- Guardz
- Ironscales
- Avanan (Check Point Harmony Email)
- Proofpoint Essentials
- Mimecast for MSP
- Abnormal Security
- Material Security
- Vade for M365 (Hornetsecurity)
- Barracuda Email Protection
- Graphus (Kaseya)
- Hornetsecurity 365 Total Protection
- Email Security Platform Comparison: Key Features at a Glance
- How to Choose: A Decision Framework
- Problems & Solutions
- The Bottom Line for MSP Email Security in 2026
Most teams discover email security gaps during a client incident review, not from a stack diagram. We are Guardz, and this is our read on the MSP email security market, shaped by what we see working alongside the providers we partner with: phishing kits that slip past default filters, OAuth abuse in Google Workspace tenants, and mailbox-rule exfiltration through the Graph API. We rank our own platform here, so weigh that as you read, and judge each tool against the criteria below rather than the order.
Three technical patterns decide outcomes for MSPs: API-level inspection inside Microsoft 365 and Google Workspace, behavioral analysis for BEC and vendor fraud, and fast cross-tenant remediation. Get those right and most other decisions fall into place.
A reality check on the stakes. Business email compromise losses reached $2.77 billion in 2024 according to the FBI’s IC3 annual report, while overall internet crime losses hit a record $16.6 billion, a 33 percent rise year over year. Those figures track with the latest breach research on rapid social engineering and rising third-party risk.
This guide explains when to choose API-native versus gateway models, which tools excel in Google Workspace, and how to design cross-tenant playbooks that cut response time. The picks below weigh efficacy, MSP tooling, and pricing signals.
Email Security Tools Comparison: Quick Overview
| Tool | Best For | Pricing Model | Highlights |
|---|---|---|---|
| Guardz | Unified MSP console with MDR plus API email protection | Quote based | Check Point Harmony Email engine integrated, plus EDR and ITDR in one pane |
| Ironscales | API email security with built-in training | Quote based | Fast API deployment with integrated training and DMARC |
| Check Point Harmony Email | Pre- and post-delivery detection with marketplace routes | Channel or marketplace | API-inline model, internal scanning, broad ecosystem |
| Proofpoint Essentials | SMB and MSP bundles with continuity and archiving | Channel quote | Mature stack and MSP program, post-acquisition roadmap evolving |
| Mimecast | Email security plus archiving and continuity | Quote based | Large install base, gateway or API options |
| Abnormal Security | Advanced BEC detection for higher-risk clients | Enterprise quote | Behavioral AI with strong BEC outcomes in reviews |
| Material Security | In-tenant protection for M365 and Google Workspace | Quote based | Account takeover and inbox data controls, strong Google support |
| Vade for M365 (Hornetsecurity) | API-native M365 email security, MSP channel-first | Quote based via distributors | No MX changes, multi-tenant partner portal, built-in training |
| Barracuda Email Protection | Recognized brand with gateway plus API options | Quote based via MSP program | Inbox defense, impersonation protection, bundled backup and archiving |
| Graphus (Kaseya) | Kaseya-aligned MSPs wanting automated protection | Per-mailbox subscription | TrustGraph BEC detection across M365 and Google Workspace |
| Hornetsecurity 365 Total Protection | Partner-first M365 suite, strong in Europe | Quote based via partner program | Email security, backup, archiving, and training in one suite (now Proofpoint) |
Guardz
Guardz is an agentic cybersecurity platform for MSPs that centralizes email protection, endpoint security, identity threat detection, and managed detection and response in one console. Recent updates embed Check Point’s API-based Harmony Email engine, formerly Avanan, to strengthen pre- and post-delivery coverage inside Microsoft 365 and Google Workspace.
Best for: MSPs that want a unified console with MDR and cross-tool signal correlation, and that prefer API-level email protection without managing MX changes.
Key features:
- API email protection with behavioral detection for phishing and BEC
- Multi-tenant MSP workflow and reporting across clients
- Endpoint security integrations, including SentinelOne EDR
- Identity threat detection and automated user risk workflows
Why we like it: Consolidating EDR, email, identity, and MDR in one MSP console reduces tool sprawl and speeds incident triage. The native Check Point integration aligns email detections with device and identity signals, which is valuable during BEC or account-takeover investigations, and the embedded engine reports a 99.7 percent phishing block rate.
