# Best email security software compared

> Compare email security software on deployment model, threats named and published pricing, using first-party vendor evidence read on 12 August 2026.

There is no single best email security product. The right one depends on where you want protection to sit: a gateway or API filter that inspects inbound mail, the filtering already included with Microsoft 365 or Google Workspace, or the authentication layer that stops your own domain being spoofed. This comparison records what seven vendors publish on their own pages, which deployment models they document, and which of them show a price. Detection quality cannot be tested from a vendor page, so nothing here is ranked on it.

## Quick takeaways

- **Deployment is a setting inside most of these products.** Proofpoint, Mimecast, Barracuda, Abnormal and Cloudflare each document a connection that leaves MX records alone.
- **Three of the eight options publish a list price.** Microsoft, Google and Palisade. The other five show none.
- **Microsoft 365 already gives you a filtering baseline.** Anti-malware, anti-spam and anti-phishing protection is on by default and cannot be switched off.
- **Filtering and domain authentication are separate purchases**, even when one vendor sells both.
- **Ask what an administrator can do with a verdict.** That decides what a false positive costs.
- **Every fact below was read from a vendor page on 12 August 2026.**

## Who this comparison is for

An IT admin, security lead or MSP technician told to pick email security software, who wants the shortlist cut down by checkable facts. It assumes mail runs on Microsoft 365 or Google Workspace. If "email security gateway" is doing the work in your requirements document, read [what an email security gateway is](/learning/email-security-gateway) first, because the label covers several architectures. Head-to-head evaluations of authentication platforms sit on the [comparison hub](/compare).

## How the options were evaluated

Each option was read on its own product or documentation pages on 12 August 2026. Review sites and marketplace listings were excluded. Four things were recorded, and nothing beyond them was inferred:

- **Deployment model.** Whether the vendor documents an MX-routed gateway, an API connection, post-delivery inspection, or a choice among them.
- **Threats named.** The categories the vendor claims to address, in its own words.
- **Published pricing.** Whether a price appears on the vendor's own page. Discounts, minimums and contract terms are not knowable from outside.
- **Admin control.** What an administrator can do with a verdict once the product has produced one.

Several pages advertise detection percentages. Each vendor measured its own, and no statement below rests on one.

### Criterion: what you already own

Microsoft documents anti-malware, anti-spam and anti-phishing protection as included in all organizations with cloud mailboxes, and on by default through the default threat policies. An admin cannot turn them off, but can override them with preset or custom policies. See [Microsoft's built-in security features for cloud mailboxes](https://learn.microsoft.com/en-us/defender-office-365/eop-about). Measure a product against that baseline, not against zero.

### Criterion: admin control over the verdict

Google documents three actions an administrator picks per setting: keep the message in the inbox with a warning, move it to spam, or hold it in admin quarantine for review before release. See [Google's advanced phishing and malware protection settings](https://knowledge.workspace.google.com/admin/gmail/advanced/advanced-phishing-and-malware-protection). Put the same question to every vendor on your shortlist.

![How email security products are deployed: gateway, API connected, native provider controls, and the authentication layer](/images/editorial/best-email-security/best-email-security-deployment-models.webp "1200x488")

*Source: Palisade.*

## The options, one by one

Listed alphabetically, from each vendor's own page.

### Abnormal Security

[Abnormal's inbound email security page](https://abnormal.ai/products/inbound-email-security) states "Deploy in 60 seconds via API. No MX changes." and describes the product as built for attacks with no payload and no prior signature. Abnormal positions itself as combining with Microsoft or Google to replace a secure email gateway, which is the vendor's position rather than a tested outcome. Its [platform page](https://abnormal.ai/platform) lists native API integrations with Microsoft 365, Google Workspace, Okta, CrowdStrike and Splunk, "no agents, no proxies", and eleven further modules.

### Barracuda Email Protection

[Barracuda's Email Protection page](https://www.barracuda.com/products/email-protection) states that the product connects to Microsoft 365 or Google Workspace with no mail exchange (MX) changes and is operational in minutes rather than weeks. Barracuda names phishing, malware, spam, account takeover, domain fraud with DMARC and post-delivery weaponization among the threats covered, and names Barracuda IQ and Bailey as its detection and explanation technology.

