Comparison
Email security an MSP can operate, price, and explain
How MailThreatZero compares with traditional cloud email security across deployment, threat detection, multi-tenant operations, data control, integrations, retention and cost structure.
Capabilities depend on deployment configuration. This page marks what is included in the per-domain price and what is optional, and the detail on each row says where it applies.
Vendor capabilities and packaging change frequently. Comparison last reviewed 2026-08-07. Verify licensing and product edition against a current quote before purchase.
Feature availability changes over time. MailThreatZero intentionally distinguishes generally available capabilities from features that are still being validated or developed — the feature status page lists the maturity of every capability, and nothing is marked as supported here on the strength of being planned. Competitor columns describe the general shape of standard offerings and are hedged deliberately: plans, tiers and licensing change, so verify anything that decides your purchase against a current quote, including ours.
Where MailThreatZero differs
Capabilities in the running console, not positioning statements. Each one changes how an MSP prices, operates or explains email security.
One price per domain, whatever the headcount
A protected domain costs the same with five mailboxes or two hundred: MailThreatZero pricing is based on protected domains rather than charging separately for every mailbox, with up to 250 mailboxes per domain. Onboarding a customer's staff, an acquisition or a seasonal intake does not move the security line on your own margin sheet.
Every engine's score, and what it found
The console shows each engine's raw and weighted score and what that stage actually found — "Reply-To domain mismatch", "Display name domain mismatch", "Dangerous file type" — against the threshold that decided the action. A stage that did not run says so, with the reason, rather than looking like a pass.
Your own AI and VirusTotal accounts
AI analysis runs on your own OpenAI or Anthropic account, and attachment reputation on your own VirusTotal account. You control the provider account, can review usage there, and pay the provider directly at your own rates. MailThreatZero adds no markup to that usage, and AI can be turned off per domain.
Watch a customer's real mail before enforcing on it
Monitor Mode, per domain: every message is scored and recorded and delivered anyway, so you can tune a customer's policy against their actual traffic with nothing being blocked while you do it.
Policy scoped to the domain, not the tenant
Thresholds, which engines run, allow and block lists, DLP, link rewriting, QR reading and retention are all set on the domain. A law firm and a haulage company under the same MSP account do not have to share a policy.
Continuous validation of the filtering pipeline
Automated health checks continuously validate the filtering pipeline and the enabled scanning services, alerting on failure. A filter that quietly stops working is the failure nobody notices, so the product watches its own.
Capability summary
The short version, for skimming. Every MailThreatZero mark below is a capability in the running product; the detailed comparison further down says how each one works.
- Included
- Not typically included
- Limited, varies or plan dependent
| Capability | MailThreatZero | Barracuda | Mimecast | Proofpoint | Microsoft 365 / Defender |
|---|---|---|---|---|---|
| Per-domain pricingBilled on protected domains, not seats. | Included | Not typically included | Not typically included | Not typically included | Not typically included |
| Up to 250 mailboxes per protected domainA domain costs the same with five mailboxes or two hundred. | Included | Not typically included | Not typically included | Not typically included | Not typically included |
| Multi-tenant MSP managementOne console across every tenant and domain. | Included | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent |
| Single sign-on (OIDC)Sign in to the console with Microsoft Entra, Google or any OIDC provider. Authorization code flow with PKCE; the provider establishes identity, roles stay on the account here. | Included | Included | Included | Included | Included |
| Explainable message scoringEvery stage's raw and weighted score, and the threshold it was judged against. | Included | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent |
| Engine-level visibilityA stage that did not run says so, with the reason. | Included | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent |
| Bring-your-own AI providerYour provider, your account. | Included | Not typically included | Not typically included | Not typically included | Not typically included |
| Customer-controlled AI credentialsHeld encrypted; never shared with us in usable form. | Included | Not typically included | Not typically included | Not typically included | Not typically included |
| AI usage and cost visibilitySpend per tenant and per day, with per-tenant credit limits. | Included | Not typically included | Not typically included | Not typically included | Not typically included |
| Monitor ModeScore and record without changing delivery, per domain. | Included | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent |
| SPF, DKIM and DMARC evaluation | Included | Included | Included | Included | Included |
| Malware scanning | Included | Included | Included | Included | Included |
| QR code detectionDecoded from images, PDFs and Office attachments, then scored on destination. | Included | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent |
| URL analysis | Included | Included | Included | Included | Included |
| Time-of-click protectionOptional URL rewriting, re-checked at the moment of the click. | Included | Included | Included | Included | Limited, varies or plan dependent |
| Campaign detectionOne run across many mailboxes is a single row. | Included | Limited, varies or plan dependent | Limited, varies or plan dependent | Included | Limited, varies or plan dependent |
| Tenant health monitoringEvery tenant scored and ranked, with the specific fault and its fix. | Included | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent |
| DMARC aggregate reportingReports ingested and analyzed per domain. | Included | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent | Not typically included |
| API accessPublished as an OpenAPI schema. | Included | Included | Included | Included | Included |
| Public pricingRates and tiers published on this site. | Included | Limited, varies or plan dependent | Not typically included | Not typically included | Included |
| Mailbox Threat ResponseCampaign investigation, exact recipient and Message-ID tracking, message detail and audit history are included. Locating and remediating delivered copies requires a connected mail platform. | Included | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent | Limited, varies or plan dependent |
| Post-delivery mailbox removalNot claimed. The code paths exist and are covered by tests against the provider APIs, but they have never been exercised against a live tenant — this deployment has none connected — so removal is not presented as available. | Not typically included | Included | Included | Included | Included |
| Behavioral sandboxingNot hosted by us. Attachments get multi-engine reputation through your own VirusTotal account, which is not behavioral analysis; real detonation runs only if you point the gateway at an analysis host you operate (CAPE) or a provider account you hold (Joe Sandbox). | Limited, varies or plan dependent | Included | Included | Included | Limited, varies or plan dependent |
We include current limitations in this comparison because an accurate evaluation is more useful than a one-sided feature list. Every capability shown for MailThreatZero reflects the current product, and areas where other platforms offer functionality we do not are intentionally identified.
