State of the space ·  AUG 2026

Email Defence Agent

The AMS Map places eight roster vendors across agent independence, job width, and output to cost, with each chip carrying its pricing metric or pricing not public.
The quadrant, Aug 2026 ·open full page →· this file does not change after publish

All eight still price by coverage

Email Defense Agents inspect email and messaging threats, triage reports, and take permitted containment actions across cloud mailboxes. Their range runs from guided investigation through policy-bounded deletion and quarantine; agentic pricing remains tied to protected users and mailboxes, with Material Security listing Essentials at $4 per user per month, billed annually.

1Protected user licensePositions: Monetizely analysisPublic data only
8 / 10
Roster / tracked companies.
2 of 8
Roster products with public numeric pricing.
2025
First named roster agents shipped.

Who is on this map

No items found.

Eight products clear the roster. The established group includes Abnormal Inbound Email Security, Barracuda Email Protection, Darktrace / EMAIL, IRONSCALES Email Protect, Microsoft Defender for Office 365, and Proofpoint Core Email Protection with Satori. Abnormal’s 2026 dataset spans 4,669 customer accounts, Barracuda states that hundreds of thousands of businesses use its platform, Darktrace reports more than 5,000 organizations using Darktrace / EMAIL, IRONSCALES reports more than 18,000 organizations, Microsoft ships the product in enterprise subscriptions, and Proofpoint reported $2.45 billion in 2025 annual recurring revenue.

Material Email Security and Sublime Security with Autonomous Security Analyst are emerging entries. Material disclosed $100 million in Series C funding, and Sublime disclosed a $60 million Series B; both have shipped automated email remediation or task-specific email work. Broader platforms route here only for their email-defense work, so Microsoft, Proofpoint, and Darktrace appear once. Tracked products graduate when public product evidence documents a task-specific agent that performs email-defense work with defined actions or guarded remediation.

Mimecast Email Security API-Based Protection and Check Point Email Security remain tracked. Both publicly document automated email remediation, while the materials reviewed for this edition did not establish a shipped, task-specific email-defense agent for the roster.

What this category does

Email Defense Agents detect phishing, business email compromise, malicious links and attachments, account compromise, and coordinated message campaigns. The category includes pre-delivery inspection and post-delivery remediation, meaning the removal, movement, quarantine, or containment of messages after they reach a mailbox, when the product can execute that work automatically under administrator-defined controls.

Email security and messaging administrators retain ownership of deployment permissions, policy thresholds, high-impact exceptions, investigation of ambiguous incidents, regulatory recordkeeping, and incident coordination. Product controls commonly preserve human review for consequential actions, particularly when a workflow can alter mailboxes, user access, or detection policy.

The task list agents can take over
  1. Detect - Classify suspicious messages, links, attachments, sender behavior, and campaign variants.
  2. Investigate - Correlate user reports, mailbox history, and related messages into an evidence-backed verdict.
  3. Contain - Delete, quarantine, relabel, or otherwise remediate confirmed threats across affected mailboxes.
  4. Adapt - Convert confirmed findings into bounded detection logic, feedback, or future workflow coverage.

The agentic shift

From automated cleanup to named task agents

In 2024, IRONSCALES extended its integrated cloud email security release for Google Workspace, while the company’s Winter 2025 release described Autopilot as full detection and remediation automation. This period shows the category’s earlier emphasis on automatic response workflows that operate within configurable controls.

In 2025, Sublime released Autonomous Security Analyst in April to triage user-reported messages, followed by Autonomous Detection Engineer for detection work. In 2026, Proofpoint documented Satori Abuse Mailbox Agent for guarded user-report triage, and Microsoft documented Security Copilot’s Phishing Triage Agent as autonomously classifying reported phishing before automated investigation and response. The named-agent pattern narrows autonomy to a defined task, evidence trail, and action boundary.

Observed commercial structure remains license-led. Material lists Essentials at $4 per user per month, billed annually, while Sublime makes its Core plan free for the first 100 mailboxes. Barracuda publishes Email Protection on a per-user-per-month structure, and Microsoft licenses Defender for Office 365 through user subscription licenses that can also be included in broader plans.

Abnormal, Darktrace, IRONSCALES, and Proofpoint route commercial evaluation through demos, quotes, or license-and-term discussions, so pricing is not public. In the public materials reviewed, no roster vendor states a separate price for an agent action, a remediated message, or a measured outcome. The roster meter is the protected user or mailbox.

Sources: Material Security, Sublime Security, Barracuda, Microsoft, Proofpoint, IRONSCALES.

Sources:category analysis,NDR comparison,Vendr

Observed monetization patterns
  1. Published seat price - Material Essentials is listed at $4 per user per month, billed annually.
  2. Free mailbox threshold - Sublime Core is free for the first 100 mailboxes, with Enterprise routed to a demo process.
  3. Per-user plan structure - Barracuda Email Protection presents a per-user-per-month price structure, subject to minimums and quote paths.
  4. Bundled user licensing - Microsoft Defender for Office 365 Plan 2 is included in specified enterprise subscriptions and adds investigation, response, and automation capabilities.
  5. Quote-led licensing - Proofpoint states that budgetary pricing varies by user licenses and contract term; pricing is not public.

This quarter

May - Aug 2026 ·gold = a monetization move· grey = product, market, or capital

The long arc

2024-2026 - documented shift from remediation automation to named task agents.

Vendor by vendor

Journalist first, analyst second

Method:we work journalist first and analyst second. We document the agentic products each vendor actually ships, with sources a reader can check, and the AMS placement follows from that documented capability. Vendors with no shipped agentic product stay on the quadrant and out of this section. We report how each vendor charges today, and we do not use this page to advise vendors on what to charge.
No items found.

Not covered

Corelight builds the evidence pipeline that most of the other tools on this page depend on, on top of  Zeek, one of the most widely used network analysis frameworks in security. When we went looking for a shipped  product that triages, investigates, or responds on its own, we did not find one, so Corelight stays on the quadrant and out of the breakdown section. The same finding applies to Netography, which provides flow observability at scale. If either company ships an agentic product, it enters this section in the edition that documents it.

About this data

Everything on this page is a synthesis of public information: published reporting, analyst coverage, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.