Email security for MSPs

Protect Every Mailbox on the Domains You Manage

Multi-tenant email security for MSPs, with explainable filtering, per-domain policy and predictable pricing for up to 250 mailboxes per protected domain.

Up to 250 mailboxes included per protected domain. Month to month. Partner rates $35–$39 per domain — the full rate card.

Already running Microsoft Defender? Keep it. See where the two disagree on your own mail.

The dashboard. Select to enlarge.

The shape of the product

Prevent, explain, respond

Three jobs, in the order they actually happen. Most gateways do the first one and leave you to work out the other two.

  1. Prevent

    Multi-stage filtering before delivery. Every enabled and applicable scanning stage runs for each message, each contributing to a weighted score rather than voting pass or fail.

    How a message is scored

  2. Explain

    Every message shows exactly why the decision was made — each stage's score against the threshold that decided it, and any stage that did not run, with the reason.

    See a real breakdown

  3. Respond

    Find the campaign and the exact recipients of anything that already landed. The gateway recorded the recipient and Message-ID on the way through, so an investigation is a targeted lookup rather than a mailbox-wide search.

    Mailbox Threat Response

Campaign detection, exact recipient and Message-ID tracking, message detail and administrator audit history are included with every protected domain. Mailbox lookup, remediation and restoration require a connected Microsoft 365 or Google Workspace environment, and the actions available depend on what that platform supports. These connected-platform actions are built and tested but not yet verified against a live customer tenant, and are not represented as generally available.

See exactly what’s available today → We publish the maturity of major capabilities so you know what is available today, what requires configuration, and what is still being developed.

What you get out of it

What changes once it is in front of your mail

  • Catch phishing before users see it

    Filtering happens in front of the mailbox, so a credential lure is scored and held on arrival rather than chased afterwards.

  • Know exactly why every message was blocked

    Each stage records what it found and what it contributed, so you can answer a customer's "why was this quarantined?" without guessing.

  • Protect growing environments without paying per mailbox

    A domain costs the same with five mailboxes or two hundred, so onboarding a customer's staff does not move your security line.

  • Test policies before enforcing them

    Monitor Mode scores and records real mail without changing delivery, so you see what a policy would have done before it does it.

  • Detect attacks across independent layers

    Reputation, authentication, attachment, content and optional AI analysis each score separately, so no single heuristic decides a message alone.

  • Investigate what already landed

    Mailbox Threat Response follows a campaign from detection to the exact recipients and messages involved, with every administrator action recorded. How the investigation works.

  • Run every customer from one console

    Tenants, domains, policy and quarantine stay separate objects, so one customer's settings never leak into another's.

Optional AI

Bring your own AI. Keep control of the spend.

MailThreatZero can use supported AI providers as one security signal alongside authentication, reputation, malware inspection, URL analysis, content analysis and policy evaluation. You connect your own provider using your own credentials.

  1. Your provider account

    OpenAI or Anthropic.

  2. Your credentials

    Held encrypted, and removable at any time.

  3. Scored with everything else

    One weighted decision per message, and AI cannot quarantine alone.

  4. Usage and cost, visible

    Spend per tenant and per day, with a credit limit you set.

You retain visibility into provider usage and costs, and pay the provider directly according to your own account or contract. MailThreatZero does not add a markup to provider usage, and AI analysis can be switched off per domain.

Explainable security

Every verdict shows its working

A quarantine is not a black box. Each stage reports what it found and what it contributed, so you can tell a customer exactly why their message was held — or see at a glance that a rule of yours is misfiring.

Illustrative example Example values, not a real message.
SPF
Pass
DKIM
Pass
DMARC
Pass
Sender reputation
Acceptable
Spam indicators
Detected
URL analysis
Suspicious destination
AI analysis
High risk
Final action Quarantine

Authentication passing does not clear a message on its own: here the sender is genuinely who they claim to be, and the message was still held on the destination of its links and the AI verdict. A stage that did not run says so, with the reason, rather than showing a green pass.

Inside the product

Every message, and the reason behind every decision

Screenshots and walkthrough come from the running product on demonstration data.

  • Message tracking

    Search by sender, recipient, subject or IP, then open a row for the per-stage breakdown behind its verdict.

  • Quarantine management

    Review what was held, read it safely in a sandboxed view, then release or delete it.