Pricing model comparison
The commercial difference is the unit, not the number. Most major email-security platforms use per-user or per-mailbox licensing. A protected domain costs the same whether it has five mailboxes or two hundred. Adding users does not increase the MailThreatZero filtering subscription, subject to the current plan terms.
Show the pricing model comparison
| MailThreatZero | Barracuda | Proofpoint | Mimecast | Microsoft Defender | Abnormal | Cloudflare Email Security | |
|---|---|---|---|---|---|---|---|
| Licensing unit | Per protected domain, up to 250 mailboxes | Per mailbox | Per mailbox | Per mailbox | Per user, or bundled in E3/E5 | Per mailbox | Per seat |
| Cost of adding 200 mailboxes | No change | Rises | Rises | Rises | Rises unless already bundled | Rises | Rises |
| Price published on the vendor's own site | Yes, in full | No — quote | No — quote | No — quote | Yes | No — quote | No — quote |
| Commitment | Month to month, no setup fee | Commonly annual | Commonly annual | Commonly annual | Annual or bundled | Commonly annual | Commonly annual |
Scroll sideways on a narrow screen.
-
Standard
$39per protected domain / month
1–39 domains
Up to 250 mailboxes per protected domain
Partners starting out, and small MSP portfolios
-
Volume
$37per protected domain / month
40–99 domains
Up to 250 mailboxes per protected domain
Growing MSP portfolios
-
Portfolio
$35per protected domain / month
100–249 domains
Up to 250 mailboxes per protected domain
Large MSP and multi-tenant portfolios
-
Custom pricing
Custom pricingcontact us for a quote
250+ domains
Contact us for an organization or service-provider quote.
The same portfolios, priced both ways
| Scenario | MailThreatZero | Per mailbox at an illustrative $3 | Per mailbox at an illustrative $5 | Per mailbox at an illustrative $7 |
|---|---|---|---|---|
| 1 domain · 25 mailboxes | $39 / month | $75 | $125 | $175 |
| 10 domains · 500 mailboxes | $390 / month | $1,500 | $2,500 | $3,500 |
| 50 domains · 2,500 mailboxes | $1,850 / month | $7,500 | $12,500 | $17,500 |
| 100 domains · 6,000 mailboxes | $3,500 / month | $18,000 | $30,000 | $42,000 |
Add mailboxes to a domain and our figure does not move. Run your own numbers →
PayPal is accepted for the monthly subscription. Billing is month to month with no setup fee and no minimum term, and AI and VirusTotal usage is billed to you by those providers directly rather than passing through us.
Where the break-even falls
Against the mid-range of the reported figures above — about $5 per mailbox per month — a domain costs less with us once it has around seven mailboxes, and the gap widens with every mailbox after that. Some Microsoft 365 plans include Defender capabilities: compare included licensing, functionality, visibility, management and pricing against your existing subscription.