Notable limitations:
- Some reviewers cite fewer granular admin and SOAR customizations than dedicated point tools, so MSPs with heavy custom-automation needs should test those workflows in a pilot.
- Best-in-class detection in any single layer, such as email or endpoint, will track the underlying engines, so MSPs that want the deepest standalone capability in one vector may still benchmark Guardz against a dedicated point tool. The platform’s differentiation is the unified data model and the correlation across email, identity, and endpoint, not any one engine in isolation.
Pricing: Not publicly listed. Contact Guardz for a custom quote. Public review hubs list plans but no authoritative list pricing.
Ironscales
Ironscales is API-based behavioral email security with integrated phishing simulation and training. It deploys inside Microsoft 365 or Google Workspace without MX changes and adds mailbox-level detection with automated remediation.
Best for: MSPs standardizing on API-native protection with built-in training, reporting, and DMARC support across tenants.
Key features:
- Mailbox-level detection, autonomous remediation, and abuse-report handling
- Integrated phishing simulation and security awareness training
- No MX change required, with rapid API deployment in Microsoft 365 and Google Workspace
- Analyst-assist and case management that reduce manual workload
Why we like it: A strong fit for MSPs that want one platform for detection, response, and human risk reduction without maintaining a separate training tool. These strengths appear repeatedly in recent user reviews.
Notable limitations:
- Some users report missed feature promises and support variability during complex rollouts.
- Market presence in large-enterprise shortlists can trail bigger brands, so MSPs serving very large clients may still face buyer familiarity hurdles.
Pricing: Not publicly listed. Contact Ironscales for a custom quote, as public listings typically require an inquiry.
Avanan (Check Point Harmony Email)
Avanan, now Check Point Harmony Email, is cloud-native email security that connects through an API to protect Microsoft 365 and Google Workspace. It is often described as inline, API-based protection with both pre- and post-delivery controls.
Best for: MSPs that want robust pre-delivery scanning plus post-delivery remediation, and teams already standardizing on Check Point’s broader security stack.
Key features:
- API-based detection that blocks advanced phishing, BEC, and malware before inbox delivery
- Internal, inbound, and outbound scanning with URL and attachment analysis
- Automated remediation and tenant-wide message pull
- Procurement through marketplaces and distributors
Why we like it: Strong efficacy against business email compromise and impersonation, plus practical remediation features. Independent peer platforms continue to provide current buyer sentiment and comparisons.
Notable limitations:
- Some feedback mentions occasional message delays or portal performance during heavy analytics, which MSPs should test in a pilot.
- Support experiences can vary by route to market and distributor.
Pricing: Varies by channel and marketplace. Check availability and terms through marketplaces or government price lists for related Harmony SKUs.
Proofpoint Essentials
Proofpoint Essentials is multi-tenant email defense for MSPs that combines spam and phishing protection with BEC controls, encryption, continuity, and optional training. It now sits inside Proofpoint’s expanded MSP strategy following the $1.8 billion Hornetsecurity acquisition that closed in December 2025.
Best for: MSPs that want a mature SMB offering with archiving and continuity, and that prefer established channel programs.
Key features:
- URL and attachment defense, sandboxing, and impersonation protection
- Multi-tenant MSP administration, continuity with an emergency inbox, and optional archiving
- Add-on training and reporting for end users
Why we like it: A long-standing MSP footprint and bundled continuity features. Moves through 2025 and into 2026 are expanding the MSP focus and platform options, now reinforced by the Hornetsecurity acquisition (covered as its own entry below).
Notable limitations:
- Product and pricing motion are still in transition after the acquisition, so MSPs should validate the roadmap and migration paths.
- Buyer reviews sometimes cite cost sensitivity versus API-only competitors and an aging UI in parts of the stack.
Pricing: Not publicly listed. Historic public list prices for legacy tiers do not represent 2026 quotes, so verify with channel partners.
