean pre-delivery. Establish whether the selected integration uses post-delivery scanning, mail-flow connectors, or both.
Native email and collaboration controls
Apply the mail provider’s policies and investigation workflows across supported email and file services.
Boundary: Base mail filtering, advanced protection, investigation and training can have different entitlements.
Domain authentication and impersonation controls
Evaluate sender authentication and contextual signs that a message is pretending to come from someone else.
Boundary: A properly authenticated compromised mailbox can still send a fraudulent request. Authentication is not an approval of message intent.
Collaboration protection
Investigate malicious links, files and account activity in supported chat and file-sharing applications.
Boundary: Email coverage does not establish equivalent Teams, Slack, SharePoint or other application coverage.
How the work flows
Map the message path
List mailbox providers, sending applications, relays, forwarding rules and internal mail. Identify which controls see each path.
Bound access and protection
Review requested API permissions, approved administrators, data location and retention. Begin with a small test group and a documented rollback.
Tune with benign comparisons
Compare an authorized synthetic impersonation exercise with legitimate supplier correspondence. Record which evidence explains each verdict.
Contain and recover
Find every supported copy, choose quarantine or a reversible mailbox move, and confirm the action completed. Test release before relying on it.
Close the business loop
Use a trusted independent channel to verify changed payment details. Investigate the identity if a real sender account may be compromised.
The environment changes the question
Use these scenarios to adapt the evaluation to your organization. They describe operational concerns, not a determination of compliance.
Finance ↗
A fictional supplier asks the payments team to change bank details from a lookalike domain. A second message comes from an authorized but simulated compromised supplier account.
Evaluate: Compare technical evidence, then require a callback using an independently maintained contact record for both requests.
Utilities ↗
A maintenance contractor sends an unexpected attachment to a test operations-support mailbox shortly before a planned outage.
Evaluate: Verify the sender and maintenance work order without forwarding suspect content into operational networks.
Manufacturing ↗
A synthetic purchase-order thread is forwarded through a supplier relay and a shared procurement mailbox.
Evaluate: Check whether authentication results, original sender context and remediated copies survive forwarding and shared-mailbox handling.
Healthcare ↗
A fabricated referral containing no patient information is mistakenly quarantined during a training exercise.
Evaluate: Demonstrate an approved release path and alternate communication procedure without letting urgency turn into a blanket sender bypass.
What drives the operating cost
- Protected users and mailbox types, including shared mailboxes, guests and inactive accounts.
- Separate modules for sandboxing, advanced investigation, account protection, domain authentication, training and archiving.
- Mail routing changes, integration permissions, exception handling and false-positive review effort.
- Retention, support, managed response and time spent validating restoration or continuity procedures.
Questions worth asking
- Which traffic is inspected before delivery and which is examined afterward?
- Can investigators trace and reverse a remediation action?
- How are missed threats, false positives and account compromise handled?
Common assumptions to check
Passing domain authentication makes a payment request trustworthy.
Authentication helps establish authorized domain use. It does not prove that the sender account is uncompromised or that a business request is legitimate.
API protection always stops a message before it reaches the inbox.
Many API workflows scan after delivery. Some integrated products also use connectors for inline enforcement. Verify the actual message path and measure the exposure window.
Quarantine, soft delete and hard delete have the same recovery behavior.
These are different operations whose recovery depends on product, provider and retention. Test the chosen action and assign release authority before automating it.
APPLY THE IDEA / EVALUATION PLAN
Make the outcome observable.
Send benign impersonation examples between lab mailboxes. Trace sender authentication, message disposition, user reporting and a reversible quarantine action.
Build a controlled corpus
Use an authorized test tenant, fictional identities, inert links and benign attachments. Include ordinary mail, a display-name impersonation and a simulated changed-payment request; no live phishing or real customer data.
Measure the delivery window
Capture message arrival, verdict and completed action timestamps. Check forwarded and shared-mailbox copies, API throttling behavior and whether a person could view the message before remediation.
Prove safe restoration
Quarantine or reversibly move an ordinary test message, request release as an end user, approve as the appropriate administrator and verify the restored copy. Do not start with permanent deletion.
Reconstruct one decision
Export the message identifier, verdict evidence, rule or model explanation where available, actor and action result. Explain what remains unknown rather than reporting a verdict as proof.
Use synthetic data and an authorized test environment. Record scope, product edition, permissions, results, and recovery behavior.
Vendors & products
8 profilesAn editorial selection of relevant offerings, with documented scope and practical evaluation questions. Atlas Fold provides a separate provisional documentation assessment for selected offerings; inclusion in this directory is not a ranking.
Microsoft / Native email and collaboration protection
Microsoft Defender for Office 365
Plan 2 is the scored scope. Exchange Online filtering, Plan 1 and Plan 2 are not interchangeable; cross-product endpoint response and additional identity products are outside this assessment.
Proofpoint / Email protection with API and gateway deployment options
Proofpoint Core Email Protection
Cover the proposed Core Email Protection deployment explicitly. Threat Response Auto-Pull, collaboration protection, outbound controls and other portfolio features require separate entitlement and integration confirmation.
Mimecast / Cloud gateway and integrated email protection
Mimecast Email Security
The profile covers email security. Cloud Integrated configuration and Cloud Gateway configuration are distinct; archiving, continuity, training and other services should not be assumed to be included.
Abnormal AI / Behavioral API-based email protection
Abnormal Inbound Email Security
Inbound Email Security is the scope. Account protection, outbound DLP and training are separate evaluation questions. Vendor statements about speed or detection superiority are not independent test results.
Check Point / Integrated email and collaboration protection
Check Point Email Security
The scored configuration is Microsoft 365 email with enforcement and Mail Explorer, using the documented Email Security service. Messaging apps, file storage, DMARC management and other add-ons are not assumed to be in the email entitlement.
Cloudflare / Gateway and post-delivery email protection
Cloudflare Email Security
The scored configuration is Microsoft 365 API deployment with auto-moves. Inline link modification and gateway quarantine are outside that scope; API scanning starts after inbox delivery.
Barracuda / Email gateway, impersonation protection and response portfolio
Barracuda Email Protection
Evaluate the exact package and modules. The cloud Email Gateway Defense service is distinct from the Email Security Gateway appliance; managed XDR and backup are not automatically included.
Cisco / Cloud mailbox investigation and remediation
Cisco Secure Email Threat Defense
The scored scope is Microsoft 365 with read/write remediation. Cisco Secure Email Gateway and Cloud Gateway are separate products. Remediation applies to Exchange Online mailboxes, not on-premises mailboxes in a hybrid environment.