Who in this market publishes a price at all
Vendor-published figures are read from the vendor's own page. Figures marked * are reported by third-party pricing trackers, not published by the vendor — treat them as indicative and confirm with a quote. Every competitor figure on this page is per user, per month — the same period as our per-domain rate, so the columns are directly comparable once you multiply theirs by your mailbox count.
| Product | Charged by | Price published? | Published figure | Source |
|---|---|---|---|---|
| MailThreatZero Up to 250 mailboxes on every domain. | per protected domain | Vendor-published | $35–$39 / protected domain / month, custom pricing above 250 domains | our pricing page |
| Microsoft Defender for Office 365 (Plan 1) Adds Safe Links, Safe Attachments, impersonation-aware anti-phishing and real-time detections on top of the Exchange Online Protection filtering every tenant already has. Included in Microsoft 365 Business Premium and — effective 1 July 2026 — in Office 365 E3 and Microsoft 365 E3, so many tenants now have it at no extra cost. | per user | Vendor-published | $2.00 / user / month, paid yearly | microsoft.com (vendor-published) |
| Microsoft Defender for Office 365 (Plan 2) Everything in Plan 1 plus Threat Explorer, Campaign Views, Threat Trackers, automated investigation and response, attack simulation training and Defender XDR integration. Included in Microsoft 365 E5, A5 and GCC G5. | per user | Vendor-published | $5.00 / user / month, paid yearly | microsoft.com (vendor-published) |
| Proofpoint Essentials Proofpoint also publishes an MSRP price list; reseller pricing differs. | per user | Reported * | $3.03 Business · $3.36 Business+ · $5.86 Professional — per user / month * | costbench, verified 20 Jul 2026 (5 data points) |
| Barracuda Email Protection Barracuda's own plans page lists no prices and routes to sales. | per user | Reported * | $5.00 Advanced per user / month * · Premium and Premium Plus by quote | costbench, verified 19 May 2026 (2 sources) |
| Mimecast Email Security Quote-based; UK G-Cloud 14 filings show roughly £4.07–£6.19 per user. | per user | Reported * | $3–$12 per user / month, reported range * (≈$3.60–$7.20 Advanced) | TrustRadius customer reports, 2026 |
| Check Point Harmony Email & Collaboration (Avanan) Licensing documentation states a licence is consumed for every user account with a Microsoft or Google licence and at least one mailbox, so cost scales with mailbox count. An MSP multi-tenant console is offered. | per user | On request | Not published — quoted | Check Point licensing documentation |
| Abnormal AI (Abnormal Security) API-native: connects to Microsoft 365 or Google without an MX change, so it runs alongside rather than in front of the platform. Pricing is quoted, not published. | per user | On request | Not published — quoted | Abnormal product documentation |
| Mailprotector CloudFilter MSP-oriented gateway. No price is published on the vendor's site; figures are quoted through the partner channel, so nothing is stated here rather than repeating a third-party estimate. | per user | On request | Not published | mailprotector.com (vendor product page) |
| Cloudflare Email Security Sold as part of Cloudflare's Zero Trust portfolio. No unit price is published on the product page. | per seat | On request | Not published | cloudflare.com (vendor product page) |
* Reported by third-party pricing trackers or customer filings, not published by the vendor. Vendor pricing varies by plan, term, volume and negotiation, and most of these vendors quote rather than publish — always confirm against your own quote.
How each product attaches to your mail
Where a product sits decides what it can do. A gateway inspects mail before it reaches the mailbox and can refuse it outright. An API tool connects to the platform after delivery, sees internal mail a gateway never routes, and withdraws what it judges bad. Neither is strictly better and the trade is worth understanding before you choose.
| Product | MX gateway | API connected | Hybrid | Source |
|---|---|---|---|---|
| MailThreatZero MX gateway is generally available. Microsoft 365 and Google connectors for mailbox lookup and post-delivery remediation are in beta testing, not GA. | Yes — supported | Partial — partial or in validation | Partial — partial or in validation | our release notes |
| Microsoft Defender for Office 365 Native to Exchange Online; protects the platform it is part of. Connectors exist for routing mail through it. | Partial — partial or in validation | Yes — supported | Yes — supported | Microsoft documentation |
| Proofpoint Traditional MX gateway with API-based additions. | Yes — supported | Yes — supported | Yes — supported | Proofpoint product pages |
| Barracuda Gateway plus an API-connected inbox-defence component. | Yes — supported | Yes — supported | Yes — supported | Barracuda product pages |
| Mimecast Long-standing MX gateway; an API-based deployment option was announced in March 2026. | Yes — supported | Yes — supported | Yes — supported | Mimecast support documentation |
| Check Point Harmony Email & Collaboration API-based inline deployment: scans after the platform's own filters, before delivery to the mailbox. No MX change. | No — not offered | Yes — supported | No — not offered | Check Point documentation |
| Abnormal AI API-native by design; documented as deploying without MX record changes. Runs alongside the platform rather than in front of it. | No — not offered | Yes — supported | No — not offered | Abnormal documentation |
| Mailprotector CloudFilter Vendor describes it as “a secure email gateway built to deliver full inbound and outbound protection anywhere you have MX record control”, working with Microsoft 365, Google Workspace, on-prem and mixed estates. | Yes — supported | No — not offered | No — not offered | mailprotector.com (vendor product page) |
| Cloudflare Email Security Vendor states it can “deploy inline, via API, or both”, combining pre-delivery processing with post-delivery retraction. | Yes — supported | Yes — supported | Yes — supported | cloudflare.com (vendor product page) |
Where we are behind. MailThreatZero's gateway is the mature half. Our API connectors are real code with real tests, but they are in beta testing against Microsoft 365 and Google Workspace and we do not call them generally available -- so on the API axis, Check Point and Abnormal are ahead of us today.
