What you are evaluating
Evaluate the exact package and modules. The cloud Email Gateway Defense service is distinct from the Email Security Gateway appliance; managed XDR and backup are not automatically included.
A useful evaluation context
Consider for organizations evaluating a packaged email-security stack or an MSP-operated service while retaining visibility into module boundaries.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Email Gateway Defense provides inbound and outbound filtering with deployment guidance for Microsoft 365 and Google Workspace.
- Impersonation Protection documents review of suspicious sign-ins, inbox rules and messages associated with account takeover.
- Incident handling can connect a reviewed account-takeover alert to response steps for tracked accounts.
Where it fits in the work
- Select the gateway service or appliance deliberately and map mail routing.
- Confirm which mailboxes the impersonation module tracks.
- Review an authorized synthetic incident and coordinate account containment with identity administrators.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A training account has a deliberately unusual but harmless forwarding rule.
Evidence to look for
Show the rule and associated message context, explain the account-takeover hypothesis and identify the authorized identity response rather than automatically disabling a production account.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which modules protect this mailbox type?
- Who owns routing, message release and account containment?
- Can the service export evidence and distinguish an account action from a message action?