Feature status
What is available today
What is available today, what is still being proven, and what is not built. We publish this because the alternative is a feature list where everything looks equally finished, and the parts that are not are the ones you would find out about during a migration.
How to read this
- Generally available Works end to end today.
- M365/Google Workspace BETA TESTING Built and covered by tests against recorded API behavior, and in beta testing against Microsoft 365 and Google Workspace. Not yet verified against a live customer tenant, so it is not offered as a capability today.
- Beta — monitor first Built and off by default. When switched on it reports rather than acts, so you can see what it would have done before it does anything. Distinct from M365/Google Workspace beta testing, which is built and being proven against those platforms but not yet verified against a live customer tenant.
- Requires setup Works, but needs infrastructure or credentials you provide.
- Not available Not implemented, and not represented as available anywhere. No date is given unless one is committed.
Prevent
- Inbound MX gateway filteringGenerally available
- Spam, phishing and malware scanning (multiple independent engines)Generally available
- BEC and impersonation detectionGenerally available
- Payment and invoice fraud detectionBeta — monitor firstOff by default, and monitor-only when first switched on. Payment language alone scores nothing, however much of it there is — a finance team discusses invoices, and that is what a finance team does. It scores only when the language is corroborated by something about the sender: no correspondence history with that person, a near-miss of a domain you really deal with, authentication that failed, a reply that would go somewhere else. One corroborating signal is a suspicion; two is a finding, and the finding names which. It has not yet been validated against real payment-fraud traffic, so it is offered as beta rather than as a solved problem — the failure mode of getting this wrong is flagging your finance department.
- QR-code phishing detectionGenerally available
- SPF, DKIM, DMARC and ARC evaluationGenerally available
- Link protection and delayed URL re-analysisGenerally available
- Static and structural attachment analysisGenerally available
- Behavioral attachment analysis (VirusTotal, Joe Sandbox, or a self-hosted CAPE host)Requires setup — requires a VirusTotal or Joe Sandbox account you supply, or a CAPE host you operateOff by default. Runs on a provider account you supply or a CAPE analysis host you operate — MailThreatZero does not offer detonation as a hosted service. Behavioral evidence feeds the same explainable score as every other engine.
- Content disarm and reconstruction (CDR)Not available
Detect
- Campaign correlation across a tenantGenerally available
- Explainable per-message scoringGenerally available
- Monitor Mode on real trafficGenerally available
- Outbound behavioral anomaly detectionGenerally available
- Account-takeover risk from Microsoft and Google identity telemetryM365/Google Workspace BETA TESTINGCoverage depends on your provider licence - sign-in risk signals are not available on every plan. Not yet verified against a live customer tenant; the gateway-side sending-behavior detection it complements is generally available and is listed separately.
- User-reported phishing triageRequires setup — requires a connected tenant, for removing matching copies from other mailboxesReporting, triage and campaign correlation work on the gateway alone. Removing matching copies from other mailboxes requires a connected tenant.
Respond
- Message tracking and threat huntingGenerally available
- Quarantine, release and end-user digestsGenerally available
- Mailbox lookup in Microsoft 365 and Google WorkspaceM365/Google Workspace BETA TESTINGBuilt against the Microsoft Graph and Google Directory APIs and covered by tests, but not yet run against a live customer tenant. Test coverage is not a substitute for that and is not offered as one.
- Post-delivery removal with verificationM365/Google Workspace BETA TESTINGEvery action is a MOVE to a recoverable folder, never a delete, and the result is read back and reported per mailbox. Built and covered by tests against recorded Graph and Gmail behavior; not yet verified against a live customer tenant.
- Bulk campaign remediationM365/Google Workspace BETA TESTINGJoins campaign detection to per-message remediation so one confirmed run is handled once. Built and tested; not yet verified against a live customer tenant.
- Automatic remediation policy and dry-run decision engineGenerally availableThe DECISION, not the removal. A per-domain policy (off by default) states which deterministic signals qualify — a signature, a detonation, a confirmed hash, an administrator — and how large a batch may be handled without approval. AI, heuristics and reputation may contribute evidence but can never authorise removal alone. The policy screen on each domain and /api/v1/auto-remediation configure it and preview what it would decide about a piece of evidence, as a dry run that touches nothing. Execution is a separate capability, listed separately, and is not offered: nothing in this product removes delivered mail unattended.
- Automatic post-delivery remediation execution (unattended removal)Not availableNot built, and deliberately so. The policy engine above decides; nothing acts on that decision without a person. Removal of delivered mail happens only through the mailbox integrations, one reviewed action at a time, and unattended execution will not be offered until it can be validated against a live tenant.
Protect data
- Outbound DLPGenerally available
- Email archivingGenerally available
- WORM retentionGenerally available
- Emergency inbox and continuityGenerally available
- Legal hold (per message)Generally availableA held message is never removed by retention expiry and its content is never collected while the hold stands; deletion requests against it are refused rather than silently ignored. Holds are placed per message with a reason and are audited. Holding a whole search result, a sender or a date range, and grouping holds into a case, are not built.
- eDiscovery casesGenerally availableCases group preserved messages under a named matter, recording who preserved each one and why. Adding a message places a legal hold that suspends deletion; closing the matter releases the holds that case alone was keeping, and a message another open case or a hand-placed hold still needs stays held. Driven from Mail > eDiscovery or through /api/v1/ediscovery. Export is not built: the case lists what is preserved, and the messages are retrieved from the archive.
Operate
- MSP multi-tenancy with per-domain policyGenerally available
- Up to 250 mailboxes per protected domainGenerally available
- Reporting and scheduled summariesGenerally available
- REST APIGenerally available
- Webhooks and SIEM deliveryGenerally available
- Single sign-on (OpenID Connect)Generally available
- Two-factor authentication with recovery codesGenerally available
- Bring your own AI provider, and run without AI entirelyGenerally available
- SAML 2.0Not available
- SCIM provisioningGenerally availableAn identity provider (Entra, Okta) creates and disables console accounts, so offboarding happens in one place. A tenant-scoped bearer token authenticates SCIM 2.0 at /scim/v2; what a provisioned user may do comes from the group-to-role mapping an operator configures, not from the directory. An unmapped group earns the lowest role and superadmin can never be granted this way. Tokens are issued and revoked from Admin > Directory Sync, shown once, and stored hashed.
- Passkeys / WebAuthnGenerally availablePasswordless console sign-in with WebAuthn. Every attestation and assertion signature is verified for real, challenges are server-issued and single-use, a person may enrol several authenticators, and an authenticator whose signature counter goes backwards — the signature of a cloned credential — is revoked rather than trusted. Enrol from My Profile; sign in with the passkey button on the login page. It is additive: it mints the ordinary session and never touches the password or TOTP path, which remain for anyone not enrolled. Nothing secret is stored, only public keys. Verified end to end in a browser with a software authenticator; not yet exercised with a hardware key.
Why this page exists
A feature list where everything looks equally finished is easy to write and expensive to believe. The parts that are not finished are exactly the parts you would otherwise discover during a migration.
Nothing here carries a date unless we have committed to one. Release notes record what actually shipped, and this page is updated for v2.61.10.