  • Light or dark

    The console ships both themes and remembers the choice per person. Every screen works in either — these captures are the running product, not a mock-up.

  • Live mail flow

    Watch messages move through the scanning stages as they arrive, with per-stage detection counts.

See MailThreatZero in action

A walkthrough of the console: tenant and domain management, message investigation, incident response, quarantine, per-domain policy, outbound review, retention and Monitor Mode.

Captions are shown in the recording. The full text is below. Every capability, grouped by outcome.
Read walkthrough transcript (47 captions)
  1. MailThreatZero - a managed secure email gateway for MSPs and multi-domain organizations. This is the live console.
  2. One console for every domain you protect: volume, verdicts, and the health of the services behind the gateway.
  3. MailThreatZero evaluates mail through five core scanning stages: network and reputation, sender authentication, malware and attachment analysis, spam/phishing/content analysis, and optional AI analysis. Each stage may use one or more specialized engines or intelligence sources.
  4. Content, header, phishing, attachment and QR analysis are enabled per domain. Every enabled and applicable scanning stage runs for each message.
  5. Domains: one gateway, many tenants. Each domain carries its own relay, thresholds and filtering policy.
  6. Per-domain filtering: which engines run, and which optional analysis is switched on for this domain only.
  7. QR codes are read out of images, PDFs and Office attachments, and scored on where they lead.
  8. Attachment reputation runs on the customer's own VirusTotal account: hash reputation and multi-engine analysis, no markup.
  9. Impersonation protection covers what a brand list cannot: a near-miss of your own domain, of a supplier you actually deal with, or of a named person.
  10. Payment and account-change language never scores on its own - the people who write it all day are the finance team. It counts only when something independent corroborates it.
  11. Warning banners: one per message, never a stack. A warning that appears on everything is one nobody reads by the second week.
  12. Monitor Mode: messages are scored and recorded while delivery remains unchanged. Evaluate policy on real mail before enabling enforcement.
  13. Scoring is a number you own: quarantine at one score, reject at another, per domain.
  14. DMARC aggregate report ingestion is part of the product, switched on per domain.
  15. Retention, a write-once period the database itself will not let you shorten, and outbound inspection - all set per domain.
  16. Delegated access: a customer's own admin signs in and sees their domains, and nothing else.
  17. Quarantine: read the held message safely, then release or delete. Every release is recorded against the person who made it.
  18. Flagged for Review: a real mistake goes back into the classifier as ham or spam, and the decision is recorded.
  19. Campaigns: one run across many mailboxes is a single row here, not one row per message.
  20. Open the run and it lists the senders, the source IPs and every domain of yours it touched.
  21. Outbound Review: a message carrying regulated data is held for review, not bounced - bouncing destroys the evidence.
  22. Detected values are masked in the findings. The unmasked message stays on the gateway for an administrator to review.
  23. Archive: searchable per domain, with retention, legal hold, and search across message bodies and the text inside attachments.
  24. Message Tracking: every message that passed through, searchable by sender, recipient, subject or IP.
  25. Any message opens to the decision behind it: every stage, its own verdict, and what that stage actually found.
  26. Authentication is judged before content: SPF, DKIM, DMARC, and whether anything aligned with the From domain.
  27. Each stage shows its score and what it found - and a stage that did not run says so, instead of showing a green pass.
  28. And the arithmetic: each stage's weight, its contribution, and the total that crossed this domain's quarantine threshold.
  29. Filtering decides what happens on arrival. Incident Response is for afterwards - when something already delivered turns out to be an attack.
  30. Sweep on anything that has turned out to be malicious - a URL, a hostname, a file hash, a sender, or the campaign fingerprint - and find every message that carried it.
  31. Delivered is not the same as still in the mailbox. What the gateway did is ours to answer; whether a copy is still there is the mail platform's, and it is never guessed.
  32. Live Mail Flow: messages moving through the scanning stages as they arrive.
  33. Link Protection: a rewritten link is checked again at the moment it is clicked - so a link that was clean on arrival is still caught.
  34. Country rules, set per domain or once on the account and inherited by every domain under it.
  35. Countries are picked on a world map, not from a list of codes.
  36. DMARC: aggregate reports ingested and analyzed per domain - who is sending as you, how much of it aligns, and what your policy does.
  37. Alerts name the problem and the fix, per domain.
  38. Fuzzy Rules: your own conditions and your own score adjustments, platform-wide or for one domain.
  39. AI Bypass Rules: traffic you already trust skips the AI pass, so the spend goes on mail that needs judging.
  40. AI analysis is optional and bring-your-own-key: your provider, your credentials, a credit limit per tenant, and no markup.
  41. What the AI pass actually cost, by tenant and by day.
  42. Storage: retention is a plan you buy and allocate to domains, not a support ticket.
  43. Billing: a per-tenant statement an MSP can put straight onto its own invoice.
  44. Reports: volume, threats and per-domain breakdowns, exportable for whoever asks.
  45. Product documentation is maintained alongside the platform, so operating guidance stays aligned with the current release.
  46. About: the exact version running, and what it is built on.
  47. Managed secure email gateway for MSPs and multi-domain organizations. mailthreatzero.com

