Email security for MSPs
Protect Every Mailbox on the Domains You Manage
Multi-tenant email security for MSPs, with explainable filtering, per-domain policy and predictable pricing for up to 250 mailboxes per protected domain.
Up to 250 mailboxes included per protected domain. Month to month. Partner rates $35–$39 per domain — the full rate card.
Already running Microsoft Defender? Keep it. See where the two disagree on your own mail.
What makes MailThreatZero different
- Per-domain pricing One rate per protected domain
- Campaign, not just the message One verdict opens the whole campaign
- Up to 250 mailboxes per domain five mailboxes or two hundred, same price
- Explainable decisions Every engine’s score, and what it found
- Bring your own AI Your provider, your account, no markup
- Monitor Mode Score real mail before you enforce
The shape of the product
Prevent, explain, respond
Three jobs, in the order they actually happen. Most gateways do the first one and leave you to work out the other two.
-
Prevent
Multi-stage filtering before delivery. Every enabled and applicable scanning stage runs for each message, each contributing to a weighted score rather than voting pass or fail.
-
Explain
Every message shows exactly why the decision was made — each stage's score against the threshold that decided it, and any stage that did not run, with the reason.
-
Respond
Find the campaign and the exact recipients of anything that already landed. The gateway recorded the recipient and Message-ID on the way through, so an investigation is a targeted lookup rather than a mailbox-wide search.
Campaign detection, exact recipient and Message-ID tracking, message detail and administrator audit history are included with every protected domain. Mailbox lookup, remediation and restoration require a connected Microsoft 365 or Google Workspace environment, and the actions available depend on what that platform supports. These connected-platform actions are built and tested but not yet verified against a live customer tenant, and are not represented as generally available.
See exactly what’s available today → We publish the maturity of major capabilities so you know what is available today, what requires configuration, and what is still being developed.
What you get out of it
What changes once it is in front of your mail
-
Catch phishing before users see it
Filtering happens in front of the mailbox, so a credential lure is scored and held on arrival rather than chased afterwards.
-
Know exactly why every message was blocked
Each stage records what it found and what it contributed, so you can answer a customer's "why was this quarantined?" without guessing.
-
Protect growing environments without paying per mailbox
A domain costs the same with five mailboxes or two hundred, so onboarding a customer's staff does not move your security line.
-
Test policies before enforcing them
Monitor Mode scores and records real mail without changing delivery, so you see what a policy would have done before it does it.
-
Detect attacks across independent layers
Reputation, authentication, attachment, content and optional AI analysis each score separately, so no single heuristic decides a message alone.
-
Investigate what already landed
Mailbox Threat Response follows a campaign from detection to the exact recipients and messages involved, with every administrator action recorded. How the investigation works.
-
Run every customer from one console
Tenants, domains, policy and quarantine stay separate objects, so one customer's settings never leak into another's.
Optional AI
Bring your own AI. Keep control of the spend.
MailThreatZero can use supported AI providers as one security signal alongside authentication, reputation, malware inspection, URL analysis, content analysis and policy evaluation. You connect your own provider using your own credentials.
-
Your provider account
OpenAI or Anthropic.
-
Your credentials
Held encrypted, and removable at any time.
-
Scored with everything else
One weighted decision per message, and AI cannot quarantine alone.
-
Usage and cost, visible
Spend per tenant and per day, with a credit limit you set.
You retain visibility into provider usage and costs, and pay the provider directly according to your own account or contract. MailThreatZero does not add a markup to provider usage, and AI analysis can be switched off per domain.
Explainable security
Every verdict shows its working
A quarantine is not a black box. Each stage reports what it found and what it contributed, so you can tell a customer exactly why their message was held — or see at a glance that a rule of yours is misfiring.
- SPF
- Pass
- DKIM
- Pass
- DMARC
- Pass
- Sender reputation
- Acceptable
- Spam indicators
- Detected
- URL analysis
- Suspicious destination
- AI analysis
- High risk
Authentication passing does not clear a message on its own: here the sender is genuinely who they claim to be, and the message was still held on the destination of its links and the AI verdict. A stage that did not run says so, with the reason, rather than showing a green pass.
