# Secure email gateway Gartner Magic Quadrant 2020

> Secure email gateway Gartner Magic Quadrant 2020 results cannot be confirmed from available primary sources. Use current control evidence instead.

No verified conclusion about the 2020 Gartner Magic Quadrant for Secure Email Gateways can be made without the official report or licensed Gartner material. A search result, vendor homepage, or remembered placement is not enough to establish the report's title, vendors, positions, criteria, or recommendations. For current security work, treat a historic market report as context and validate the controls protecting your own mail flow.

## Quick takeaways

- The official 2020 report or licensed Gartner material is required to verify a vendor placement or Gartner conclusion.
- A general vendor homepage does not establish inclusion, ranking, or evaluation criteria in a historical analyst report.
- Historic market research does not prove that a current email-security control is configured or operating for your domain.
- Current decisions need evidence from the deployed mail path, control settings, and delivered-message results.
- The [email threat-management hub](/learning/threats) is a better starting point when the task is to assess current exposure.

## Why a historical report needs primary evidence

An analyst report is a separate work with its own title, publication date, scope, evaluation criteria, and vendor positions. Those details must come from the report itself, an official Gartner page that identifies the report, or licensed material that reproduces the relevant content accurately.

The available public homepages for [Fortinet](https://www.fortinet.com/) and [Microsoft](https://www.microsoft.com/) describe their companies and products generally. Neither page identifies a 2020 Secure Email Gateway Magic Quadrant, confirms a vendor's placement, or provides the report's evaluation criteria. They therefore cannot support a claim that a named vendor was a Leader, Challenger, Visionary, or Niche Player.

This distinction matters because a market-position statement is more specific than a general statement that a company offers cybersecurity products. It also prevents a historical result from being mistaken for a current technical assessment.

If you need an explanation of the control category itself, see [how secure email gateways protect an organization](/learning/how-secure-email-gateways-protect-organization). That article addresses the purpose of a secure email gateway, which is a different question from what a historical analyst report concluded.

## When a historical result can inform a decision

A 2020 market report can be useful as background only after its details are verified from the report or an official Gartner record. It may help identify questions to investigate, such as which product capabilities were considered relevant at the time.

It should not decide whether a current deployment is adequate. Products change, provider integrations change, and an organization's own mail routes, domains, third-party senders, and policy settings may differ from the conditions described in any market assessment.

Use this decision rule:

- If the task is to quote, cite, or compare a 2020 Gartner result, obtain the official report or licensed Gartner material first.
- If the task is to choose or review an email-security control today, collect current evidence from the actual environment.
- If the task is to understand email-security controls before testing them, start with [Palisade's email security guidance](/learning/email-security).
- If the task is to compare a newer historical query with supported evidence, use the related [2021 secure email gateway Magic Quadrant article](/learning/secure-email-gateway-gartner-magic-quadrant-2021) only for that distinct year and its cited material.

A vendor's current product page can describe its current offering, but it does not retroactively prove what an analyst report said in 2020. Likewise, an old report cannot prove that a current mail path filters malicious messages, enforces authentication, or handles a particular user report as intended.

![Decision flow for using a historical secure email gateway report as context and validating current email-security controls with current evidence](/images/editorial/secure-email-gateway-gartner-magic-quadrant-2020/secure-email-gateway-gartner-magic-quadrant-2020-research-decision.webp "1200x676")

*Source: Palisade.*

## A worked evidence checklist

Use a separate evidence set for the historical claim and the current control decision.

```text
Historical report claim
- Official report title:
- Publication date:
- Official Gartner page or licensed report reference:
- Exact vendor name:
- Exact placement or wording:
- Applicable evaluation criteria:

Current email-security control check
- Sending and receiving domains in scope:
- Current mail-routing evidence:
- Current gateway or provider status:
- Delivered-message headers from the production path:
- DMARC aggregate-report findings:
- Owner, rollback method, and unresolved exceptions:
```

The first group establishes what the historical publication actually said. The second group establishes whether the organization has an effective control now. Do not merge the two.

A current control review should test the relevant layer of evidence:

- DNS evidence confirms the records currently published through authoritative DNS and a public resolver.
- Vendor evidence confirms the present status shown by the deployed provider or gateway.
- Message evidence comes from a real delivered message on the exact production path, including its raw headers or `Authentication-Results` field where applicable.
- DMARC evidence comes from aggregate reports after they have accumulated.

A control indicator can be useful, but it is not a delivered-message check. A public DNS result also cannot prove that every production sender uses the intended path, that a receiver accepted a message, or that future messages will receive the same treatment.

## Choose the next check from the evidence you have

If you only have a historic search query, obtain the official report before repeating any placement or recommendation. If you have a current domain and need to begin a practical review, use current email-security guidance to identify the evidence your team needs.

If you have a public domain but no internal configuration access, an external check may help identify visible DNS posture. It cannot inspect a private gateway configuration, a receiver's private decision, continuous state, or future delivery behavior.

For a current explanation of the protection categories and review questions, read [email security guidance](/learning/email-security). If your team needs a broader assessment starting point, the [Email Security Score tool](/tools/email-security-score) is available for a public check.

## Review current email-security evidence

A historical market reference cannot show whether your present domains, mail routes, and controls behave as intended. Start with current email-security guidance, then collect production-path and message evidence before making a control decision.

[Review current email security](/learning/email-security)

This guidance does not verify a 2020 Gartner placement, inspect a private gateway configuration, or guarantee that future messages will be accepted or placed in the inbox.

## Sources and further reading

- [Fortinet homepage](https://www.fortinet.com/)
- [Microsoft homepage](https://www.microsoft.com/)
- [Palisade email security guidance](/learning/email-security)
- [How secure email gateways protect an organization](/learning/how-secure-email-gateways-protect-organization)

## Frequently asked questions

### Can I cite a vendor as a 2020 Magic Quadrant Leader from its homepage?

No, because a vendor homepage describes current products and says nothing about a report's title, scope, date, criteria, or vendor positions. Cite the official report, an official Gartner page, or licensed material that names the exact result.

### Does a 2020 analyst report prove a secure email gateway works today?

No, because a 2020 report describes a market as it stood then, not your current mail routes, policy settings, or deployment status. Evidence that a gateway works today comes from the deployed environment: the live mail path, the gateway's current status, and real delivered messages.

### What evidence should I collect for a current gateway review?

Collect the domains and mail paths in scope, current provider or gateway status, a real delivered message from the production path, and DMARC aggregate-report findings after reports accumulate. Compare those results with the organization's approved configuration.

### Can a public email-security check validate a private gateway configuration?

No, because a public check sees only externally observable information such as published DNS records. It cannot read private gateway settings, prove the production sending path, monitor the control over time, or reveal a receiver's delivery decision.

### Should I use the 2020 report to select an email-security product now?

Use the 2020 report as background only, and only after you have verified it against the original document. A decision made today needs current product documentation, your own requirements, and validation of the controls that will protect your live mail flow. Products and vendors have changed since the report was written.
