# Mimecast pricing: what is published and what drives cost

> Mimecast pricing is quote-only. See what Mimecast publishes, the modules and deployment choices that affect cost, and questions to ask sales.

Mimecast pricing is not published as a list price. Mimecast names its plans and products, but its current plans page uses "Contact for pricing," "Custom pricing available," and "Custom options available" instead of dollar amounts. Choose Mimecast if its email security, insider-risk, or security-behaviour products match the scope you need. Choose a focused DMARC platform if the purchase is specifically about operating DMARC across domains.

## Quick takeaways

- Mimecast publishes plan names and feature packaging, but no public dollar price, currency, per-user rate, or price range.
- A reseller, marketplace, or review-site estimate is not Mimecast's published list price.
- The quote can vary with the product family, feature tier, deployment model, and paid services selected.
- DMARC Analyzer is a separate Mimecast product with its own trial call to action and no published price.
- Mimecast's older service matrix identifies DMARC visibility and reporting as a paid module outside one plan, but its tier names predate the August 2025 plan transition.
- A public email-security scan can establish published DNS controls, but it cannot establish the price, production mail flow, or receiver decisions behind a Mimecast quote.

## Who this comparison is for

This comparison is for an IT buyer, security owner, or MSP who needs to budget for Mimecast and has found plan names but no public price card. It also helps teams decide whether they are evaluating a secure email gateway, an API-connected email-security deployment, DMARC reporting, or a separate operational need.

Mimecast is broader than DMARC. Its MX-based email-security product scans incoming, outbound, and internal mail, including attachments and URLs. Its integrated cloud email-security product supports both MX-based and API-based deployment. A DMARC purchase has a different job: identify the services sending for a domain, assess authentication and alignment, then move safely toward enforcement.

For broader managed DMARC product evaluation, use Palisade's [DMARC comparison hub](/compare). If the question is specifically whether a DMARC-focused workflow is a better fit than Mimecast's DMARC product, see the [Mimecast DMARC alternative comparison](/compare/mimecast-dmarc-alternative).

## How the options were evaluated

The criteria below were checked against Mimecast and Palisade first-party pages on August 12, 2026:

- Published price: whether the vendor provides a dollar amount, currency, rate, or range that a buyer can use without requesting a quote.
- Scope: whether the documented product is email security, insider-risk management, security behaviour management, or DMARC operations.
- Quantity and service levers: documented limits, included capabilities, migration costs, implementation services, or modules that can affect the final commercial scope.
- Deployment: whether the product uses MX routing, an API connection, or another documented deployment choice.
- Boundary: what the documented offering does not establish or perform.

A documented feature counts as published evidence. An absent price is recorded as absent, not estimated. A capability that Mimecast does not describe remains an open question for the sales process.

![Decision flow for assessing a Mimecast quote by product scope, deployment, modules, and paid services](/images/editorial/mimecast-pricing/mimecast-pricing-quote-decision.webp "1200x829")

*Source: Palisade.*

## Mimecast plans and quote-based pricing

Mimecast's [plans page](https://www.mimecast.com/products/mimecast-plans/) names threat-protection tiers as Critical, Advanced, and Premium. It names insider-risk-management tiers as Professional, Enterprise, and Gov, and security-behaviour-management tiers as Core and Pro. The same page does not publish a dollar price for any of them. Its price fields direct buyers to contact Mimecast or describe custom pricing or options.

- Best fit: Teams buying a broader email-security, insider-risk, or security-behaviour package and prepared to scope it with Mimecast sales.
- Relevant evidence: [Mimecast plans](https://www.mimecast.com/products/mimecast-plans/) describes Critical as the broad email-security tier, with features such as AI-powered BEC protection, URL analysis, attachment sandboxing, malware scanning, spam filtering, continuity, and collaboration-tool protection. Advanced adds data protection, while Premium extends across collaboration tools, checked August 12, 2026.
- Tradeoff: A buyer cannot calculate a vendor-supported annual or per-user cost from the public plans page. Any public figure from a reseller or review site is not a Mimecast-published list price.