### Cloudflare Email Security

[Cloudflare's Email Security documentation](https://developers.cloudflare.com/cloudflare-one/email-security/) documents three deployment approaches: an API connection, post-delivery inspection through BCC or journaling, and pre-delivery placement through MX or inline. Cloudflare says the service uses AI, threat intelligence and security rules to analyze every incoming email, and names phishing, malware, business email compromise, vendor email fraud and spam. The page states no price.

### Google Workspace and Gmail

[Google Workspace pricing](https://workspace.google.com/pricing) publishes per-seat prices for the Business tiers and lists "Phishing and spam protection that blocks more than 99.9% of attacks" on every one of them, which is Google's own figure. Data loss prevention, S/MIME encryption and context-aware access are listed under Enterprise, which is quoted by sales. The advanced protections are administrator settings rather than a separate product.

### Microsoft Defender for Office 365

Microsoft documents a ladder rather than one product. [Its Defender for Office 365 overview](https://learn.microsoft.com/en-us/defender-office-365/mdo-about) says Plan 1 "protects email and collaboration features from zero-day malware, phishing, and business email compromise (BEC)" through Safe Attachments, Safe Links, impersonation protection and Real-time detections. Plan 2 "adds phishing simulations, post-breach investigation, hunting, and response, and automation", naming Threat Explorer, Campaigns and Automated Investigation and Response.

### Mimecast Advanced Email Security

[Mimecast's Advanced Email Security page](https://www.mimecast.com/products/email-security/) presents two paths to one product. The MX-based path routes all incoming mail through Mimecast's gateway first and intercepts threats in line. The API path connects in minutes, with no MX record changes and no mail flow disruption. Mimecast names phishing, business email compromise, ransomware and zero-day exploits. Which capabilities differ between the two paths is not stated, so ask.

### Proofpoint Core Email Protection

[Proofpoint's Core Email Protection page](https://www.proofpoint.com/us/products/threat-defense) lists "Flexible Deployment via API or SEG", so the gateway question here is a configuration decision rather than a choice between suppliers. The page names phishing, business email compromise, ransomware and account takeover, describes post-delivery detection with automated remediation, and covers sandboxing for URLs and attachments. It integrates with Microsoft 365 and Google environments.

![Email security software comparison by deployment model, filtering layer, and domain authentication](/images/editorial/best-email-security/best-email-security-deployment-models.webp "1200x488")

*Source: Palisade.*

## How pricing was handled

Three of these options publish a price. [Microsoft's Defender for Office 365 page](https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365) lists Plan 1 at $2.00 per user per month and Plan 2 at $5.00 per user per month, both paid yearly on an auto-renewing annual subscription. Google publishes per-seat prices on its Workspace pricing page, though the currency and any promotional rate depend on your region. [Palisade publishes its plans and prices](https://www.palisade.email/pricing), including a free tier.

The others publish nothing. [Barracuda's plans page](https://www.barracuda.com/products/email-protection/plans) names three tiers, Advanced, Premium and Premium Plus, with a feature comparison and no cost figure. [Mimecast's product index](https://www.mimecast.com/products/) lists eight products with no price beside any of them, and Proofpoint's page routes buyers to a demo request. Abnormal and Cloudflare show no price on the pages cited above. Quoted pricing is normal in this segment and says nothing about cost.

## Where Palisade fits

Filtering and domain authentication are bought separately, even from one supplier. Mimecast, for instance, sells DMARC Analyzer as its own product beside Advanced Email Security on [its product index](https://www.mimecast.com/products/).

Palisade sits in that authentication row and nowhere else. [Palisade's documentation](https://docs.palisade.email/) covers DMARC, SPF, DKIM, BIMI and MTA-STS, domain onboarding, hosted DNS records, aggregate report processing, sender classification and PSA ticketing. It does not filter, sandbox, rewrite links in or quarantine inbound mail, so it replaces none of the products above. Its narrow job is your own domain: [hosted DMARC](https://docs.palisade.email/page-breakdowns/hosted-dmarc) publishes and maintains the record through a CNAME delegation, so a policy move needs no further DNS edit, and the documentation requires resolving the senders list before enforcement. If DMARC is new to you, start with [what DMARC is](/learning/what-is-dmarc).