How protection works

Five core scanning stages combined into one weighted decision per message

Every enabled and applicable scanning stage runs for each message, contributing to a weighted score rather than an isolated pass-or-fail call. The score, the thresholds and the decision are recorded against the message.

  1. Network and reputation

    Hosts with a known bad history are cut off before a header is parsed, using multiple real-time DNS reputation sources with per-domain country and network policy.

  2. Sender authentication

    SPF, DKIM and DMARC decide whether a sender may claim the domain it is using, and the result carries into the later stages.

  3. Malware and attachment analysis

    Signature scanning, document and macro inspection, and per-domain attachment type policy. Optional attachment reputation and multi-engine analysis through VirusTotal, using the customer's own account.

  4. Spam, phishing and content analysis

    Rule-based and statistical scoring, fingerprint checks, phishing and header filters, plus QR codes decoded from images, PDFs and Office attachments. Optional URL rewriting and click-time destination analysis.

  5. AI analysis

    Targeted phishing and business email compromise carry no signature, so ambiguous messages get a second look. Optional AI analysis uses the provider and credentials selected for the deployment and can be enabled or disabled per domain.

Automated health checks continuously validate the filtering pipeline and enabled scanning services.

See the full mail path and how the decision is made · Compare MailThreatZero with other email security options

Partner pricing

Priced per protected domain, with up to 250 mailboxes per domain

The rate falls as the portfolio grows.

  • Standard

    $39per protected domain / month

    1–39 domains

    Up to 250 mailboxes per protected domain

    Partners starting out, and small MSP portfolios

  • Volume

    $37per protected domain / month

    40–99 domains

    Up to 250 mailboxes per protected domain

    Growing MSP portfolios

  • Portfolio

    $35per protected domain / month

    100–249 domains

    Up to 250 mailboxes per protected domain

    Large MSP and multi-tenant portfolios

  • Custom pricing

    Custom pricingcontact us for a quote

    250+ domains

    Contact us for an organization or service-provider quote.

    Contact Us

These are partner rates. A single organization protecting its own domains pays $39 per protected domain — see the pricing page for both.

Billed month to month, with no setup fee and no minimum term.

See Pricing

See everything included with a protected domain

Evaluate One Domain Before You Commit

Run a customer domain in Monitor Mode to review classifications, policy behavior, and message-level decisions before enabling enforcement.

Evaluate One Domain

Multi-tenant operations and deployment How it runs across a portfolio

For MSPs

Run a portfolio, not a stack of unrelated accounts

Tenants, domains, policy and quarantine are separate objects, so settings for one customer never leak into another.

  • Tenant isolation and roles

    Each tenant sees only its own domains, mail and quarantine, under platform, tenant, domain-administrator and read-only roles with TOTP two-factor available.

  • Policy stays separate

    Thresholds, filters, allow and block lists, country rules and AI settings belong to one domain at a time, so one customer's tolerance does not dictate another's.

  • One quarantine queue

    Work the whole portfolio from a single view, or hand a domain administrator only their own.

  • Onboarding is three steps

    Add the domain, set its destination, point MX. Nothing gets installed at the customer site.

How MailThreatZero fits an MSP practice

Deployment

Fits the mail platform each customer already runs

MailThreatZero is a managed secure email gateway that scans inbound email before securely relaying it to your existing mail platform. It works with Microsoft 365, Google Workspace, Exchange, hosted email providers, and customer-owned mail servers.

