TLDR: Email security solutions describe at least five different product categories that solve different problems: secure email gateways, API-based filtering, email authentication, encryption and data loss prevention, and security awareness training. Most buyers evaluate one category, buy it, and assume email is handled. This leaves gaps and vulnerabilities for attackers to exploit.
Two vendors can both call themselves email security solutions and have almost no functional overlap.
One inspects inbound messages for malicious links and attachments. The other stops attackers from sending mail that appears to come from your domain. Both are legitimate and necessary, but neither does the other’s job. And a buyer who evaluates them against the same checklist is going to end up with a stack that has a hole in it somewhere.
That’s the core problem with buying email security. The category label covers several distinct product types, vendor marketing tends to blur the distinctions, and the gaps only show up after something gets through.
This guide breaks the email security solutions into their proper layers, lays out an evaluation framework, and covers the questions you should be asking before signing anything.
What email security solutions typically cover
Email security is a category label, not a standalone product. Underneath it sits five layers, each addressing a different part of the threat model.
| Layer | Protects against | Direction |
| Secure email gateway (SEG) | Malicious links, attachments, malware, spam | Inbound |
| API-based / integrated cloud email security (ICES) | Social engineering, BEC, account anomalies | Inbound, post-delivery |
| Email authentication (SPF, DKIM, DMARC) | Domain spoofing, exact-domain impersonation | Outbound |
| Encryption and DLP | Interception, accidental data exposure | Outbound |
| Security awareness training | Human error and manipulation | The user |
Most organizations deploy strong inbound filtering, then leave the outbound side of the equation unaddressed. Sure, their inbox is well defended, but their domain is wide open for anyone who wants to impersonate it against customers and partners.
The five categories of email security solutions
1. Secure email gateways
A secure email gateway sits in front of your mail server and inspects inbound messages before delivery, filtering spam, malware, malicious URLs, and known-bad attachments. Gateways are mature, well understood, and remain a foundational layer for most organizations.
Their strength is volume and breadth. A SEG handles the enormous quantity of commodity threats so nothing else has to. Their limitation is that they work by evaluating content and reputation, which means a well-crafted message containing no malicious payload can pass through (which is what we’re seeing with many AI phishing attacks).
That describes most modern business email compromise.
Providers include: Proofpoint, Mimecast, Cisco, Barracuda.
2. API-based and integrated cloud email security
ICES platforms connect to Microsoft 365 or Google Workspace through APIs rather than sitting inline, analyzing message content, sender behavior, and relationship history to catch what gateways miss. They can also remediate post-delivery by pulling a message out of inboxes after it’s already landed.
This category exists to address the gap SEGs leave: socially engineered attacks with no malicious payload. Behavioral analysis catches strange actions in a way content scanning can’t.
Providers include: Abnormal, IRONSCALES, Sublime Security, Check Point.
3. Email authentication
Authentication protocols verify that mail claiming to come from your domain is genuinely authorized:
- SPF lists permitted sending IPs
- DKIM applies a cryptographic signature
- DMARC ties both to the visible From address and tells receiving servers what to do when they fail
This is the outbound layer, and it’s the one most commonly missing. Authentication doesn’t inspect anything arriving in your inbox. Instead, it stops attackers from using your domain against other people, and it’s the only layer that addresses exact-domain impersonation at all.
Learn more about Valimail and other top DMARC providers.
4. Encryption and data loss prevention
Encryption protects message contents in transit and at rest. DLP scans outbound mail for sensitive data and blocks or quarantines it before it leaves. These often ship together and are typically driven by compliance requirements rather than threat prevention.
Relevant standards include TLS for transport, S/MIME and Microsoft Purview for message-level encryption, and MTA-STS for enforcing encrypted transport between mail servers.
5. Security awareness training
Simulated phishing and user education, aimed at the human layer. Yes, it’s still worth doing, but its effectiveness is declining as AI-generated phishing removes the grammar and formatting errors that training taught people to spot. Programs that emphasize verifying unusual requests hold up better than ones teaching people to recognize suspicious writing.
How to evaluate email security solutions
Once you know which layer you’re buying, these are the criteria to narrow down your email security options:
- Threat coverage against your risks. Map the solution’s coverage to the threats your organization realistically faces. A company with heavy vendor payment activity needs BEC and invoice fraud coverage more than commodity spam filtering. Ask vendors to demonstrate against your scenarios.
- Deployment model and disruption. Inline gateways require MX record changes and can introduce a failure point. API-based tools deploy in hours with no mail flow changes. Authentication requires DNS work and (depending on the vendor) ongoing DNS maintenance. Each carries a different implementation cost in staff time.
