State of the space ·  AUG 2026

Email Defense Agents

The AMS Map places eight roster vendors across agent independence, job width, and output to cost, with each chip carrying its pricing metric or pricing not public.
The quadrant, Aug 2026 ·open full page →· this file does not change after publish

All eight still price by coverage

Email Defense Agents inspect email and messaging threats, triage reports, and take permitted containment actions across cloud mailboxes. Their range runs from guided investigation through policy-bounded deletion and quarantine; agentic pricing remains tied to protected users and mailboxes, with Material Security listing Essentials at $4 per user per month, billed annually.

2Protected user licensePositions: Monetizely analysisPublic data only
8 / 10
Roster / tracked companies.
2 of 8
Roster products with public numeric pricing.
2025
First named roster agents shipped.

Who is on this map

Abnormal AI

Eight products clear the roster. The established group includes Abnormal Inbound Email Security, Barracuda Email Protection, Darktrace / EMAIL, IRONSCALES Email Protect, Microsoft Defender for Office 365, and Proofpoint Core Email Protection with Satori. Abnormal’s 2026 dataset spans 4,669 customer accounts, Barracuda states that hundreds of thousands of businesses use its platform, Darktrace reports more than 5,000 organizations using Darktrace / EMAIL, IRONSCALES reports more than 18,000 organizations, Microsoft ships the product in enterprise subscriptions, and Proofpoint reported $2.45 billion in 2025 annual recurring revenue.

Material Email Security and Sublime Security with Autonomous Security Analyst are emerging entries. Material disclosed $100 million in Series C funding, and Sublime disclosed a $60 million Series B; both have shipped automated email remediation or task-specific email work. Broader platforms route here only for their email-defense work, so Microsoft, Proofpoint, and Darktrace appear once. Tracked products graduate when public product evidence documents a task-specific agent that performs email-defense work with defined actions or guarded remediation.

Mimecast Email Security API-Based Protection and Check Point Email Security remain tracked. Both publicly document automated email remediation, while the materials reviewed for this edition did not establish a shipped, task-specific email-defense agent for the roster.

What this category does

Email Defense Agents detect phishing, business email compromise, malicious links and attachments, account compromise, and coordinated message campaigns. The category includes pre-delivery inspection and post-delivery remediation, meaning the removal, movement, quarantine, or containment of messages after they reach a mailbox, when the product can execute that work automatically under administrator-defined controls.

Email security and messaging administrators retain ownership of deployment permissions, policy thresholds, high-impact exceptions, investigation of ambiguous incidents, regulatory recordkeeping, and incident coordination. Product controls commonly preserve human review for consequential actions, particularly when a workflow can alter mailboxes, user access, or detection policy.

The task list agents can take over
  1. Detect - Classify suspicious messages, links, attachments, sender behavior, and campaign variants.
  2. Investigate - Correlate user reports, mailbox history, and related messages into an evidence-backed verdict.
  3. Contain - Delete, quarantine, relabel, or otherwise remediate confirmed threats across affected mailboxes.
  4. Adapt - Convert confirmed findings into bounded detection logic, feedback, or future workflow coverage.

The agentic shift

From automated cleanup to named task agents

In 2024, IRONSCALES extended its integrated cloud email security release for Google Workspace, while the company’s Winter 2025 release described Autopilot as full detection and remediation automation. This period shows the category’s earlier emphasis on automatic response workflows that operate within configurable controls.

In 2025, Sublime released Autonomous Security Analyst in April to triage user-reported messages, followed by Autonomous Detection Engineer for detection work. In 2026, Proofpoint documented Satori Abuse Mailbox Agent for guarded user-report triage, and Microsoft documented Security Copilot’s Phishing Triage Agent as autonomously classifying reported phishing before automated investigation and response. The named-agent pattern narrows autonomy to a defined task, evidence trail, and action boundary.

Observed commercial structure remains license-led. Material lists Essentials at $4 per user per month, billed annually, while Sublime makes its Core plan free for the first 100 mailboxes. Barracuda publishes Email Protection on a per-user-per-month structure, and Microsoft licenses Defender for Office 365 through user subscription licenses that can also be included in broader plans.

