Back to Learning CenterEmail Authentication

Abnormal email security

By Samuel ChenardJuly 28, 20265 min read
Abnormal email security

Abnormal email security is Abnormal AI's cloud email-security offering. Its public materials describe an API-connected product for Microsoft 365 and Google that uses behavioral signals to identify email threats and support remediation. That is a product description, not proof of effectiveness in a specific tenant. Evaluate its permissions, mail-flow fit, investigation evidence, remediation timing, and false-positive handling before deciding whether it closes a documented gap.

At a glance

Quick takeaways

  • Abnormal describes its Email Security offering as API-deployed cloud email security.
  • Its public materials position behavioral context as distinct from rule or signature matching.
  • API-connected email security and an MX-routed secure email gateway have different deployment questions.
  • DMARC validates authorized use of the visible From domain. It does not assess message legitimacy.
  • A tenant-specific evaluation should test detection, response, investigation, and rollback with approved scenarios.

What Abnormal email security public materials describe

Abnormal's Email Security product page describes a cloud email-security platform that builds behavioral models around people and vendors connected to an organization. The same page describes API deployment and coverage for Microsoft 365 and Google. Those statements establish the vendor's published product position, not an independently measured detection outcome.

The threat model matters when comparing products. A team worried about supplier impersonation, compromised accounts, or lookalike senders should define those cases explicitly. For the wider category and trial scorecard, see how to compare anti-phishing software. For a separate explanation of the attack pattern, see email impersonation and prevention.

How its deployment differs from a gateway and DMARC

An API-connected product generally raises questions about authorization scope, message access, response actions, and coexistence with native controls. An MX-routed gateway raises mail-routing and gateway-operation questions instead. Those are different architectures, so do not assume that every email-security product is a secure email gateway. Read how secure email gateways protect an organization for the gateway model.

Decision map separating API-connected email security, MX-routed gateways, and DMARC evidence
Source: Original deterministic decision map based on Abnormal Email Security product material and RFC 9989, DMARC. View the full-size decision map.

DMARC is another boundary. RFC 9989 defines it as a mechanism through which a domain owner can enable validation of the domain used in an email's visible From field and publish handling preferences and reporting requests. It does not make a claim about whether a message is otherwise legitimate or valuable. A public DMARC checker can inspect a domain's published DMARC record, but it cannot evaluate Abnormal in a tenant or prove an inbound filter's effectiveness.

What to collect before an evaluation

Use a written test plan that keeps vendor statements, tenant evidence, and protocol evidence separate. The blank fields below are intentional. A criterion should remain unscored until the evaluation produces evidence.

YAMLyaml
abnormal_email_security_evaluation:
  connection_and_permissions:
    evidence: "approved authorization scope and data-access review"
    result: null
  representative_attack_cases:
    evidence: "authorized impersonation and compromised-account scenarios"
    result: null
  response_operations:
    evidence: "timestamps for investigation, remediation, release, and rollback"
    result: null
  false_positive_handling:
    evidence: "known-good business mail and exception workflow"
    result: null
  native_control_coexistence:
    evidence: "documented baseline and change record"
    result: null
decision_rule: "Do not score a criterion without tenant-specific evidence."

Ask who owns each evidence item before the evaluation begins. Include approved business mail as well as authorized simulations, then retain timestamps and the steps needed to investigate, release, or reverse an action. Do not send realistic phishing to users without authorization and safeguards. The data sheet's descriptions of remediation and investigation features are useful questions for the evaluation, but they do not replace observed results.

What a public record check can and cannot answer

Sender-domain authentication remains worth checking alongside an inbound-security evaluation because it addresses direct spoofing of domains you control. It is not a substitute for evaluating display-name impersonation, lookalike domains, malicious content, or a compromised mailbox. Inspect the published record before changing policy, then compare it with message and trial evidence. A public record alone cannot disclose an organization's Abnormal configuration, permissions, detections, message timing, or false positives.

Check the sender-domain record beside the trial

Use Palisade's DMARC checker to inspect the published DMARC record for a domain in scope, then keep that DNS evidence beside the tenant trial record. The checker can show public DMARC publication and policy information. It cannot test Abnormal, inspect a tenant, reproduce a detection, or prove inbound-filter effectiveness.

Evidence

Sources and further reading

Questions readers ask

Frequently asked questions

Keep going with AI

Ask AI how this applies to you

Take this guide to your assistant — each question opens pre-filled, with a link back to this page so it can read the details.

  • Is Abnormal email security a secure email gateway?
  • How does this apply to my domain?
  • What should I do about it, step by step?

Share this article

Samuel Chenard

Written by

Samuel Chenard

CEO & Co-Founder, Palisade

Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.

More from Samuel

Related articles