What you are evaluating
Cover the proposed Core Email Protection deployment explicitly. Threat Response Auto-Pull, collaboration protection, outbound controls and other portfolio features require separate entitlement and integration confirmation.
A useful evaluation context
Consider for organizations evaluating a dedicated email protection platform and willing to validate how its selected modules work together.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Advertised inspection combines sender and behavioral context with URL and attachment analysis.
- An API deployment can integrate with Microsoft 365 without changing MX routing.
- The broader portfolio includes post-delivery response and collaboration products that must be selected deliberately.
Where it fits in the work
- Document whether the proposal uses Core Email Protection API or SEG and which mail flows it sees.
- Review a synthetic impersonation verdict in the proposed investigation console.
- Verify the licensed remediation path and inspect what happens to forwarded copies.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A test purchase-order message reaches multiple authorized training mailboxes.
Evidence to look for
Trace the verdict and prove the selected response module can locate and handle the relevant copies; do not assume a portfolio diagram grants that capability.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which API or SEG edition is in scope?
- Does the quote include the response workflow demonstrated?
- What content and metadata are retained, where, and for how long?