
Email Security
Advanced Email Security
Email security for Microsoft 365, Google, and on-prem, via MX gateway or API deployment.
Advanced Email Security Overview
What it does
Advanced Email Security is Mimecast's email security product for Microsoft 365, Google Workspace, and on-premise or hybrid mail environments. It defends against phishing, business email compromise (BEC), impersonation, malicious URLs, and weaponized attachments. Its distinguishing approach is anomaly detection with social graphing, which models the strength and pattern of communication relationships to flag deviations that signal social engineering. The same protection is delivered two ways: a Cloud Gateway routed by MX record, or a gateway-less Cloud Integrated deployment connected to the mailbox by API.
How it works
The product applies machine learning and behavioral analysis to message content, links, and attachments, scoring relationship strength, urgency, and linguistic context to surface social engineering and business email compromise. Suspicious links are checked before delivery and re-evaluated at the moment of click, attachments are detonated in a sandbox, and computer vision inspects branded login pages used for credential theft. Cloud Gateway routes inbound mail through Mimecast by MX record change for pre-delivery filtering, while Cloud Integrated connects to Microsoft 365 by API for post-delivery detection and remediation. Emails users report are auto-classified and removed across all affected mailboxes.
Credentials and traction
SOC 2 Type II, ISO/IEC 27001:2022, and ISO/IEC 42001:2023 certified, with attestations available through the Mimecast Trust Center. Mimecast protects more than 42,000 organizations and 27 million users across over 100 countries, and this product anchors its broader Human Risk Management portfolio. It targets enterprises standardized on Microsoft 365 or Google Workspace that need threat protection layered alongside native email security controls.
Key Capabilities
mapped to solution categoriesRoutes all inbound email through the SEG via MX record change, enabling pre-delivery inspection, queuing, and filtering before messages reach the mail server.
Detonates email attachments in an isolated execution environment before delivery, detecting zero-day malware and weaponized documents that bypass signature-based detection.
Rewrites links in inbound email and re-checks the destination at the moment the user clicks, blocking pages that were weaponized after delivery.
Filters spam and bulk unwanted mail before delivery.
Detects and prevents phishing and business email compromise using reputation, signatures and content analysis.
Inspects outbound email for data loss prevention policy violations, malicious content, and phishing links before delivery to external recipients.
Enforces TLS for SMTP transport and supports S/MIME or PGP for end-to-end message encryption based on sender policy or recipient certificate availability.
Connects to Microsoft 365 or Google Workspace via native APIs for visibility into internal and delivered mail, enabling post-delivery clawback without changing MX records.
Builds per-user and per-vendor communication baselines from historical email patterns to detect anomalous content, timing, or sender behavior without relying on signatures or blocklists.
Detects signs of internal mailbox compromise (anomalous login geography, mail forwarding rule creation, unusual send volume), and can trigger automated session revocation.
Detects compromised or spoofed third-party supplier accounts by analyzing communication pattern deviations, domain aging, and content signals, targeting invoice fraud and payment redirection attacks.
Analyzes email body text semantically to detect social engineering, pretexting, and urgency manipulation in messages that contain no malicious attachments or URLs.
Automates the intake, deduplication, and triage of user-submitted suspicious emails, cross-references against in-flight campaigns and triggers retroactive remediation across all recipients.
Inserts dynamic banners into delivered messages flagging risk signals such as first-time senders, lookalike domains, or unusual payment requests at read time.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on August 5, 2026
Buyers
See how Advanced Email Security fits your stack
Add Advanced Email Security to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.