Vendor capabilities verified against the linked documentation on 2026-08-24. Vendor capabilities, packaging and pricing change frequently. Verify the current product edition and commercial terms before purchase.
Where the others are stronger
A comparison that only flatters the vendor writing it is not worth reading. These are the places a large incumbent will serve you better than we will today.
- Threat intelligence at scale. Proofpoint, Mimecast, Abnormal and Microsoft each see a volume of mail we do not. Breadth of corpus is a real advantage for catching a campaign in its first hour, and it is not something a smaller platform argues its way out of.
- Hosted behavioral detonation, which we do not offer. They run the sandbox; we do not run one for you. Real detonation here needs an analysis host you operate or a provider account you hold, and nothing has been detonated on this deployment.
- Post-delivery remediation in production. Their removal paths run against live Microsoft 365 and Google Workspace tenants every day. Ours are written and tested against the provider APIs and have never been exercised against a live tenant.
- Account-takeover telemetry. A platform inside the mailbox sees sign-ins, session anomalies and forwarding rules. We see mail arriving at the gateway, and we infer from that. The inference is weaker than the signal.
- Security awareness training. Several of them sell simulated phishing and user training programmes. We do not offer this at all.
None of that is an argument against those products. It is the trade you are making, and it is worth stating plainly before the trade in the other direction:
- Pricing that ignores mailbox count. A protected domain costs the same whether it holds four mailboxes or two hundred.
- An explanation for every verdict. Each stage's score and finding against the threshold it was judged on, for any message, without opening a support case.
- One console across every customer domain, rather than one tenant at a time.
- Monitor Mode, so you can watch a production domain be classified before anything is allowed to act on it.
- Your own AI account, your own analysis host, your own keys — the parts we do not run are parts you control, and you pay those providers directly.
- Independence from your mailbox vendor. A second opinion in front of the platform is worth something precisely because it is not the platform.
Where we are behind, in one sentence. MailThreatZero's gateway is the mature half. Our API connectors are real code with real tests, but they are in beta testing against Microsoft 365 and Google Workspace and we do not call them generally available -- so on the API axis, Check Point and Abnormal are ahead of us today.
Payment fraud, and why we do not claim to have solved it
The expensive attack is not malware. It is an email saying a supplier’s bank details have changed — no link, no attachment, nothing for a scanner to find. Abnormal and Check Point built their businesses on it, and it is fair to ask what we do about it.
We build a picture of who each person actually corresponds with, per address rather than per domain, from delivered mail. The distinction matters: an attacker registering a near-miss of a supplier you really use passes a domain-level check the moment anyone at your company has emailed the real supplier. The fraud is aimed at one person in accounts payable, and whether that person has a history with that sender is what separates a genuine bank change from somebody stealing an invoice payment.
Payment language on its own scores nothing, however much of it there is. Your finance team discusses invoices; that is what a finance team does. It scores only when the words are corroborated by something about the sender — no history with this person, a near-miss of a domain you really deal with, authentication that failed, a reply that would go somewhere else. And the finding says which, in a sentence, rather than reporting a number.
Status: Beta. It is off by default, monitor-only when first switched on, and it has not been validated against real payment-fraud traffic — this gateway has not seen any. Replaying 239 real delivered messages produced no false positives, which tells you it stays quiet, not that it catches attacks. We will call it generally available when we have measured it against the real thing, and not before.
Want the technical details?
The summary above is designed for quick evaluation. The sections below explain how each capability is implemented, where the limitations are, and what varies by deployment or vendor edition.
Deployment comparison
MailThreatZero is a managed secure email gateway. A domain's MX points at it, it scans, and it relays to wherever the mailboxes already live — which stay exactly where they are. The table below sets that against the deployment shapes used by other categories of product.
Show the deployment comparison
How to read the status column
- Included In the product, at the per-domain price.
- Deployment-dependent Applies to the mail or the configuration the row describes.
- Optional An add-on, or a capability running on your own provider account.
- Not included Not part of the product.
- Varies by edition Packaging differs by plan, tier and negotiation — verify against a current quote.
Every status is written as a word as well as a symbol, so nothing on this page depends on color to be read.