  • Inbound filtering

    The domain's MX points at mt0.mailthreatzero.com. Mail is scanned, then relayed over TLS to the destination configured for that domain.

  • Mixed platforms, one console

    Each domain routes to its own destination, so different customer platforms sit side by side. Mailboxes, users and licensing stay where they are.

  • Checked before cut-over

    A setup wizard verifies the domain, destination and delivery path before MX moves, returning a specific remedy for anything that would break.

  • Outbound and hosting

    Outbound inspection and DLP are available for mail routed through the MailThreatZero gateway. We host and maintain the gateway, so there is no appliance or agent to deploy.

Certain capabilities depend on mail-flow configuration or optional integrations.

Questions

The things buyers actually ask

What is MailThreatZero?

A managed secure email gateway. Inbound mail for a protected domain is evaluated through five core scanning stages, each of which may use one or more specialized engines or intelligence sources, then relayed to the destination you configure.

What is Mailbox Threat Response?

One workflow for the questions that come after a message is classified: which campaign it belongs to, exactly who received it, what each scanning stage found, and what any administrator did about it. Because the gateway records the recipient and Message-ID of every message as it passes through, an investigation is a targeted lookup rather than a search of every mailbox.

Campaign detection, recipient and message tracking, message detail and audit history are included with a protected domain. Locating delivered copies, previewing an action, remediating and restoring require a connected Microsoft 365 or Google Workspace platform, and supported actions depend on it. These connected-platform actions are built and tested but not yet verified against a live customer tenant, and are not represented as generally available.

Who is it for?

MSPs and MSSPs protecting many customer domains from one console, plus internal IT teams running several domains or many mailboxes without a bill that grows with headcount.

Does it replace Microsoft 365 or Google Workspace?

No. It sits in front of them. Mailboxes, calendars, users and licensing stay exactly where they are, and inbound mail is filtered before it reaches them. What that looks like on each platform: Microsoft 365 email security and Google Workspace email security.

How is it deployed?

Add the domain, set the destination for its filtered mail, then point MX at the gateway. The wizard verifies each step before the cut-over rather than after it.

How does per-domain pricing work?

You pay a monthly rate per protected domain, and every mailbox and alias on that domain is covered. Message volume does not change the price; retained storage on the archive add-on is the one metered component. See the rates and calculator.

Can we evaluate it before it changes anything?

Yes. Monitor Mode records how MailThreatZero would classify messages while allowing normal delivery. Review decisions, tune policy, and validate the fit before enabling enforcement.

Does it handle multiple customers and domains?

Yes. Every domain you manage lives in one console with each tenant's data scoped to that tenant, and policy is set per domain so one customer's tuning never becomes another's. More on multi-tenant management for MSPs.

What support is included?

Email support is included with every protected domain. Mail-flow interruptions, widespread false positives, and suspected security incidents receive priority handling. Support terms and response targets are provided with each service plan.

What's new

A selection of recent changes a customer would notice. Only what is available today — anything still needing setup is described on the release notes page rather than listed here. Current platform version: v2.61.10.

  • Two-factor recovery codes
  • Fewer false positives on commercial mail
  • AI model chosen by measurement
  • Malware scoring no longer double-counts

Selected release notes →

Who the pricing model suits

Anyone can buy it. These are the shapes of organization where paying per protected domain rather than per mailbox makes an obvious difference.

  • MSPs and MSSPs

    Every customer domain in one multi-tenant console, with per-domain policy and a rate that does not move when a customer hires. How it works for partners →

  • Multi-domain organizations

    Several business units, brands or acquired companies protected under one account, without a separate per-user licence for each.

  • Organizations with many shared mailboxes

    Aliases, shared inboxes, service accounts and role addresses are mailboxes on a protected domain. They are covered, and they do not each carry a licence.

Built to Be Examined

Email security should not require blind trust. MailThreatZero documents how major controls work, publishes feature maturity, exposes filtering decisions, and clearly distinguishes production capabilities from features still being validated or developed.

Each capability is labelled with how finished it is, in plain words.

See how it would handle your mail.

Request a Demo, or evaluate one real domain in Monitor Mode and judge the decisions yourself before anything is enforced.