Abnormal, Darktrace, IRONSCALES, and Proofpoint route commercial evaluation through demos, quotes, or license-and-term discussions, so pricing is not public. In the public materials reviewed, no roster vendor states a separate price for an agent action, a remediated message, or a measured outcome. The roster meter is the protected user or mailbox.

Sources: Material Security, Sublime Security, Barracuda, Microsoft, Proofpoint, IRONSCALES.

Sources:category analysis,NDR comparison,Vendr

Observed monetization patterns
  1. Published seat price - Material Essentials is listed at $4 per user per month, billed annually.
  2. Free mailbox threshold - Sublime Core is free for the first 100 mailboxes, with Enterprise routed to a demo process.
  3. Per-user plan structure - Barracuda Email Protection presents a per-user-per-month price structure, subject to minimums and quote paths.
  4. Bundled user licensing - Microsoft Defender for Office 365 Plan 2 is included in specified enterprise subscriptions and adds investigation, response, and automation capabilities.
  5. Quote-led licensing - Proofpoint states that budgetary pricing varies by user licenses and contract term; pricing is not public.

This quarter

May - Aug 2026 ·gold = a monetization move· grey = product, market, or capital

Packaging

On June 17, Barracuda launched Integrated Email Protection, an API-based ICES offering that continuously detects and remediates threats after delivery, including message clawback. The launch turned autonomous post-delivery defense into the base of a three-tier commercial lineup: Integrated Email Protection, Premium, and Premium Plus. Premium adds Microsoft 365 data protection, while Premium Plus adds awareness training and archiving; pricing not public because Barracuda publishes customized quotes rather than list prices.

Source: Barracuda Integrated Email Protection launch announcement, Barracuda Integrated Email Protection plans and quote-based pricing

Agent workflows

On June 24, Trend Micro deployed six capabilities to its U.S. Cloud Email and Collaboration Protection environment without mail-flow downtime. The release made AI-assisted investigation and response more native to the email-security workflow, with centralized quarantine operations, risky-user queries in Vision One Companion, Outlook AskAI, and automatic collection of user-reported messages. It also added mailbox-level misdirected-mail detection for outbound email, extending the category's remit to accidental data exposure.

Source: Trend Micro June 2026 Cloud Email and Collaboration Protection deployment notes

Encrypted-mail detection

On July 29, Check Point Email Security introduced an AI engine for phishing detection in secured and encrypted emails, where message content is unavailable to conventional inspection before the recipient authenticates. The new engine became the default handling workflow for secured email unless an administrator had previously changed the setting. The release shows vendors pushing email defense into edge cases where policy and sender reputation alone can create either blind spots or excessive false positives.

Source: Check Point secured-email AI detection product update

Managed response

On August 3, Mimecast introduced Managed Threat Response, a redesigned 24/7 service in which AI triages every user-reported email and Mimecast analysts remediate confirmed threats. The service shifts part of email defense from a customer-operated console to an outcome-oriented managed workflow, including tenant-wide campaign removal, sender or domain blocking, and detection updates based on confirmed incidents. Mimecast did not disclose pricing or contract terms for the service, so pricing not public.

Source: Mimecast Managed Threat Response launch announcement

The long arc

2024-2026 - documented shift from remediation automation to named task agents.

2021
PRIVATE OWNERSHIP RESET

Thoma Bravo completed its $12.3 billion cash acquisition of Proofpoint on August 31, while Check Point added Avanan as its cloud email-security asset that year. These transactions placed major email-defense assets inside a private-equity-owned vendor and a broader cybersecurity platform. The ownership reset increased the importance of platform roadmaps and acquisition-led expansion in a category once centered on standalone secure email gateways.

2022
API DEFENSE MODEL

Cloudflare completed its Area 1 Security acquisition in April and made the cloud-native email-defense capability available to Enterprise buyers, while Abnormal raised $210 million to expand its API-based Integrated Cloud Email Security product. The category began moving from mail-flow appliances toward API-deployed controls that could layer onto Microsoft 365 and Google Workspace. Mimecast also transitioned from public to private ownership under Permira in May, reinforcing the sector's consolidation behind subscription platforms and broader security portfolios source.