The complete row-by-row comparison, kept in full rather than summarised.
Show the full deployment comparison
| MailThreatZeroMSP partner rate | Traditional cloud gateway | Built-in mailbox security | API-based, post-delivery | |
|---|---|---|---|---|
| Where mail is scanned | Our gateway, then relayed to you | Vendor cloud | Inside your mail platform | Your tenant, by API after delivery |
| How it attaches to your platform | MX to us, plus an inbound connector in your tenant | MX to the vendor | Already in the platform | OAuth app — no MX change |
| Where a threat is stopped | Before delivery, MX-inline | Before delivery | Inline in the platform | After delivery, then remediated |
| Your mail platform and mailboxes | Stay where they are | Stay in place | Already there | Stay in place |
| Policy scoped per domain | Standard | Verify tenancy model | One policy per tenant | Verify tenancy model |
Scroll sideways on a narrow screen. Product names are trademarks of their respective owners.
What MailThreatZero delivers into
| Capability | Status | What that means in practice |
|---|---|---|
| Inbound filtering, MX-inline | Included | Your MX points at the gateway; messages are inspected and scored before they reach your platform, so a blocked message is never in a mailbox to be withdrawn afterwards. |
| Delivery into Microsoft 365 | Included | Over an Exchange Online inbound connector — SMTP with TLS, configured inside your tenant. Mailboxes, users and licensing do not move. |
| Delivery into Google Workspace | Included | Over a Google Workspace inbound gateway. Same model, and the same option to restrict the platform to accepting mail from the gateway. |
| Delivery to any other SMTP destination | Included | A destination host and port per domain: hosted Exchange, cPanel-based mail, Zimbra or anything that accepts SMTP relay. |
| Pre-cutover verification against the live tenant | Included | Before MX changes, the setup wizard verifies the tenant, public DNS, the destination and that your platform will accept mail from the gateway — each check returning a specific remedy rather than a bare pass or fail. |
| ARC sealing of the gateway's own verdict | Included | We seal the authentication result we determined, so your platform trusts our verdict instead of deriving a wrong one from our address — the single most common way a gateway deployment quietly degrades a tenant's security. |
| Authenticated outbound submission | Included | Applications and devices submit on port 587 with a per-domain credential. |
| Internal user-to-user mail | Deployment-dependent | Requires mail-flow routing: internal mail is captured when your platform's journal rule is pointed at the gateway, as with any gateway. |
Security capability matrix
Grouped by the outcome being protected rather than by product name, so one protection is not counted several times under different labels. Engines contribute to a weighted score rather than voting pass or fail, so one heuristic cannot block a message on its own. Every enabled and applicable scanning stage runs for each message.
Show the security capability matrix
Every capability we compare, including the ones where we do not come out ahead.
Show the full security capability matrix
| Capability | MailThreatZero | Comparable products |
|---|---|---|
| Sender authentication | Included SPF, cryptographic DKIM verification against the published key, and DMARC with organizational-domain alignment. The result is ARC-sealed for your platform. | Varies by product or license |
| Authentication-aware scoring | Included When a sender authenticates, the heuristics that exist to catch spoofing stand down. Authentication context helps reduce false positives by providing additional trusted signals alongside the rest of the message. | Varies by product or license |
| Phishing, impersonation and BEC indicators | Included Display-name spoofing, homograph and lookalike domains, brand impersonation, credential lures, link-text-versus-target mismatch and header mismatches, configured per domain. | Varies by product or license |
| Impersonation of your own suppliers and named people | Included Compared against the domains this recipient actually corresponds with, built from their own delivered mail, plus a per-domain list of protected names. The supplier list is visible in the console. Payment and account-change language never scores on its own — it counts only when something independent corroborates it. | Commonly included; verify current edition |
| Warning banners on delivered mail | Optional One banner per message, never stacked, and every trigger is off until switched on. Signed and encrypted messages are never modified. | Commonly included; verify current edition |
| Account takeover signals | Included Detected from sending behavior — volume, sudden fan-out to strangers, and phishing sent from the account — with each account compared against its own history. Sign-in logs, mailbox rules and forwarding are not consulted: those need permissions on a connected mail platform, and every alert names what it could not check. Automatic containment is off and needs an explicit per-domain opt-in. | Commonly included; verify current edition |
| Links re-checked after delivery | Included Links delivered in the last week are re-evaluated every six hours against the same reputation sources the click-time check uses. A host that has since been listed raises an incident naming the messages that carried it. | Commonly included; verify current edition |
| Malicious URL protection | Deployment-dependent URL analysis at delivery is included — shorteners, unencrypted destinations, link volume and per-domain blocked URLs. Link rewriting and click-time destination analysis are enabled per domain. | Commonly included; verify current edition |
| QR code destinations | Included QR codes are decoded from image attachments, PDFs and Office documents and judged on where they lead. What was decoded is always recorded. Switched on per domain. | Varies by product or license |
