What you get
What a customer actually receives
Not a capability list — the things that arrive, the things you can do, and the things that turn up in your inbox without you asking, plus exactly what is covered by the domain rate and what is billed by a provider directly.
Included in the per-domain price
Everything here is covered by the domain rate. No per-mailbox component, no module to add on.
- Up to 250 mailboxes, users, aliases and shared mailboxes per protected domain
- Every scanning stage, with each engine configurable per domain
- Gateway hosting, updates, signature feeds and maintenance
- DMARC aggregate report collection, analysis and alerting per domain
- Quarantine, message tracking and per-message filter breakdown
- Multi-tenant administration with role-based access and TOTP two-factor
- Email support
Your first week
What onboarding actually looks like, in the order it happens.
1. Add the domain
Tell us where your mail should go afterwards. Nothing changes yet — your mail still flows exactly as it does today.
2. Set your platform up
The console generates the exact settings for Microsoft 365 or Google Workspace, filled in for your domain, with copy buttons rather than placeholders to translate.
3. Prove it works first
We ask your mail server whether it will accept mail for a real mailbox from us — before you change a single DNS record. Nothing is delivered by the check, and a check that could not run is reported as untested rather than counted as a pass.
4. Point MX, then watch
Monitor Mode scores and records every message for the domain with delivery unchanged, so you see the policy working on your real mail before it is enforced.
What arrives without you asking
The point of a managed service is that you are told, rather than having to go and look. These run on a schedule and only speak up when there is something to say.
Summary reporting, per domain
What was delivered, quarantined and rejected, broken down by which filter decided. Opt-in per domain, so a customer who does not want it does not get it, alongside a platform summary for the operator.
DMARC alerts
Someone sending as your domain, a policy that has weakened, your own senders quietly failing alignment, or reports that have simply stopped arriving — which looks exactly like having no problems.
DNS problems
MX, SPF, DKIM and DMARC are re-checked daily. A record that gets edited months after onboarding is the failure nobody notices.
Platform integration failures
An expiring Azure secret, a revoked key, a domain leaving the tenant, or MX being pointed away from the gateway — each one caught and raised while it is still a configuration issue.
Filters that stop working
Automated health checks continuously validate the filtering pipeline and enabled scanning services, and alert on failure — so a scanner that stops working surfaces without waiting for a customer complaint.
A link that has since gone bad
Links delivered in the last week are re-checked against reputation sources every six hours. One that was clean on arrival and is now listed raises an incident naming the messages that carried it — the mail is already in a mailbox by then, which is exactly why this runs.
An account sending unlike itself
A mailbox that has sent eleven messages a day for a year and suddenly sends four hundred, to people it has never written to. Compared against its own history, not a shared threshold. Alerting only — nothing is done to the account unless you have explicitly asked for that.
Storage over its allocation
If you use the archive add-on, storage is measured per domain and a domain over its allocation is reported. Retention continues either way, so the record stays complete and the overage is simply visible.
What you can do in the console
See why, not just what
Open any message and read each stage's verdict and score — including which one actually pushed it over the line. This is the difference between closing a false-positive ticket in a minute and arguing about it.
Release, allow, deny
Release from quarantine or add the sender to an allow or deny list from the same screen, scoped to that domain alone.
Search what arrived
Message tracking across every domain you manage, with the filter breakdown attached to each result.
Tune per domain
Thresholds, engines, geographic rules and custom rules are all per domain, so one customer's tuning never becomes another's.
Evaluate it safely
Monitor Mode scores and records every message for a domain with delivery unchanged, so a policy can be sized before it is enforced.
Find every message that carried it
Something turns out to be malicious after the fact. Sweep on the URL, hostname, file hash, sender or campaign and get every message that carried it, who received it and what was done. It runs on what the gateway recorded, so it needs no connection to your mail platform.
Protect the names people trust
Lookalikes of your own domain, of the suppliers you actually deal with, and of named people whose identity an attacker borrows. The supplier list is built from your own delivered mail and is on screen, so you can see what it is comparing against.
See where mail comes from
A world map of where a domain's mail actually originates, which is usually the clearest way to justify a geographic rule.
What is billed separately
Three things, all by the provider directly or as a metered add-on, named here so there are no surprises on an invoice.
- AI analysis API usage — use your own OpenAI or Anthropic account and pay the provider directly. MailThreatZero adds no markup.
- Attachment reputation and multi-engine analysis use your own VirusTotal account. Provider charges, if any, are paid directly to VirusTotal. MailThreatZero adds no markup.
- Message archiving — an optional MailThreatZero add-on, billed separately based on retained storage and retention term
How it deploys
The conditions are the same for every domain, and they are worth knowing before you start. The full comparison sets out every capability and how it applies.
- Mail routes through the gateway. The domain's MX points at
mt0.mailthreatzero.com, and filtered mail is handed to your platform over its own supported inbound path — an Exchange Online inbound connector, a Google Workspace inbound gateway, or any SMTP destination you set per domain. - Outbound inspection and DLP are available for mail routed through the MailThreatZero gateway. Applications and devices submit on port 587 with a per-domain credential, and outbound messages are checked against data-loss rules before they leave. Coverage depends on mail-flow configuration.
- Those submission sign-ins are watched. Every authenticated submission on port 587 happens on this gateway, so we can see it without any permission on your mail platform: a login that succeeds straight after a run of failures, a credential used from a country it has never been used from before, two sign-ins too far apart to be the same person, and bursts of failed attempts — rated by whether the username tried actually exists here. This does not cover sign-ins to your own mail server; those are in its log rather than ours.
- Attachment coverage. Signature scanning, document and macro analysis on every message, with multi-engine attachment reputation available on your own VirusTotal account.
- Internal mail joins the archive when you point a journal rule at us. Mail between two of your own users does not cross any gateway; the console generates the exact journal-rule steps so it is retained alongside everything else.
- Support. Email support is included with every protected domain. Service-impacting mail-flow issues, widespread false positives, and suspected security incidents receive priority handling.
See it against your own mail.
Run a domain in Monitor Mode and look at what it would have done, before it does anything.