- Detection accuracy in both directions. False negatives let threats through. False positives bury legitimate mail and train users to check their quarantine…which erodes the whole control. Ask for both figures. A vendor that just discusses catch rate is only telling you half the story.
- Time to value. How long from contract to protection? Some solutions protect on day one. Others require weeks of tuning, or months of monitoring before enforcement is safe to enable. Long ramp periods are a real cost, and they’re where a lot of deployments stall permanently. For example, if you’re investing in DMARC, Valimail gets you to enforcement (actual protection) 4x faster than any other platform.
- Administrative overhead. How much ongoing work does this create? A solution requiring a half-time analyst to manage costs far more than its license. Ask what routine maintenance looks like at your scale in hours per week.
- Integration with your existing stack. SIEM, SOAR, ticketing, identity provider. A solution that can’t feed your existing workflows becomes an island your team stops checking.
- Reporting for the audiences that need it. Security teams need technical detail. Leadership needs posture summaries. Auditors need evidence. Solutions vary in whether they serve all three.
- Scaling economics. Understand what drives price: users, domains, message volume, or sending services. Then model it at double your current size. Pricing that’s reasonable now can become punitive as you grow.
Questions to ask every email security vendor
- What specific threats does this catch that our current stack doesn’t?
- What are your false positive and false negative rates, and how are they measured?
- How long does a typical deployment take at our size, and what does our team have to do?
- What ongoing administrative work does this require each week?
- What happens to mail flow if your service goes down?
- What drives the price, and what does it look like at twice our scale?
- Which of the email security layers does this cover, and which does it leave to others?
That last question is the one that surfaces gaps fastest. A vendor with a clear answer understands where they fit. A vendor who claims to cover everything is worth a second look.
Where email security buyers go wrong
The most expensive mistake is treating email security as a single purchase. An organization buys a well-regarded gateway, checks the box, and never addresses the outbound side. Their domain stays spoofable for years while their inbound filtering gets steadily better. The attack that eventually lands doesn’t come through their inbox at all—no, it goes to a customer, from a domain that looks exactly like theirs.
The second mistake is buying overlapping capability. Gateways, ICES platforms, and native Microsoft 365 or Google Workspace protection all overlap meaningfully. Layering three tools that catch the same commodity threats while leaving authentication unaddressed is a common and costly pattern.
The third is over-indexing on detection rates. Catch rate is easy to market and difficult to verify independently. Administrative burden, false positive rate, and time to value have more effect on whether a deployment succeeds, and vendors discuss them far less.
The fourth is assuming training covers the human layer. It helps, but it has never been sufficient, and the margin is narrowing as attack content improves.
Where authentication fits into your security stack
Gateways and ICES platforms answer whether a message is dangerous or not. They do it well, and every organization needs that capability. Valimail partners with leading SEG providers for exactly this reason: Inbound content analysis catches threats that authentication has no visibility into.
Authentication answers a different question, though: Can this sender prove they’re allowed to use this domain?
It’s a cryptographic check rather than an assessment of content, which means it holds up regardless of how convincing a message is. That property matters more as generative AI makes convincing content easy to produce.
The two are complementary, and neither substitutes for the other.
- A gateway can’t stop someone spoofing your domain in mail sent to your customers, since that mail never touches your infrastructure.
- Authentication can’t tell you whether an inbound attachment is malicious.
An email security stack needs both, and the outbound layer is the one more often missing.
Get email protection sooner rather than later
Before evaluating vendors, get a baseline. Most organizations don’t have a current picture of who’s sending email using their domain, and that inventory shapes which layers need investment.
Valimail Monitor is free and identifies every service sending as your domain, by name. Check your domain for your current authentication status.
With that baseline, map your existing coverage against the five layers above. The gaps usually make the buying decision obvious.
Frequently asked questions
What are email security solutions?
Email security solutions are products that protect email against threats, spanning five distinct categories: secure email gateways that filter inbound messages, API-based platforms that detect social engineering and BEC, email authentication protocols that prevent domain spoofing, encryption and DLP for protecting message contents, and security awareness training for the human layer.
What’s the difference between a secure email gateway and email authentication?
A secure email gateway inspects inbound mail for malicious content and blocks it before delivery, protecting your users. Email authentication verifies that outbound mail claiming to come from your domain is genuinely authorized. They address opposite directions of the threat and work together rather than substituting for one another.
How much do email security solutions cost?
Pricing varies by layer and model. Gateways and API-based platforms typically price per user per month. Authentication platforms usually price per domain or by sending complexity. Encryption and DLP are often bundled with productivity or compliance suites. Model total cost at twice your current size, since scaling economics differ substantially between vendors.