Inside the product
Every message, and the reason behind every decision
Screenshots and walkthrough come from the running product on demonstration data.
-
Message tracking
Search by sender, recipient, subject or IP, then open a row for the per-stage breakdown behind its verdict.
-
Quarantine management
Review what was held, read it safely in a sandboxed view, then release or delete it.
-
Light or dark
The console ships both themes and remembers the choice per person. Every screen works in either — these captures are the running product, not a mock-up.
-
Live mail flow
Watch messages move through the scanning stages as they arrive, with per-stage detection counts.
See MailThreatZero in action
A walkthrough of the console: tenant and domain management, message investigation, incident response, quarantine, per-domain policy, outbound review, retention and Monitor Mode.
Read walkthrough transcript (47 captions)
- MailThreatZero - a managed secure email gateway for MSPs and multi-domain organizations. This is the live console.
- One console for every domain you protect: volume, verdicts, and the health of the services behind the gateway.
- MailThreatZero evaluates mail through five core scanning stages: network and reputation, sender authentication, malware and attachment analysis, spam/phishing/content analysis, and optional AI analysis. Each stage may use one or more specialized engines or intelligence sources.
- Content, header, phishing, attachment and QR analysis are enabled per domain. Every enabled and applicable scanning stage runs for each message.
- Domains: one gateway, many tenants. Each domain carries its own relay, thresholds and filtering policy.
- Per-domain filtering: which engines run, and which optional analysis is switched on for this domain only.
- QR codes are read out of images, PDFs and Office attachments, and scored on where they lead.
- Attachment reputation runs on the customer's own VirusTotal account: hash reputation and multi-engine analysis, no markup.
- Impersonation protection covers what a brand list cannot: a near-miss of your own domain, of a supplier you actually deal with, or of a named person.
- Payment and account-change language never scores on its own - the people who write it all day are the finance team. It counts only when something independent corroborates it.
- Warning banners: one per message, never a stack. A warning that appears on everything is one nobody reads by the second week.
- Monitor Mode: messages are scored and recorded while delivery remains unchanged. Evaluate policy on real mail before enabling enforcement.
- Scoring is a number you own: quarantine at one score, reject at another, per domain.
- DMARC aggregate report ingestion is part of the product, switched on per domain.
- Retention, a write-once period the database itself will not let you shorten, and outbound inspection - all set per domain.
- Delegated access: a customer's own admin signs in and sees their domains, and nothing else.
- Quarantine: read the held message safely, then release or delete. Every release is recorded against the person who made it.
- Flagged for Review: a real mistake goes back into the classifier as ham or spam, and the decision is recorded.
- Campaigns: one run across many mailboxes is a single row here, not one row per message.
- Open the run and it lists the senders, the source IPs and every domain of yours it touched.
- Outbound Review: a message carrying regulated data is held for review, not bounced - bouncing destroys the evidence.
- Detected values are masked in the findings. The unmasked message stays on the gateway for an administrator to review.
- Archive: searchable per domain, with retention, legal hold, and search across message bodies and the text inside attachments.
- Message Tracking: every message that passed through, searchable by sender, recipient, subject or IP.
- Any message opens to the decision behind it: every stage, its own verdict, and what that stage actually found.
- Authentication is judged before content: SPF, DKIM, DMARC, and whether anything aligned with the From domain.
- Each stage shows its score and what it found - and a stage that did not run says so, instead of showing a green pass.
- And the arithmetic: each stage's weight, its contribution, and the total that crossed this domain's quarantine threshold.
- Filtering decides what happens on arrival. Incident Response is for afterwards - when something already delivered turns out to be an attack.
- Sweep on anything that has turned out to be malicious - a URL, a hostname, a file hash, a sender, or the campaign fingerprint - and find every message that carried it.
- Delivered is not the same as still in the mailbox. What the gateway did is ours to answer; whether a copy is still there is the mail platform's, and it is never guessed.
- Live Mail Flow: messages moving through the scanning stages as they arrive.
- Link Protection: a rewritten link is checked again at the moment it is clicked - so a link that was clean on arrival is still caught.
- Country rules, set per domain or once on the account and inherited by every domain under it.
- Countries are picked on a world map, not from a list of codes.
