Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Look for clarity on deployment-model tradeoffs — API-based tools see mailbox-native signals but may act post-delivery, while a SEG blocks pre-delivery but requires MX changes.
BEC/VEC often has no malicious link or attachment, so detection relies on behavioral/relationship analysis — strong answers explain that mechanism specifically, not generic 'AI detection.'
Look for outbound/internal anomaly detection (unusual sending behavior, forwarding-rule abuse) as a distinct capability from inbound filtering.
Strong answers give a measured false-positive rate and a scoped release mechanism, not an all-or-nothing allowlist that weakens protection.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Look for a stated latency figure and confirmation of time-of-click re-scanning — a link benign at delivery but weaponized later is a common evasion.
This is a newer, fast-growing evasion technique — a vendor with no answer likely hasn't kept pace with current threats.
Strong answers describe closed-loop automated response, not just detection-and-alert requiring manual follow-up.
Look for guided DMARC policy progression (monitor → quarantine → reject) with visibility into legitimate senders that would break, not just raw report parsing.
Automatic, policy-driven encryption based on content inspection is materially stronger than a manual opt-in the sender can simply forget to use.
Look for a genuine retroactive, organization-wide search capability with a stated retention window; a platform that can only act on mail going forward from detection is materially weaker for incident response.
Proactive vendor-domain risk monitoring is a more advanced capability than purely reactive inbound filtering — ask for a concrete example of a caught vendor-compromise incident.
Strong answers give transparent per-tier economics and are explicit about which protections (e.g., BEC detection) are gated behind a premium tier rather than included in the base product.
A real coverage gap on mobile (a common attack surface given time-pressured, distracted reading on phones) should be disclosed explicitly, not glossed over.
Strong answers cite a concrete, named IR capability and timeline, not a generic 'we have support' answer — email-borne fraud incidents often need fast, specialized response.
Look for genuine regional processing options; a vendor scanning all customer email content in a single fixed region regardless of customer location is a real compliance gap for many regulated buyers.
Real-time integration between actual caught threats and targeted training is materially more effective than disconnected simulated-only phishing training.