Back to Learning CenterSecurity

Mimecast competitors: who else serves the same job

By Samuel ChenardAugust 12, 20269 min read
Mimecast competitors: who else serves the same job

Mimecast's closest competitors sort into four groups by how they attach to mail. Proofpoint and Cloudflare Email Security can sit inline in the MX path, the way Mimecast's gateway does. Barracuda and Abnormal connect over an API and leave MX records alone. Microsoft Defender for Office 365 and Google Workspace controls ship with the mailbox you already pay for. DMARC platforms work on the authentication layer and replace none of the above. Which group you shop in depends on whether you are replacing Mimecast or filling a gap next to it.

At a glance

Quick takeaways

  • Deployment model is the first split. A gateway takes the MX record, an API connector does not, and several vendors sell both.
  • Proofpoint, Barracuda, Abnormal and Cloudflare all document products that do the filtering job Mimecast's gateway does.
  • Microsoft 365 and Google Workspace already filter mail for their own mailboxes, so part of the work comes with the seat.
  • Microsoft is the only vendor here publishing a per user list price for email security.
  • Mimecast also sells archive, awareness training and governance products, so a filter alone is not a full swap.
  • DMARC sits outside the core filtering package at every vendor here, Mimecast included.

Who this comparison is for

This is for an IT team or an MSP that runs Mimecast, or has it on a shortlist, and wants the real field before a renewal conversation. It also helps when the trigger is narrower than the contract: a DMARC requirement, an archive requirement, or a mail flow change.

Who competes with Mimecast, grouped by how they deploy
Source: Palisade.

Cheapest is not a question published material can answer, because Mimecast shows no list price. What can be answered is which products do the same job in the same place in the mail path. The Palisade comparison hub collects the vendor pages, and the guide to email security software covers the category types in depth.

How the options were evaluated

Every claim below was read off the vendor's own product, plans or documentation pages on August 12, 2026. Reseller listings and review sites were excluded, because they commit the vendor to nothing.

  • Where the product attaches: the MX path, an API, or the mail platform itself.
  • What the vendor publishes commercially: list prices, tier names, or sales contact language.
  • Whether DMARC is inside the core package or sold beside it.
  • Whether the catalogue covers archiving, awareness training and compliance review.
An absence of published documentation is an open question, not a missing feature.
Mimecast competitor deployment models and evaluation criteria
Source: Palisade.

Source: Palisade.

Gateways that sit in the MX path

A gateway takes delivery first. Mimecast describes its own MX based deployment as perimeter protection that blocks mail in line, with all incoming mail routing through its secure gateway before the mailbox sees it. That is the shape a direct replacement has to match, and why a swap is a cutover project rather than a settings change.

Proofpoint sells the same shape. Its Core Email Protection page lists flexible deployment via API or secure email gateway, so one product covers both paths. Its buying page names four packages, Core, Tier 2, Tier 3 and Prime, with no figure against any. It does say budgetary pricing follows user licence count and contract term, with exceptions for consumption, the most specific cost driver statement in this group.

Cloudflare Email Security can also take the inline position. Its documentation lists pre-delivery deployment through MX or inline placement as one of three options. No price appears.

Platforms that connect by API

Barracuda states that Email Protection connects to Microsoft 365 or Google Workspace with no mail exchange changes, and calls the result operational in minutes rather than weeks. Its coverage list includes phishing, malware, spam, account takeover, domain fraud with DMARC, and post-delivery weaponization. Its plans page names Advanced, Premium and Premium Plus, with no price figure.

Abnormal takes the same position. Its inbound email security page says the product deploys in 60 seconds via API with no MX changes, and describes its target as attacks with no payload, no prior signature and nothing for a rule to flag. The same page states that Abnormal with Microsoft or Google replaces a secure email gateway, which is positioning rather than a tested result.

Cloudflare belongs here too, since it also documents an API mode and a post-delivery mode using BCC and journaling. And Mimecast documents an API path of its own. Deployment model is a configuration choice as often as a vendor choice, so ruling a vendor out on that basis will mislead you.

Controls you may already own

Microsoft's Exchange Online Protection documentation states that anti-malware, anti-spam and anti-phishing filtering are included in all organizations with cloud mailboxes and on by default. The wording is blunt: you cannot turn them off, though preset or custom threat policies can override them. That baseline runs behind whatever gateway you route through.