- DMARC: aggregate reports ingested and analyzed per domain - who is sending as you, how much of it aligns, and what your policy does.
- Alerts name the problem and the fix, per domain.
- Fuzzy Rules: your own conditions and your own score adjustments, platform-wide or for one domain.
- AI Bypass Rules: traffic you already trust skips the AI pass, so the spend goes on mail that needs judging.
- AI analysis is optional and bring-your-own-key: your provider, your credentials, a credit limit per tenant, and no markup.
- What the AI pass actually cost, by tenant and by day.
- Storage: retention is a plan you buy and allocate to domains, not a support ticket.
- Billing: a per-tenant statement an MSP can put straight onto its own invoice.
- Reports: volume, threats and per-domain breakdowns, exportable for whoever asks.
- Product documentation is maintained alongside the platform, so operating guidance stays aligned with the current release.
- About: the exact version running, and what it is built on.
- Managed secure email gateway for MSPs and multi-domain organizations. mailthreatzero.com
How protection works
Five core scanning stages combined into one weighted decision per message
Every enabled and applicable scanning stage runs for each message, contributing to a weighted score rather than an isolated pass-or-fail call. The score, the thresholds and the decision are recorded against the message.
-
Network and reputation
Hosts with a known bad history are cut off before a header is parsed, using multiple real-time DNS reputation sources with per-domain country and network policy.
-
Sender authentication
SPF, DKIM and DMARC decide whether a sender may claim the domain it is using, and the result carries into the later stages.
-
Malware and attachment analysis
Signature scanning, document and macro inspection, and per-domain attachment type policy. Optional attachment reputation and multi-engine analysis through VirusTotal, using the customer's own account.
-
Spam, phishing and content analysis
Rule-based and statistical scoring, fingerprint checks, phishing and header filters, plus QR codes decoded from images, PDFs and Office attachments. Optional URL rewriting and click-time destination analysis.
-
AI analysis
Targeted phishing and business email compromise carry no signature, so ambiguous messages get a second look. Optional AI analysis uses the provider and credentials selected for the deployment and can be enabled or disabled per domain.
Automated health checks continuously validate the filtering pipeline and enabled scanning services.
See the full mail path and how the decision is made · Compare MailThreatZero with other email security options
Partner pricing
Priced per protected domain, with up to 250 mailboxes per domain
The rate falls as the portfolio grows.
-
Standard
$39per protected domain / month
1–39 domains
Up to 250 mailboxes per protected domain
Partners starting out, and small MSP portfolios
-
Volume
$37per protected domain / month
40–99 domains
Up to 250 mailboxes per protected domain
Growing MSP portfolios
-
Portfolio
$35per protected domain / month
100–249 domains
Up to 250 mailboxes per protected domain
Large MSP and multi-tenant portfolios
-
Custom pricing
Custom pricingcontact us for a quote
250+ domains
Contact us for an organization or service-provider quote.
These are partner rates. A single organization protecting its own domains pays $39 per protected domain — see the pricing page for both.
Billed month to month, with no setup fee and no minimum term.
Evaluate One Domain Before You Commit
Run a customer domain in Monitor Mode to review classifications, policy behavior, and message-level decisions before enabling enforcement.
Multi-tenant operations and deployment How it runs across a portfolio
For MSPs
Run a portfolio, not a stack of unrelated accounts
Tenants, domains, policy and quarantine are separate objects, so settings for one customer never leak into another.
Tenant isolation and roles
Each tenant sees only its own domains, mail and quarantine, under platform, tenant, domain-administrator and read-only roles with TOTP two-factor available.
Policy stays separate
Thresholds, filters, allow and block lists, country rules and AI settings belong to one domain at a time, so one customer's tolerance does not dictate another's.
One quarantine queue
Work the whole portfolio from a single view, or hand a domain administrator only their own.
Onboarding is three steps
Add the domain, set its destination, point MX. Nothing gets installed at the customer site.
How MailThreatZero fits an MSP practice
Deployment
Fits the mail platform each customer already runs
MailThreatZero is a managed secure email gateway that scans inbound email before securely relaying it to your existing mail platform. It works with Microsoft 365, Google Workspace, Exchange, hosted email providers, and customer-owned mail servers.