## How to choose

- **You run Microsoft 365 and have not configured what you own.** Set up the built-in policies and measure first. Defender for Office 365 Plan 1 or Plan 2 is the smallest documented step up.
- **You need inspection in the delivery path.** Proofpoint, Mimecast and Cloudflare each document an MX or inline deployment. Expect a quote rather than a price.
- **You cannot change mail flow.** Abnormal, Barracuda, Cloudflare, Mimecast and Proofpoint all document a connection that leaves MX records untouched.
- **Attackers are spoofing your domain rather than reaching your users.** That is the authentication layer, and a separate purchase from every filtering product above.
- **You are not sure which layer is failing.** Run a domain through the free [email security score](/tools/email-security-score) before shortlisting anyone.

## Sources and further reading

Every page below was read on 12 August 2026.

- [Proofpoint Core Email Protection](https://www.proofpoint.com/us/products/threat-defense).
- [Mimecast Advanced Email Security](https://www.mimecast.com/products/email-security/) and the [Mimecast product index](https://www.mimecast.com/products/).
- [Barracuda Email Protection](https://www.barracuda.com/products/email-protection) and its [plans page](https://www.barracuda.com/products/email-protection/plans).
- [Abnormal inbound email security](https://abnormal.ai/products/inbound-email-security) and the [Abnormal platform page](https://abnormal.ai/platform).
- [Microsoft Defender for Office 365 overview](https://learn.microsoft.com/en-us/defender-office-365/mdo-about), [built-in security features for cloud mailboxes](https://learn.microsoft.com/en-us/defender-office-365/eop-about) and the [Defender for Office 365 plans and pricing page](https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365).
- [Cloudflare Email Security documentation](https://developers.cloudflare.com/cloudflare-one/email-security/).
- [Google Workspace pricing](https://workspace.google.com/pricing) and [advanced phishing and malware protection](https://knowledge.workspace.google.com/admin/gmail/advanced/advanced-phishing-and-malware-protection).
- [Palisade documentation](https://docs.palisade.email/), [hosted DMARC](https://docs.palisade.email/page-breakdowns/hosted-dmarc) and [Palisade pricing](https://www.palisade.email/pricing).

## Frequently asked questions

### What is the best email security software?

No product is best for every organization, because these products do different jobs. Microsoft and Google secure the mailbox you already pay for. Proofpoint, Mimecast, Barracuda, Abnormal and Cloudflare add inspection in the delivery path or through an API. Palisade works on domain authentication, which none of the others replaces. Decide which layer your evidence points at, then compare only those products.

### Do I still need email security software if I use Microsoft 365?

Not automatically. Microsoft documents anti-malware, anti-spam and anti-phishing filtering as on by default for every organization with cloud mailboxes, and those policies cannot be turned off. Configure them, apply the preset security policies, then see what still gets through. Defender for Office 365 Plan 1 and Plan 2 add impersonation protection, Safe Links, Safe Attachments, hunting and automation.

### Is a secure email gateway still required?

Not in every case. Barracuda, Abnormal, Cloudflare, Mimecast and Proofpoint all document a connection that needs no MX record change, and Cloudflare documents post-delivery inspection by BCC or journaling. A gateway remains the documented option when you want mail inspected before delivery, or when you route mail for systems other than Microsoft 365 and Google Workspace.

### Does email security software stop someone spoofing my domain?

Not by itself. Inbound filtering protects the mailboxes you own. It does nothing about mail an attacker sends to other people using your domain in the visible From address. That is what DMARC, with SPF and DKIM alignment, is for, and it is a separate purchase from every filtering product here.

### Which email security companies publish public pricing?

Microsoft publishes per-user list prices for Defender for Office 365, Google publishes per-seat Workspace prices, and Palisade publishes its plans. Proofpoint, Mimecast, Barracuda, Abnormal and Cloudflare publish no price on their own product pages, routing buyers to a quote or a demo instead.