Mimecast for MSP
Mimecast is cloud email and collaboration security with archiving and continuity, plus MSP partner tooling. It offers both gateway and API-based deployment options depending on the plan.
Best for: MSPs that want email security plus archiving and continuity under one brand, and that still prefer or require a secure email gateway model.
Key features:
- Spam and phishing defense with URL and attachment analysis
- Archiving, e-discovery, and continuity capabilities
- An MSP program with multi-tenant administration options
Why we like it: Coverage that reaches beyond inbound filtering can simplify the vendor count for MSPs that bundle email security with archiving. Independent review hubs continue to document large, real-world deployments.
Notable limitations:
- Gateway change management can add complexity in Microsoft 365 and Google Workspace compared with API-native platforms.
- Support and UI feedback vary by account and region.
Pricing: Not publicly listed. Contact Mimecast for a custom quote.
Abnormal Security
Abnormal Security is a behavioral AI platform for Microsoft 365 and Google Workspace that profiles user and vendor relationships to stop BEC, phishing, and impersonation, with post-delivery remediation.
Best for: MSPs serving security-sensitive mid-market and enterprise clients that need advanced BEC protection and can justify premium pricing.
Key features:
- Behavioral baselining of users and vendors to detect subtle anomalies
- Post-delivery detection with rapid message pull and investigation context
- Account-takeover detection, VIP protection, and integrated remediation
Why we like it: Consistently strong feedback on BEC efficacy and analyst experience in verified reviews.
Notable limitations:
- Premium pricing is a common concern, and post-delivery analysis means users may briefly see a malicious email before it is removed.
- Minimum contract values can apply for smaller deployments.
Pricing: Not publicly listed. Negotiated enterprise quotes are typical, and marketplaces note minimums and deal ranges.
Material Security
Material Security is API-deployed email and workspace protection focused on account takeover, sensitive data exposure, and configuration drift in Microsoft 365 and Google Workspace.
Best for: MSPs standardizing on Google Workspace or mixed estates that need in-tenant controls, mailbox data protections, and rapid deployment.
Key features:
- In-tenant API protection for Microsoft 365 and Google Workspace
- Account-takeover detection and sensitive-message controls with MFA
- Automated clustering and remediation of similar malicious emails across tenants
Why we like it: The focus on protecting stored inbox data and identity context complements native Microsoft 365 and Google filters, and analyst reviews note fast deployment and strong Google Workspace support.
Notable limitations:
- Works best alongside a pre-delivery filter to keep commodity spam low.
- Pricing is quote-only and less transparent in public sources.
Pricing: Not publicly listed. Request a quote from the vendor.
Vade for M365 (Hornetsecurity)
Vade for M365 is API-based, AI-driven email security built for the MSP channel. It integrates with Microsoft 365 via API with no MX changes and adds detection, automated response, and behavior-triggered phishing awareness training, all managed from a multi-tenant partner portal.
Best for: MSPs that want a low-touch, channel-first API layer over Microsoft 365 with cross-tenant incident response and built-in user training.
Key features:
- API-based detection of phishing, spear phishing, ransomware, and malware with no MX changes
- Multi-tenant partner portal with cross-tenant remediation and user-reported email handling
- Automated phishing awareness training triggered by user behavior
- AI engine trained across a large alliance of protected mailboxes and daily user reports
Why we like it: A purpose-built MSP model with fast onboarding and a partner portal that centralizes tenants, which keeps admin time per client low.
Notable limitations:
- Coverage is centered on Microsoft 365 rather than mixed Google Workspace estates
- Deeper investigation tooling sits behind paid add-ons
Pricing: Not publicly listed. Available through distributors and the Vade partner program; contact Vade or a distributor for a quote.
Barracuda Email Protection
Barracuda Email Protection combines a secure email gateway with API-based inbox defense and impersonation protection for Microsoft 365, backed by a long-running MSP program and multi-tenant management.
Best for: MSPs that want a recognized email brand with both gateway and API options, plus bundled backup and archiving through the Barracuda MSP program.