Inbound filtering
The domain's MX points at
mt0.mailthreatzero.com. Mail is scanned, then relayed over TLS to the destination configured for that domain.Mixed platforms, one console
Each domain routes to its own destination, so different customer platforms sit side by side. Mailboxes, users and licensing stay where they are.
Checked before cut-over
A setup wizard verifies the domain, destination and delivery path before MX moves, returning a specific remedy for anything that would break.
Outbound and hosting
Outbound inspection and DLP are available for mail routed through the MailThreatZero gateway. We host and maintain the gateway, so there is no appliance or agent to deploy.
Certain capabilities depend on mail-flow configuration or optional integrations.
Questions
The things buyers actually ask
What is MailThreatZero?
A managed secure email gateway. Inbound mail for a protected domain is evaluated through five core scanning stages, each of which may use one or more specialized engines or intelligence sources, then relayed to the destination you configure.
What is Mailbox Threat Response?
One workflow for the questions that come after a message is classified: which campaign it belongs to, exactly who received it, what each scanning stage found, and what any administrator did about it. Because the gateway records the recipient and Message-ID of every message as it passes through, an investigation is a targeted lookup rather than a search of every mailbox.
Campaign detection, recipient and message tracking, message detail and audit history are included with a protected domain. Locating delivered copies, previewing an action, remediating and restoring require a connected Microsoft 365 or Google Workspace platform, and supported actions depend on it. These connected-platform actions are built and tested but not yet verified against a live customer tenant, and are not represented as generally available.
Who is it for?
MSPs and MSSPs protecting many customer domains from one console, plus internal IT teams running several domains or many mailboxes without a bill that grows with headcount.
Does it replace Microsoft 365 or Google Workspace?
No. It sits in front of them. Mailboxes, calendars, users and licensing stay exactly where they are, and inbound mail is filtered before it reaches them. What that looks like on each platform: Microsoft 365 email security and Google Workspace email security.
How is it deployed?
Add the domain, set the destination for its filtered mail, then point MX at the gateway. The wizard verifies each step before the cut-over rather than after it.
How does per-domain pricing work?
You pay a monthly rate per protected domain, and every mailbox and alias on that domain is covered. Message volume does not change the price; retained storage on the archive add-on is the one metered component. See the rates and calculator.
Can we evaluate it before it changes anything?
Yes. Monitor Mode records how MailThreatZero would classify messages while allowing normal delivery. Review decisions, tune policy, and validate the fit before enabling enforcement.
Does it handle multiple customers and domains?
Yes. Every domain you manage lives in one console with each tenant's data scoped to that tenant, and policy is set per domain so one customer's tuning never becomes another's. More on multi-tenant management for MSPs.
What support is included?
Email support is included with every protected domain. Mail-flow interruptions, widespread false positives, and suspected security incidents receive priority handling. Support terms and response targets are provided with each service plan.
What's new
A selection of recent changes a customer would notice. Only what is available today — anything still needing setup is described on the release notes page rather than listed here. Current platform version: v2.61.10.
- Two-factor recovery codes
- Fewer false positives on commercial mail
- AI model chosen by measurement
- Malware scoring no longer double-counts
Who the pricing model suits
Anyone can buy it. These are the shapes of organization where paying per protected domain rather than per mailbox makes an obvious difference.
-
MSPs and MSSPs
Every customer domain in one multi-tenant console, with per-domain policy and a rate that does not move when a customer hires. How it works for partners →
-
Multi-domain organizations
Several business units, brands or acquired companies protected under one account, without a separate per-user licence for each.
-
Organizations with many shared mailboxes
Aliases, shared inboxes, service accounts and role addresses are mailboxes on a protected domain. They are covered, and they do not each carry a licence.
Built to Be Examined
Email security should not require blind trust. MailThreatZero documents how major controls work, publishes feature maturity, exposes filtering decisions, and clearly distinguishes production capabilities from features still being validated or developed.
Each capability is labelled with how finished it is, in plain words.
See how it would handle your mail.
Request a Demo, or evaluate one real domain in Monitor Mode and judge the decisions yourself before anything is enforced.