Documented quantities and access levels can shape the quote. Mimecast states that insider-risk Professional includes 30 days of historical activity, while Enterprise includes 90 days. Professional includes one SaaS or cloud-app exfiltration detector, while full API access is listed for Enterprise. Those differences are commercial scoping questions, even though the public page does not attach a price to them.

Plan timing also matters. Mimecast states that, from August 15, 2025, new customers must purchase the new email-security plans, while existing purchases remain online, uninterrupted, and unchanged. Mimecast also states that migration to the new plans can involve an additional cost and that standard price-increase terms apply. Ask sales which plan structure applies to the account, whether migration is included, and which terms govern renewal.

The public route to a number is Mimecast's [quote-request page](https://www.mimecast.com/get-a-quote/), which offers a customised plan and quote without publishing a price or range.

## Mimecast deployment and DMARC costs

Mimecast's [integrated cloud email security page](https://www.mimecast.com/products/email-security/integrated-cloud-email-security/) documents two deployment models. MX-based deployment routes incoming mail through Mimecast's gateway. API-based deployment connects without MX-record changes and is described as avoiding mail-flow disruption. The correct model depends on the email environment and desired controls, so it belongs in the quote request.

- Best fit: Buyers who need Mimecast's documented gateway or integrated cloud email-security capabilities as part of the commercial scope.
- Relevant evidence: [Mimecast Email Security MX Based Protection](https://www.mimecast.com/products/email-security/secure-email-gateway/) is documented as a cloud-native secure email gateway that scans inbound, outbound, and internal mail, including attachments and URLs, checked August 12, 2026.
- Tradeoff: A DMARC requirement should be scoped separately. A gateway purchase does not state a public price for DMARC reporting or show that every DMARC-related service is included.

Mimecast [DMARC Analyzer](https://www.mimecast.com/products/dmarc-analyzer/) is a named product for visibility into senders using a domain, aggregate, forensic, and TLS reports, plus self-service tools, summaries, filters, and a recommendation engine. Its page offers a free 14-day DMARC trial, but no price.

Mimecast's [service matrix version 4.1](https://assets.mimecast.com/api/public/content/0e60226dd6e641b5937ec5440ec56527?v=a6cf7965&download=true), dated July 2020, identifies DMARC visibility and reporting as standard in one plan and available for an additional fee in four others. Its plan names predate the 2025 transition, so the useful current conclusion is limited: Mimecast has published DMARC as separately chargeable packaging, not as a universally included gateway feature.

The same matrix lists real-time domain monitoring, unlimited monthly DMARC-compliant email volume, subdomain detection, RUA and encrypted RUF overviews, setup wizards, SPF delegation, record tools, and a DNS timeline within DMARC Analyzer. It marks managed deployment help and onboarding implementation as additional-fee services.

> Do not assume that a generated DMARC, SPF, or DKIM record is deployed. Mimecast documents analysis, generation, and recommendations for DMARC Analyzer. The domain owner must still control and validate the DNS change.

## Palisade for DMARC automation

Palisade is a narrower fit for teams buying DMARC operations rather than inbound email filtering. It is AI-first, agent-first DMARC software for IT teams and MSPs that analyzes DMARC aggregate-report data, identifies sending sources and authentication or alignment issues, creates prioritized remediation tickets, and proposes the next policy step for human review.

- Best fit: Teams that want an AI agent to do the DMARC work across one domain or many domains.
- Relevant evidence: [Palisade pricing](https://www.palisade.email/pricing) publishes a free plan at $0 for one domain and up to 1,000 emails a month, IT-team plans from $19 a month based on monthly email volume, MSP pricing per client domain with a free NFR domain, and enterprise custom terms, checked August 12, 2026.
- Tradeoff: Palisade is not a secure email gateway and does not filter inbound mail. It also does not autonomously change a DMARC policy. A human reviews the evidence and applies the DNS change.

![Scope comparison between Mimecast email security and Palisade DMARC automation](/images/editorial/mimecast-pricing/mimecast-pricing-scope-comparison.webp "1200x466")

*Source: Palisade.*

Palisade's published pricing provides a starting point that Mimecast's public plans page does not. That does not make it a substitute for Mimecast filtering plans. The products solve overlapping DMARC visibility needs, but different email-security jobs.