The paid step up carries the only published per seat figure in this article. Microsoft lists Defender for Office 365 Plan 1 at $2.00 and Plan 2 at $5.00 per user per month, both paid yearly. Its plan documentation splits them: Plan 1 covers prevention and detection with Safe Attachments, Safe Links and impersonation protection, and Plan 2 adds phishing simulations, post-breach investigation, hunting and automation.

Google Workspace bundles filtering into the seat as well. Every published tier on its pricing page lists phishing and spam protection that Google states blocks more than 99.9% of attacks, while data loss prevention, S/MIME and context aware access sit under Enterprise only. If Mimecast was held for baseline filtering, some of it is already paid for.

The layer that none of these replace

DMARC, SPF and DKIM decide whether a receiver believes mail claiming to come from your domain. That work points outward at your own senders, and an inbound filter does not do it, whichever way it is deployed. Mimecast's product structure agrees. DMARC Analyzer is a separately named product listed apart from Advanced Email Security, documenting aggregate, forensic and TLS reporting, SPF delegation, a record generator, record checkers and a recommendation engine. What the page does not claim is that Mimecast publishes or changes your DNS records for you. The record edits stay with your team.

The pattern repeats. Proofpoint puts this work in Email Fraud Defense and places hosted DMARC, DKIM and SPF in Prime, the top of its four packages. Barracuda lists DMARC reporting on its tiers. Microsoft tells administrators to publish those records themselves. If DMARC is the reason Mimecast is under review, the Mimecast DMARC alternative page covers that narrower question.

What Mimecast sells beyond filtering

Mimecast's product index lists Advanced Email Security next to Engage Security Awareness, Incydr Data Protection, the Aware Governance and Compliance Suite, DMARC Analyzer and Email Archive. A team that bought several of those is not made whole by a filter, however well it performs.

Part of the field covers that ground and part does not. Proofpoint's product index lists Archive, Capture, Discover, Supervision and Track on the compliance side, plus ZenGuide for risk based learning. Barracuda puts cloud archiving and security awareness training in Premium Plus. Microsoft's Defender Plan 2 includes phishing simulations, and Google reserves Vault retention and eDiscovery for higher tiers. Abnormal lists AI Phishing Coach and AI Governance. Cloudflare documents filtering, and neither archiving nor training.

Where Palisade fits

Palisade is DMARC automation. It is not a gateway, it does not sit in the MX path, and it does not filter, sandbox or quarantine inbound mail, so it replaces none of the products above. Its documentation covers DMARC, SPF, DKIM, BIMI and MTA-STS, hosted records, aggregate report processing, sender classification and PSA ticketing. The agent investigates every sender, drafts every fix and proposes each policy step, and you approve before anything ships.

That is the narrow case: you keep whichever filter you land on, and the authentication work stops living in a spreadsheet. For a public read on a domain first, the Email Security Score tool reports the DMARC, SPF, DKIM, MX and MTA-STS state visible in DNS.

How to choose

Start from what triggered the review. If it was cost, every vendor here except Microsoft routes you to a salesperson, so the comparison you can run is between quotes. If it was a mail flow constraint, the API vendors and the API paths inside Mimecast and Proofpoint remove the cutover. If it was overlap, check what Microsoft 365 or Google Workspace already runs by default. If it was DMARC, buy for the authentication layer and leave the filter alone.

Then put the same questions to every vendor on the shortlist:

  • Which named package and modules are in this quote, and what is excluded?
  • Is DMARC in the core package, a separate product, or an add-on fee?
  • Who publishes and changes the SPF, DKIM and DMARC records, us or you?
  • Which deployment path carries production mail, and what is validated before cutover?
  • Which archive, training and compliance modules replace the ones we use today?
  • What drives renewal cost: seats, term, consumption, or repackaging?

Evidence

Sources and further reading

Questions readers ask

Frequently asked questions

Make email authentication easier to manage

Start in Palisade.

Get started

Share this article

Samuel Chenard

Written by

Samuel Chenard

CEO & Co-Founder, Palisade

Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.

More from Samuel

Related articles