| Attachment protection | Included Signature scanning on each message, a second signature database available per domain, document and macro analysis, and executable, double-extension and archive rules. Multi-engine reputation intelligence is optional, on your own VirusTotal account. A confirmed virus is rejected regardless of other scores or allow lists. | Commonly included; verify current edition |
| Behavioral sandboxing | Requires your own host Not hosted by us, and worth separating from what a reputation lookup does. Every attachment is looked up by hash first, which discloses nothing. A file nobody has seen before can be submitted to your own VirusTotal account for multi-engine analysis — off by default, because submitting hands the file to a third party — and what comes back is engine verdicts, not a behavioral report. Real detonation is available when you point the gateway at an analysis host you operate (CAPE) or a provider account you hold (Joe Sandbox); the behavioral evidence then scores like any other engine. We do not run detonation infrastructure on your behalf, and nothing has been detonated on this deployment. Where no verdict arrives in time the file is recorded as inconclusive rather than clean. | Varies by edition |
| Connection and sender reputation | Included Multiple real-time DNS reputation sources on the sending IP, evaluated alongside content scoring. Honeypot trap addresses collect campaigns aimed at addresses that should never receive mail. | Varies by product or license |
| Geographic policy | Included Country rules set per domain, or once on the account and inherited, with a map of where a domain's mail actually originates. Rules by ASN are not configurable from the console. | Varies by product or license |
| Spam, bulk and content filtering | Included Rule and Bayesian scoring, collaborative fingerprint checks, a second independent scorer available per domain, plus keyword policy, hidden text, obfuscated HTML and per-domain rules. | Varies by product or license |
| AI-assisted analysis of inconclusive mail | Optional Uses the provider and credentials selected by the customer, and can be enabled or disabled per domain. It runs after the deterministic stages, and an AI verdict below critical cannot quarantine a message on its own. | Vendor-provided where offered |
| Your branding on customer reports | Included The weekly summary a customer receives carries your name, logo and color rather than ours. The line stating that mail was scanned by a security gateway is not removable — white-labelling is about whose service it appears to be, not about hiding what happened to someone's mail. | Varies by product or license |
| End-user quarantine summaries | Included Each person receives a list of the mail held for them and can release what they want, without an account and without a support call. Serious threats still require an administrator. | Commonly included |
| Read API for PSA/RMM integration | Included Versioned, scoped keys, paginated. A counters-only scope lets a monitoring integration answer "is this customer healthy" without reading anyone's mail. | Varies by product or license |
| Per-customer spam training | Included Each customer has their own Bayesian corpus rather than sharing one, so training on your mail changes your filtering and nobody else's — and a classification you later disagree with is withdrawn from your corpus exactly. An administrator can also ask the AI to re-examine a delivered message; the AI proposes a bounded change and trains nothing until a person confirms it. | Varies by product or license |
| Outbound inspection and data-loss prevention | Deployment-dependent Outbound inspection and DLP are available for mail routed through the MailThreatZero gateway. Card, ID and bank data are checksum-validated, and a message that trips a rule is held for review rather than bounced. | Requires mail-flow routing; varies by product or license |
| Per-message investigation record | Included Every engine's score, what each stage found, and the total against the threshold that decided the action. A stage that did not run records that it did not run. | Varies by product or license |
| Find every message that carried an indicator | Included Sweep on a URL, hostname, file hash, sender, QR destination or campaign fingerprint and get every message that carried it, who received it and what was done. Runs on what the gateway recorded as the mail passed through, so it needs no connection to your mail platform. | Generally requires the mail platform connection |
| Delivered and still-in-the-mailbox reported separately | Included Two different facts from two different sources. Still-present is reported as unknown unless a mail platform can answer it — never inferred from what was delivered. | Varies by product or license |
| Removing a delivered message from mailboxes | Deployment Preview then execute, as a move to a recoverable folder that can be undone — never a delete. Requires a connected Microsoft 365 or Google Workspace integration on the domain. These connected-platform actions are built and tested but not yet verified against a live customer tenant, and are not represented as generally available. | Commonly included; verify current edition |
| Retention and investigation | Optional Searchable message retention, legal hold, export and original retrieval, journaling ingestion, access auditing, tamper evidence and write-once retention are the archive add-on, charged per gigabyte retained. Message tracking and quarantine retention are included at the per-domain price. | Separate product or higher-tier plan |
| Continuous validation of the filtering pipeline | Included Automated health checks continuously validate the filtering pipeline and enabled scanning services, alerting on failure. | Not exposed |
| Published independent test results | Not currently available | Varies by product or license |
Thresholds are set per domain, so a message is judged on the balance of what several stages found rather than on one engine's opinion. Every engine, grouped by outcome →
MSP operations matrix
What running fifty customers on the product involves. Multi-tenant administration and role-based access are standard rather than an upsell tier.