Key features:
- Gateway filtering plus API-based inbox defense and impersonation protection for Microsoft 365
- Account-takeover detection and post-delivery remediation
- Multi-tenant MSP management with optional bundled backup and archiving
- Security awareness training available within the broader suite
Why we like it: A mature, widely deployed platform with a deep MSP channel and a broad suite that can consolidate email, backup, and training under one vendor.
Notable limitations:
- Gateway components can add routing and change-management overhead versus pure API tools
- Suite breadth means feature depth and UI vary across modules
Pricing: Not publicly listed for MSP tiers. Available through the Barracuda MSP program and distributors; contact for a quote.
Graphus (Kaseya)
Graphus, part of Kaseya, is an API-based, automated email security platform for Microsoft 365 and Google Workspace aimed at SMBs and the MSPs that serve them. Its patented TrustGraph models communication patterns to flag anomalous messages.
Best for: MSPs already in the Kaseya ecosystem that want low-touch, AI-driven phishing and BEC protection priced per mailbox.
Key features:
- API deployment for Microsoft 365 and Google Workspace with no MX changes
- TrustGraph relationship modeling to detect impersonation and BEC
- EmployeeShield warning banners that flag suspicious mail to end users
- Multi-tenant management and integration with the wider Kaseya platform
Why we like it: Simple, automated deployment and per-mailbox pricing make it an easy add-on for MSPs standardizing on Kaseya tooling.
Notable limitations:
- Detection depth and reporting are lighter than enterprise-grade behavioral platforms
- Strongest fit for MSPs already invested in the Kaseya ecosystem
Pricing: Subscription, priced per mailbox. Contact Graphus or Kaseya for current MSP pricing.
Hornetsecurity 365 Total Protection
Hornetsecurity 365 Total Protection is an MSP-focused suite for Microsoft 365 that bundles email security, archiving, encryption, backup, and awareness training. Proofpoint completed its $1.8 billion acquisition of Hornetsecurity in December 2025, and it now operates as a dedicated MSP business unit.
Best for: MSPs, especially in Europe, that want a partner-first Microsoft 365 suite consolidating email security, backup, and compliance under one contract.
Key features:
- Multi-layer email filtering with sandboxing and high published spam and virus catch rates
- Email encryption, archiving, and continuity for Microsoft 365
- Multi-tenant partner portal with tiered margins and co-branded materials
- Optional backup and security awareness training within the same suite
Why we like it: A deep, partner-friendly MSP program with broad suite coverage and a large European install base, now backed by Proofpoint threat research.
Notable limitations:
- Centered on Microsoft 365 rather than Google Workspace
- Product and roadmap are in transition as Proofpoint integration proceeds
Pricing: Not publicly listed. Available through the Hornetsecurity partner program and distributors; contact for a quote.
Email Security Platform Comparison: Key Features at a Glance
| Tool | API Deployment | Internal Mail Scanning | Built-in Training |
|---|---|---|---|
| Guardz | Yes | Via Check Point engine | Yes (awareness) |
| Ironscales | Yes | Yes | Yes |
| Check Point Harmony Email | Yes | Yes | No |
| Proofpoint Essentials | Yes or gateway | Varies by package | Optional add-on |
| Mimecast | Gateway or API | Gateway scope | Optional add-on |
| Abnormal Security | Yes | Yes | No |
| Material Security | Yes | Yes | No |
| Vade for M365 (Hornetsecurity) | Yes | Yes | Yes (awareness) |
| Barracuda Email Protection | Gateway or API | Via API inbox defense | Optional add-on |
| Graphus (Kaseya) | Yes | Yes | Banners, not full SAT |
| Hornetsecurity 365 Total Protection | API or gateway | Yes | Optional add-on |
How to Choose: A Decision Framework
Start with the deployment model. API tools inspect post-delivery context and simplify rollout in Microsoft 365 or Google Workspace, while gateways add routing changes. Pilot both in a lab, comparing latency, detection on internal mail, and the quarantine experience, and treat MX changes that risk outages or a lack of internal scanning as red flags.
