
Email Security
Darktrace / EMAIL
Self-learning AI email security for advanced threats, BEC, and GenAI-powered attacks.
Darktrace / EMAIL Overview
What it does
Darktrace / EMAIL is a cloud-native email security platform that uses Self-Learning AI to detect and respond to advanced threats through behavioral analysis rather than static rules or threat intelligence feeds. Deployed via API to Microsoft 365 and Google Workspace, the platform baselines normal communication for every user and detects novel BEC, phishing, account takeover, and generative AI social engineering attacks without relying on known signatures.
How it works
Antigena autonomous response quarantines suspicious messages, rewrites links, and disables compromised accounts at machine speed. Cyber AI Analyst produces natural language investigation narratives, while label-free behavioral DLP monitors outbound email and Microsoft Teams chat for data loss. The Mailbox Security Assistant gives analysts a unified remediation console, and multi-domain correlation links signals across email, identity, and SaaS to expose full attack chains.
Credentials and traction
Darktrace / EMAIL is certified to ISO/IEC 27001, ISO/IEC 27018, and ISO/IEC 42001 (BSI AI management system) standards. Darktrace was named a Leader in the 2025 Gartner Magic Quadrant for Email Security Platforms and a Gartner Peer Insights Customers' Choice for Email Security Platforms. Named customers include Aston Martin, McLaren, and West Ham United, part of an installed base of more than 10,000 organizations worldwide.
Key Capabilities
mapped to solution categoriesConnects to Microsoft 365 or Google Workspace via native APIs for visibility into internal and delivered mail, enabling post-delivery clawback without changing MX records.
Separates newsletters and bulk mail from threats by routing them to dedicated folders, refining classification from how each user files messages.
Automates the intake, deduplication, and triage of user-submitted suspicious emails, cross-references against in-flight campaigns and triggers retroactive remediation across all recipients.
Builds per-user and per-vendor communication baselines from historical email patterns to detect anomalous content, timing, or sender behavior without relying on signatures or blocklists.
Analyzes email body text semantically to detect social engineering, pretexting, and urgency manipulation in messages that contain no malicious attachments or URLs.
Detects compromised or spoofed third-party supplier accounts by analyzing communication pattern deviations, domain aging, and content signals, targeting invoice fraud and payment redirection attacks.
Assesses the email communication risk posture of external supplier domains, flagging suppliers with poor email authentication, recent domain registration, or anomalous communication patterns.
Detects signs of internal mailbox compromise (anomalous login geography, mail forwarding rule creation, unusual send volume), and can trigger automated session revocation.
Inserts dynamic banners into delivered messages flagging risk signals such as first-time senders, lookalike domains, or unusual payment requests at read time.
Detects AI-generated impersonation in email-borne fraud - synthetic text, deepfake audio and video lures, and cloned sender styles - beyond signature and rule-based content analysis.
Extends the same phishing, malware, and social-engineering detection applied to email to messages and files in collaboration and productivity tools such as Teams, Slack, SharePoint, OneDrive, Google Drive, and Salesforce, through the tools' APIs, so threats that arrive outside the inbox are caught by the same policies and remediation.
Checks outbound messages before they are sent for recipients who do not match the sender's normal communication pattern, wrong or lookalike addresses, and attachments that do not belong with the message, and warns or blocks the sender, so accidental data exposure by misaddressed email is stopped at the point of sending.
Presents one quarantine and release workflow across the vendor's own detections and the cloud email provider's native filtering, so administrators and end users do not manage two split quarantines when an API-based product is layered on Microsoft Defender for Office 365 or Google Workspace.
Detects and suppresses subscription-bombing and mail-flood attacks, in which an inbox is deliberately buried under thousands of newsletter confirmations or spam to hide a fraudulent message or account-takeover alert, and restores normal delivery for the targeted user.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
Start a shortlist with Darktrace / EMAIL
Compare options, add your notes, and run informed evaluations.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.