## How to choose

Start by writing down the operational problem, then request a quote only after the required product scope is clear.

- Choose Mimecast when the purchase includes documented secure email gateway controls, API-connected cloud email security, insider-risk management, security-behaviour management, or a combined security package.
- Choose Palisade when the requirement is recurring DMARC analysis, source identification, remediation prioritisation, and human-reviewed progression toward DMARC enforcement.
- Ask Mimecast whether DMARC Analyzer is included, separately priced, or subject to an additional service fee for the exact package.
- Ask which deployment model is proposed, what migration costs apply, and whether onboarding or managed deployment assistance is separately charged.
- Record every quantity limit, retained-history period, API entitlement, and collaboration-tool scope in the quote.

```yaml
option: Mimecast
checked_on: 2026-08-12
best_fit: "Broad email security and separately scoped DMARC operations"
verified_evidence:
  - "Public plans have no published dollar price or range"
  - "MX-based and API-based deployment are documented"
  - "DMARC Analyzer is a named product with no published price"
open_question: "Quoted price, minimum commitment, included modules, and implementation fees"

option: Palisade
checked_on: 2026-08-12
best_fit: "DMARC automation for IT teams and MSPs"
verified_evidence:
  - "Published free, IT team, MSP, and enterprise pricing paths"
  - "DMARC aggregate-report analysis and prioritised remediation workflow"
  - "Human review before policy changes"
open_question: "Exact monthly-volume or multi-domain scope for the account"
```

## Check the domain controls behind the quote

Before treating a DMARC module as the answer, run the domain through Palisade's [Email Security Score](/tools/email-security-score). It checks publicly resolvable email-security controls, which helps identify whether DMARC, SPF, DKIM, BIMI, MX, MTA-STS, or TLS-RPT has an obvious public DNS gap before you scope a remediation workflow.

A public scan does not prove which production senders fail alignment, confirm Mimecast packaging, monitor later DNS changes, or guarantee inbox placement. Those questions require message evidence, vendor confirmation, and DMARC reporting over time.

## Sources and further reading

- [Mimecast plans and product tiers](https://www.mimecast.com/products/mimecast-plans/)
- [Mimecast quote request](https://www.mimecast.com/get-a-quote/)
- [Mimecast integrated cloud email security deployment options](https://www.mimecast.com/products/email-security/integrated-cloud-email-security/)
- [Mimecast DMARC Analyzer](https://www.mimecast.com/products/dmarc-analyzer/)
- [Mimecast service matrix version 4.1](https://assets.mimecast.com/api/public/content/0e60226dd6e641b5937ec5440ec56527?v=a6cf7965&download=true)
- [Palisade pricing](https://www.palisade.email/pricing)

## Frequently asked questions

### Does Mimecast publish its pricing?

No. Mimecast's current plans page publishes tier names and feature descriptions, but it does not publish dollar amounts, currencies, per-user rates, or price ranges. The public route to a commercial number is a customised quote request.

### What affects a Mimecast quote?

Mimecast's published materials indicate that product family, tier, deployment model, included capabilities, retention period, API access, DMARC packaging, and paid implementation or managed services can affect scope. The vendor does not publish a formula that converts those variables into a price.

### Is Mimecast DMARC Analyzer included with email security?

Not universally. Mimecast documents DMARC Analyzer as a separate product. Its July 2020 service matrix shows DMARC visibility and reporting as standard in one historical plan and available for an additional fee in others. Confirm current packaging in the quote because the plan names changed for new customers after August 2025.

### Does Mimecast change DNS records for DMARC?

No published Mimecast page checked states that Mimecast changes customer DNS records or hosts SPF, DKIM, or DMARC records. Mimecast documents analysis, record-generation tools, and recommendations. The customer must apply and validate DNS changes.

### Is Palisade an alternative to Mimecast email filtering?

No. Palisade is a DMARC automation platform, while Mimecast's email-security products include gateway and cloud email-security capabilities. Palisade can fit a DMARC operating need, but it does not filter inbound mail or replace a secure email gateway.