Check Google Workspace parity. Many stacks lean toward Microsoft 365, but Workspace needs first-class support. Verify API scopes, internal scanning, and OAuth controls, and be cautious where directory sync for Google looks weak. For cross-tenant operations, efficient bulk policy and message pull reduce the cost to serve, so favor multi-tenant dashboards with global search and remediation over tools that force per-tenant pivots or manual exports.
Weigh BEC and vendor fraud efficacy, since the FBI flags BEC as the largest loss driver. Prioritize behavioral detection, vendor mapping, and VIP protection over signature-only approaches. Finally, scrutinize pricing transparency, because MSP margins depend on predictable seat economics; watch for high minimums on small tenants and undisclosed add-ons.
On sizing, smaller shops of roughly 10 to 250 users often pair an API-native email layer plus training, such as Ironscales, or consolidate on a unified stack like Guardz. Mid-market estates of 250 to 1,500 users may lead with behavioral BEC defense from Abnormal or Check Point Harmony Email with internal scanning and message pull. Larger or regulated organizations of 1,500 users and up typically layer an API platform over native Microsoft 365 and Google controls and add archiving and continuity from Mimecast or Proofpoint. Pricing across all tiers remains quote-only.
Problems & Solutions
- Problem: Vendor invoice fraud reaches finance inboxes despite basic filters. BEC drives the highest financial losses, with $2.77 billion in adjusted losses reported in 2024.
Solution: Abnormal Security baselines user and vendor behavior to flag anomalous requests and remove messages post-delivery, Check Point Harmony Email blocks before inbox delivery and can pull messages across tenants, and Material Security protects sensitive inbox data while enforcing MFA on high-value content even when credentials are stolen. - Problem: Internal phishing and lateral movement stay invisible to perimeter filters.
Solution: IRONSCALES adds mailbox-level detection and internal scanning with automated remediation, Material Security runs in-tenant scanning and remediation across tenants with clustering of similar threats, and Guardz links email detections to endpoint and identity telemetry to speed cross-tool response. - Problem: Google Workspace tenants get second-class support in some ecosystems.
Solution: Material Security and IRONSCALES both deploy via API inside Google and Microsoft 365 with strong reviewer feedback, and Check Point Harmony Email supports API-based protection for both, including internal and outbound scanning. - Problem: Proving ROI and reducing dwell time across many small tenants is hard.
Solution: API-native tools enable message pull and bulk policy across tenants, cutting mean time to remediate, a pattern that aligns with breach research highlighting rapid social engineering and growing third-party risk.
The Bottom Line for MSP Email Security in 2026
Start with the deployment model. If you run Microsoft 365 or Google Workspace, API-native inspection with strong behavioral detection should be your baseline, while gateways with archiving and continuity, such as Mimecast or Proofpoint Essentials, stay relevant when continuity or compliance drives the decision.
Among the API options, Ironscales and Material Security pair cleanly with native controls, Abnormal Security shines for higher-risk clients that can absorb premium pricing, and Check Point Harmony Email is a strong inline choice when you want pre-delivery depth and marketplace routes.
For MSPs weighing margin alongside protection, though, the most complete answer is usually a consolidated one. A fair question follows: if the detection engine is Check Point Harmony Email, why not license Harmony directly and skip the platform layer? The answer is what surrounds the engine. Bought standalone, Harmony gives you email detection and one more console to staff and bill; Guardz puts that same inline detection next to endpoint, identity, and MDR in a single multi-tenant pane, with one contract, one onboarding flow, and one place to work an incident when a malicious email, a risky sign-in, and an endpoint event turn out to be the same attack.
The aim is to correlate those signals automatically rather than leave an analyst stitching them across tools, and that cross-signal email correlation is still deepening as the engine integration matures. For an MSP, the value is less the engine than the consolidation around it: fewer consoles to learn, fewer vendors to manage, and seat economics that stay predictable, which is where MSP profitability is won or lost.
Whatever the shortlist, BEC remains the budget-setter, so test for vendor fraud efficacy and cross-tenant remediation speed first, then weigh how much each platform simplifies the daily operations behind your margins.