Show the MSP operations matrix
Multi-tenant administration, per-domain policy, billing and reporting, row by row.
Show the full MSP operations matrix
| Capability | MailThreatZero | Comparable products |
|---|---|---|
| Multi-tenant console and role-based access | Included One sign-in across every customer you manage, with each tenant's data scoped to them. Four roles: platform administrator, tenant, domain administrator and read-only user. | Verify tenancy model |
| Delegated customer access | Included A customer can hold a domain-administrator account scoped to their own domain, without visibility of the wider portfolio. | Verify tenancy model |
| Per-domain policy | Included Thresholds, enabled engines, AI scanning, country rules, allow and block lists, DLP, link rewriting, QR analysis, archiving and retention are configured per domain. Country rules also have an account-level default, but it is only a default: a domain inherits it unless it is set to use only its own. | Verify tenancy model |
| Domain onboarding wizard | Included Generates that domain's platform-side configuration with copy-ready settings, including the two steps that are invisible until after cut-over: telling your platform to look past the gateway to the real sender, and restricting it to accept mail only from the gateway. | Varies by product or license |
| Monitor a domain's live mail before enforcing | Included Per domain: every message is scored and recorded, and delivery is unchanged, so you can tune policy against real mail before anything is enforced. | Varies by product or license |
| Central and per-domain quarantine | Included Every domain your role can see in one queue, with release, delete and sender allow or deny per message. Release reinjects the retained original message content through the configured delivery path. | Included |
| End-user quarantine access without an account | Included Tokenised links in the notification. | Portal or digest link; verify current edition |
| Cross-customer investigation | Included Message tracking searches sender, recipient, subject, IP, domain and verdict across every domain your role can see, with the per-message filter breakdown behind each row. | Varies by product or license |
| Incidents delivered to a SIEM or chat channel | Included Signed webhooks — JSON for a SIEM, plus Slack and Microsoft Teams formats. Each delivery carries an HMAC-SHA256 signature over the timestamp and body, so a captured request cannot be replayed. Counts and a reference only, never recipients, subjects or message contents. | Commonly included; verify current edition |
| Threat intelligence shared across your customers | Included An indicator confirmed independently on two separate tenancies becomes community knowledge. No tenant, domain, recipient or sender address is recorded in the shared data, a customer's own domain is never shared, and volume alone never promotes an indicator. | Vendor-wide intelligence; verify current edition |
| Portfolio health triage across customers | Included Customers ranked worst-first, with every row opening to the findings that produced it and the fix for each. | Verify current edition |
| Campaign view | Included A run that hits four hundred recipients is one row rather than four hundred, with mixed-outcome campaigns sorted first. | Varies by product or license |
| DMARC aggregate report ingestion and alerting | Included Per domain, not a separate subscription — point the record's rua= at the mailbox the console shows you. | Separate product or add-on |
| DNS validation and daily sweep | Included MX, SPF, DKIM and DMARC checked on demand and swept daily, with alerting when a record changes underneath you. | Varies by product or license |
| Two-factor authentication and audit log | Included TOTP on any administrative account with lockout on repeated failed sign-ins, and administrative and security-sensitive activity recorded to support accountability and investigation. | Varies by product or license |
| Usage figures and scheduled reporting | Included A per-tenant statement of domains at the tier rate and storage usage, plus opt-in per-domain summary emails and dashboards over selectable ranges. | Varies by product or license |
Evaluate One Domain Before You Commit
Run a customer domain in Monitor Mode to review classifications, policy behavior, and message-level decisions before enabling enforcement.
Nothing changes for users
Every message is scored and recorded and delivery is unchanged, so the evaluation runs on live production mail with nothing being blocked while you watch.
Real findings, your traffic
You see what would have been quarantined or rejected on your own domains, with the per-engine breakdown behind each decision.
Tune, then enforce
Adjust policy, allow lists and which engines run per domain, then switch enforcement on when the results look right.
What the evaluation produces
The evaluation is measured rather than described as a success in advance. At the end, you receive the number of messages assessed, proposed actions, administrator-confirmed false positives, confirmed missed threats, policy adjustments, and — where a connected tenant is used — the result of every mailbox action. Until those measurements exist, we do not publish a detection rate.
