Get listed

Email Security

Best Secure Email Gateways in 2026: 6 MX and API-Based Email Security Tools

Filter the message on MX or read it after delivery. The FBI IC3 2024 report logged $2,770,151,146 in Business Email Compromise losses.

Expertise: Email Security · Level: Intermediate · 6 min read

The FBI 2024 Internet Crime Report recorded 21,442 Business Email Compromise complaints and $2,770,151,146 in losses. Those threads often pass SPF. The invoice is rewritten after authentication succeeds.

A secure email gateway sits on MX and filters content before the mailbox. A mailbox-API product reads after that hop. Domain policy (SPF, DKIM, DMARC) is a DNS record; it does not inspect the conversation. That record work already lives on DMARC tools.

Owning the MX hop and reading the mailbox after delivery catch BEC in different places. Buy the filter that would have stopped the rewritten invoice, not another authentication lookup.

How we evaluated

We read first-party docs, source, licenses, and release notes, and we treat a marketing page as a claim, not as proof that two products do the same work.

We grouped by architecture: MX hop versus mailbox API. We also asked whether you operate it, whether BEC is the pitch or a side module, and whether the docs name a mailbox or MX you already run.

We read first-party docs, licenses, and release notes. Unless a write-up says otherwise, we did not run a paid tenant.

ToolBest forWhat to check
RspamdModern open filter on an MX you operateModern open filter ยท Apache-2.0 ยท you operate MX
Apache SpamAssassinClassic rule filter you can still grepRule scores ยท Apache-2.0 ยท you host it
ProofpointKnown commercial SEGKnown SEG ยท commercial ยท MX gateway they sell
MimecastThe other known SEG plus archive storiesKnown SEG ยท commercial ยท continuity neighbor
Microsoft Defender for Office 365The button if mail already lives in M365Same M365 tenant ยท Microsoft terms ยท Safe Attachments / Links
AbnormalAPI-first BEC desk on a mailbox you ownAPI-first BEC ยท commercial ยท no MX cutover story
How the tools differ
Open filter
Classic SEG
Self-host rules
API / M365
1

Rspamd

Best for modern open filter on an MX you operate

Rspamd

Rspamd is a fast spam and malware-adjacent filter. Lua rules. Redis. You sit it on mail you already accept.

If you still run your own MX and will not rent a SEG on day one, this is the modern open filter. You staff it. Phish kits evolve. It is not a Microsoft API product.

Key features

  • Apache-2.0
  • Lua rules
  • You operate MX
  • Web UI they ship

Why we like it

An MX you already accept mail on can run a filter you can read.

Limits

You staff it. Phish kits evolve. Not a Microsoft API product.

2

Apache SpamAssassin

Best for classic rule filter you can still grep

Apache SpamAssassin

SpamAssassin is the rule engine a generation of MX boxes still run. Scores. Custom rules you can read.

A lot of mail still dies here, so do not pretend it is a BEC neural net. Rule lag and CPU on big queues are the catch. Not a vendor SOC.

Key features

  • Rule scores
  • Apache-2.0
  • Huge memory in ops
  • You host it

Why we like it

Honesty. The classic filter is still the box a lot of mail hits.

Limits

Rule lag. CPU on big queues. Not a vendor SOC.

3

Proofpoint

Best for known commercial SEG

Proofpoint

Proofpoint is the SEG procurement already wrote. MX cutover. Targeted-attack add-ons they sell.

If it is already in the path, tune it before you add an API desk on a whim. Commercial. MX politics.

Key features

  • MX gateway they sell
  • URL and attachment stories
  • Enterprise desk
  • Commercial

Why we like it

The hop procurement already named is the first commercial gate.

Limits

Commercial. MX politics.

4

Mimecast

Best for the other known SEG plus archive stories

Mimecast

Mimecast sells email security and continuity. Common Proofpoint alternative in RFP decks.

Second commercial so the list is not a one-logo SEG page. Archive and continuity stories sit next to the gate. Public pages are not a lab.

Key features

  • Gateway they sell
  • Continuity stories
  • Archive neighbor
  • Commercial

Why we like it

The second commercial MX is here so the shortlist is not one vendor logo. Procurement already knows this hop.

Limits

Commercial. Public pages are not a lab.

5

Microsoft Defender for Office 365

Best for the button if mail already lives in M365

Microsoft Defender for Office 365

Safe Attachments, Safe Links, and policies on the tenant you already pay for. SKU maze is the tax.

A second MX hop is sometimes vanity if Plan 2 is sitting unused. BEC that looks like a real vendor still leaks through. Microsoft-shaped.

Key features

  • Same M365 tenant
  • Safe Attachments / Links
  • Policies on the public docs
  • Microsoft docs

Why we like it

Honesty. The mailbox you already pay for is the first suite gate.

Limits

Microsoft-shaped. SKUs. BEC that looks like a real vendor still leaks through.

6

Abnormal

Best for API-first BEC desk on a mailbox you own

Abnormal

Abnormal sits on Microsoft or Google APIs rather than MX. The pitch is vendor-email fraud that survived the SEG.

When the hole is a real domain and a real vendor, an MX filter is the wrong door. API consent is a review.

Key features

  • API integration
  • BEC-shaped detections they sell
  • No MX cutover story
  • Commercial

Why we like it

A real vendor mailbox is a different hole than a lookalike domain.

Limits

Commercial. API consent is a review.

What we left out

  • Barracuda Email Security. People want a commercial SEG that is not the two logos already in every RFP. Proofpoint and Mimecast already cover the commercial MX job on this page.
  • Cisco Secure Email. Teams already run the old IronPort hop. It failed the focused-shortlist check. Two known SEGs are already on the page.

Questions before you buy

If procurement cannot get written answers, you are still buying a brochure.

  1. Does a known malware sample in a fixture mailbox we own get quarantined?
  2. Do we still own the MX hop, or is mail already in a suite we will not move?
  3. Is the hole a payload, a lookalike domain, or a real vendor mailbox?

Pick a gateway if you still own the hop. Pick an API desk if mail is already in M365 and BEC is the pain. You still need DMARC on the domain.

FAQs

Does a gateway replace DMARC?

No. DMARC is domain policy. The gateway is content and BEC. Those are different jobs. Open the matching list for the other one.

MX or API?

MX if you still own the hop. API if mail is already M365 or Google and you will not move MX.

Will you publish a phish kit?

No.

Is this a scored bake-off?

No.

Email Security resources