Security.com

9 secure email gateway options for 2024

By Karen Scarfone

Business email has been around a long time, but that doesn't mean it's always safe to use -- quite the contrary.

As you sit here reading, malicious hackers and other cybercriminals are drawing a target on your company's back. The bull's-eye mark is your corporate email, the wide-open entry through which attackers can gain admission to your proprietary information and wreak general havoc.

No industry is safe, and email phishing attacks continue to pummel enterprises. But companies can take steps to protect themselves from email-based attacks, such as educating their user bases and investing in email security tools.

Email security gateways, for example, work by filtering out email with malicious content and preventing them from ever reaching employees' inboxes. Today's email security gateways are available as cloud-based installations, on-premises installations and cloud-based services.

Here's a look at some popular email security gateways and similar products, in alphabetical order.

Abnormal

Abnormal Security positions its cloud-native email security platform as a replacement for or supplement to traditional email security gateway appliances. It offers similar capabilities, but instead of relying on known indicators of compromise, it develops baselines of known-good behavior and uses AI to detect anomalies.

Abnormal also emphasizes its use of APIs to integrate with Microsoft 365, Google Workspace and other email and collaboration technologies, as well as other cybersecurity tools.

As of publication, all ratings for Abnormal on the Gartner and G2 peer review sites were four or five stars -- significantly higher than average for this product class. Reviewers noted the Abnormal service's strong automatic remediation capabilities, as well as its insight-rich dashboard and threat reports. But reviewers also mentioned occasional false positives and false negatives.

Features of the Abnormal platform include the following:

Avanan

Avanan, owned by Check Point, offers a cloud-based, inline email security service that the company positions as an alternative to traditional email security gateways.

Avanan relies on API-based integration to support Microsoft 365, Google Workspace and other email and collaboration platforms, focusing on identifying and stopping advanced threats email service providers miss. The company claims to reduce phishing attacks by 99%.

At the time of publication, nearly every review on the G2 and Gartner peer review sites was positive. Many reviewers highlighted Avanan's ability to accurately detect and stop novel attacks, as well as its ability to explain threats and their causes. Common complaints included weak data loss prevention (DLP) capabilities, a lack of configuration and tuning options, and a relatively steep learning curve for less experienced administrators.

The Avanan service includes the following features:

Barracuda Email Protection

Barracuda Email Protection from Barracuda Networks provides advanced, cloud-based email security gateway functionality specifically for Microsoft 365 email accounts.

Barracuda Email Protection is available in three tiers: Advanced, Premium and Premium Plus. All offer the same core email security functionality, with Premium and Premium Plus providing additional capabilities, such as domain fraud protection, integration with other security technologies and automated workflows.

The Gartner peer review site had numerous positive reviews for Barracuda Email Protection. Many praised its integration with Microsoft 365, the quality of its detection and filtering capabilities, and service from the Barracuda support team. Others, however, had concerns about Email Protection's interfaces, especially its limited integration capabilities and lack of API. (Note: The RESTful API is in beta as of this writing.)

Features of Email Protection include the following:

Cisco Secure Email Threat Defense

Cisco Secure Email Threat Defense is a cloud-native product for secure email communications, which also aims to prevent corporate data loss by staving off malware, ransomware, phishing and spam.

Cisco offers Email Threat Defense as an add-on to its other technologies with a per-user subscription fee. It is designed to supplement Microsoft 365's own security capabilities, improving threat detection and defense and increasing an organization's visibility into its own email security.

Positive G2 reviews cited excellent performance and strong cybersecurity features of Cisco Secure Email Threat Defense. The most common complaint among reviewers was the relatively high cost of the offering compared to competitors.

Features of Email Threat Defense include the following:

Fortinet FortiMail

Fortinet's FortiMail offers a secure email gateway that focuses on volume-based attacks and targeted cyberthreats, with the aim of helping organizations comply with regulations and keep corporate data safe. It provides antispam and antimalware protection and also folds in advanced features, such as outbreak protection, sandbox analysis and impersonation detection, to execute more complex security functions.

Customers can deploy FortiMail on premises as appliances or in VMs in the cloud, via services such as Microsoft Azure or AWS. It's also available as a SaaS offering: FortiMail Cloud for Email Security.

FortiMail reviews on the Gartner and G2 sites were mostly positive, with many citing the value that FortiMail provides and its ease of use. Negative feedback most often involved installation challenges and poor setup documentation -- problematic for less experienced administrators.

Features include the following:

Ironscales Protect

Ironscales Protect is a cloud- and API-based email security service that replaces traditional email security gateways. Its email security features provide protection against email spoofing, impersonation, malware, phishing and account takeovers, plus phishing simulations and employee security awareness training.

Ironscales uses AI to automatically analyze and respond to threats and to provide advice and support to human administrators.

Comments on the Gartner and G2 peer review sites were mostly positive, with many praising the company for rapidly evolving and improving Ironscales Protect and for being responsive to questions and suggestions from customers. Common complaints about Ironscales Protect included repetitive and limited phishing simulations and security awareness training, as well as limited data reporting functions.

Features of Ironscales Protect include the following:

Microsoft Exchange Online Protection

Microsoft's Exchange Online Protection (EOP) is a cloud-based service that protects against spam and malware. It uses URL and domain blocking tools, antimalware engines, antispoofing protection, and deep message and attachment inspection.

EOP is included in Microsoft 365 deployments that have Microsoft Exchange Online mailboxes, and it can also be added on to protect on-premises Microsoft Exchange mailboxes and any other SMTP-based mail server. The full set of EOP features is available for Exchange Online mailboxes only, although most EOP features are supported regardless of the deployment model.

Feedback from users on Gartner indicated EOP's spam filtering and malware detection work well and setup is extremely easy for existing Microsoft customers. Common complaints included false positives that caused emails or email attachments to be blocked or quarantined. Users also noted the need for more granular policy definitions.

Features include the following:

Mimecast Email Security, Cloud Gateway

Mimecast Email Security, Cloud Gateway uses sophisticated detection engines and intelligence to protect email data and employees from spam, malware, phishing and targeted attacks. Mimecast's email security features are available through cloud-native, on-premises and hybrid deployments, and they can supplement the security features built into Microsoft 365 and Google Workspace. The service includes email archiving and security awareness training.

Gartner and G2 reviewers gave Mimecast high marks for its flexible and customizable policies and the power they provide to administrators. But reviewers also said the complexity of the administrator interface makes Mimecast challenging to learn and use, complicating both initial deployment and daily administrative use.

Features include the following:

TitanHQ SpamTitan

TitanHQ's SpamTitan delivers email security products in the following models:

SpamTitan uses a variety of techniques and technologies, including sandboxing and multilayered antispam analysis and antivirus protection, to identify and stop email-based threats. SpamTitan is intended to minimize the amount of time human administrators need to spend on email security, in part by enabling users to vet their own blocked emails.

Comments from Gartner and G2 reviewers were generally positive and indicated that they find SpamTitan to be easy to set up and implement, with a strong end-user interface. Several complaints centered on poor detection performance, with high rates of both false positives and false negatives, and slow customer support response times.

SpamTitan features include the following:

Editor's note: The author selected these email security tools based on market research and prioritized offerings that have sizable customer bases; are under active development -- i.e., not nearing end of life; have recent user reviews that are mostly positive; and have distinguishing characteristics and features.

31 Jan 2024

All Rights Reserved, Copyright 2000 - 2024, TechTarget | Read our Privacy Statement