Specifically, the report states:
- Messages processed
- Would-deliver, would-quarantine and would-reject counts
- Administrator-confirmed false positives
- Administrator-confirmed missed threats
- Messages that disagreed with Microsoft Defender or the existing gateway
- Median investigation time
- Campaigns correlated
- Mailbox actions attempted, verified and failed
- Policy changes made before enforcement
Mailbox lookup, remediation and restoration are in beta testing on Microsoft 365 and Google Workspace, so the mailbox-action figures appear only where an evaluation connects a tenant. The remaining measurements come from the gateway's own records and do not depend on a connector.
Running one platform in particular? The platform-specific detail is on Microsoft 365 email security and Google Workspace email security.
Keep Defender. Add another point of view.
Microsoft Defender can remain part of your security stack. MailThreatZero does not ask you to turn anything off.
Plenty of Microsoft 365 plans now include Defender for Office 365, and telling you to stop paying for something already in your subscription would be a poor argument. The case for a second layer is not that the first one is bad — it is that two independent engines disagree, and the disagreement is where you learn something.
What a separate layer adds:
- An independent judgement. Different engines, different reputation sources and a different scoring model, in front of your platform rather than inside it.
- Portfolio visibility. One console across every customer domain, rather than one tenant at a time.
- Explainable verdicts. Every stage's score and finding against the threshold it was judged on, for any message.
- Per-domain control. Thresholds, engines, geographic rules and retention set per customer, not per tenancy-wide policy.
- Monitor Mode. Watch what a second opinion would have done to your live mail before it changes anything.
- Predictable licensing. Per protected domain, so adding mailboxes does not change the bill.
We do not claim to catch what Microsoft misses. We have not measured that, and neither has anyone who tells you otherwise without showing you the sample. What we will say is that the two look at mail differently, and that you can run one domain in Monitor Mode and see the difference on your own traffic before deciding.
What deploying in front of Microsoft 365 involves → The same for Google Workspace →
Check any of these claims
Each capability below links to documentation saying what it does, when it runs, what it uses and how it affects the score — so a claim in the table above can be checked rather than believed.
Attachment analysis
Antivirus, structure, macros, archives and multi-engine reputation. Behavioral analysis is a separate optional integration needing a provider key you supply.
QR code protection
Decoded from images, PDFs and Office documents, then assessed through the same pipeline as any link.
Click-time link protection
Rewritten links are re-checked at the moment of the click, and delivered links are re-evaluated on a schedule.
Post-delivery removal
Built and tested, and in beta testing on Microsoft 365 and Google Workspace — not yet verified against a live Microsoft 365 or Google Workspace tenant, so it is not offered yet.
Explainable scoring
Every stage's raw score, weight and the threshold it was judged against, recorded per message.
Architecture
Which interfaces carry mail and which do not, tenant isolation, and what deployment involves.
See what multiple AI models concluded
The comparison above is ours. We also give leading AI models the same neutral prompt and publish what they say, unedited, including where they rate a competitor above us.
No model response has been published yet. We publish the methodology and every response in full rather than a selected quotation.
AI scores are generated from stored model responses and are not independent certification or laboratory testing.
Deployment and capability notes
Brief clarifications where a capability depends on how the gateway is deployed.
Show the deployment and capability notes
| Capability | How it applies |
|---|---|
| Outbound inspection and DLP | Outbound inspection and DLP are available for mail routed through the MailThreatZero gateway. Applications and devices submit on port 587 with a per-domain credential, and a message that trips a rule is held for review rather than bounced. |
| Internal user-to-user mail | Internal mail is captured once your platform's journal rule is pointed at the gateway. This is a property of gateway deployment generally, and the onboarding wizard generates the steps. |
| Malicious URL protection | URL analysis at delivery is included. Link rewriting and click-time destination analysis are configured per domain, so the destination is checked at the click rather than trusted from the scan. |
| Attachment protection | Signature scanning, document and macro analysis and attachment policy are included. Multi-engine reputation intelligence runs on your own VirusTotal account, billed by them with no markup from us. Behavioral analysis is available and off by default: enabled per domain, it runs on a provider account you supply or a CAPE analysis host you operate, and is not offered as a hosted service. Submitting previously unseen files to a third-party provider is separately optional, since it discloses the file to them. |
| AI-assisted analysis | Optional, using the provider and credentials selected by the customer, enabled per account and disabled per domain. You pay your provider directly at their rates, and the per-domain subscription does not move with usage. |
| Retention and investigation | Message tracking, quarantine and the per-message investigation record come with the subscription. Searchable message retention, legal hold, export, journaling ingestion and write-once retention are the archive add-on, charged per gigabyte retained so the per-domain filtering price stays independent of your mail volume. |
See how MailThreatZero fits your mail flow, hosting model and customer base
Monitor Mode scores your real mail and records what would have happened, with delivery unchanged. That is a more useful evaluation than any table on this page.
Vendor capabilities and packaging change frequently. Comparison last reviewed 2026-08-07. Verify licensing and product edition against a current quote before purchase.