2023
BEHAVIORAL RESPONSE LAYER

Proofpoint closed its acquisition of Tessian in December to add AI-based protection against accidental data loss and evolving email threats. Darktrace's ActiveAI platform launch positioned email features around early phishing detection, account-compromise signals, automated investigation, and stand-alone purchasing options. Email defense consequently expanded from filtering inbound threats to behavioral detection, investigation, and response across inbound and outbound mail.

2025
MSP SCALE PACKAGING

Proofpoint completed its $1.8 billion acquisition of Hornetsecurity on December 8, gaining a Microsoft 365 security platform with a multi-tenant control panel for MSPs and their customers. MSP and SMB delivery became a distinct package design, combining email security with backup, compliance, awareness, and access controls. In parallel, Abnormal AI's rebrand retained email as its core behavioral dataset while signaling expansion to connected applications, increasing pressure on email-defense vendors to explain their role inside broader human-risk platforms.

2026
AUTONOMOUS RESPONSE STACK

As of August 31, Barracuda had introduced Integrated Email Protection with continuous post-delivery detection and clawback, sold in three quote-based plans, so pricing not public. Trend Micro's June deployment added AI-led quarantine operations, outgoing misdirected-mail detection, end-user AskAI, and guided investigation to its cloud email product source, while Check Point made AI classification for secured emails the default workflow source. The current category is defined by continuous post-delivery evaluation and automated or guided remediation, with vendors differentiating through packaging, managed operations, and deployment model rather than inbound filtering alone.

Vendor by vendor

Journalist first, analyst second

Method:we work journalist first and analyst second. We document the agentic products each vendor actually ships, with sources a reader can check, and the AMS placement follows from that documented capability. Vendors with no shipped agentic product stay on the quadrant and out of this section. We report how each vendor charges today, and we do not use this page to advise vendors on what to charge.
Abnormal AI
L · M · Infl
SHIPPED AGENTIC PRODUCTS

Inbound Email Security uses identity, relationship, behavioral, and content signals to detect business email compromise, impersonation, phishing, malware, and payload-free attacks. It can automatically remove malicious messages before users interact with them and supports investigation and bulk remediation across Microsoft 365 and Google Workspace.

Placement:
L
 on independence,
M
 on job width, and
Inflecting
 on the value curve.

Pricing not public. Abnormal does not publish a standard rate card. The company has documented a per-user mailbox pricing model whose rate varies with the platform features purchased. Customers can procure subscriptions directly, through channel partners, or through a private Azure Marketplace offer.

Packaging is modular and can be bundled. The March 24, 2026 HRSD award combined 1,050 Inbound Email Security licenses with core account protection, AI Security Mailbox, and Email Productivity for $75,590 for one year, with two renewal options and a $226,770 estimated cumulative value. The agency documented a 4% discount from retail pricing. Public-contract estimate: dividing the first-year award by 1,050 licenses implies approximately $72 per licensed mailbox per year for that specific bundle. This is a derived estimate from the March 2026 contract, not a public list price, and it includes multiple modules and support.

Abnormal's cloud terms allow annual and multi-year subscriptions. Unless an order states otherwise, invoices are due within 30 days, later years of a multi-year term are billed on the anniversary date, and fees are non-refundable and non-cancellable. Usage exceeding an order's baseline quantity by more than 5% can be charged at the contracted per-unit rate on a prorated basis. No public evidence shows a separate meter for agent actions, investigations, messages processed, automated responses, or remediations.

HOW THEY CHARGE TODAY

Not covered

Corelight builds the evidence pipeline that most of the other tools on this page depend on, on top of  Zeek, one of the most widely used network analysis frameworks in security. When we went looking for a shipped  product that triages, investigates, or responds on its own, we did not find one, so Corelight stays on the quadrant and out of the breakdown section. The same finding applies to Netography, which provides flow observability at scale. If either company ships an agentic product, it enters this section in the edition that documents it.

About this data

Everything on this page is a synthesis of public information: published reporting, analyst coverage, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.