Proofpoint vs Abnormal vs Mimecast: 9x Customer Gap [2026]

Business email compromise cost victims $2.77 billion in reported losses in 2024 alone, according to the FBI’s Internet Crime Complaint Center, and the bureau’s cumulative tally for BEC scams between October 2013 and December 2023 now stands at $55.5 billion worldwide. Legacy spam filters were built for a different era of attacks. Today’s threats rarely carry a malicious attachment or a broken link — they arrive as a perfectly worded invoice request from a “vendor” or an urgent, executive-styled request from the “CEO,” and no static rule engine catches that. That gap is why three platforms keep showing up at the top of enterprise shortlists in September 2026: Proofpoint, Abnormal Security, and Mimecast.

All three were named Leaders in Gartner’s Magic Quadrant for Email Security Platforms, but they solve the problem in fundamentally different ways, at fundamentally different prices, and with fundamentally different ownership structures behind them. Proofpoint is a $12.3 billion Thoma Bravo asset reportedly shopping for its next acquisition. Abnormal Security is an AI-native challenger sitting on a $5.1 billion valuation and eyeing an IPO. Mimecast is a Permira-owned incumbent that still protects more organizations than the other two combined. This comparison breaks down the architecture, pricing, benchmarks, and real deployment scenarios for each, so buyers can pick based on data rather than a sales deck.

Google · Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

Why Email Security Decisions Got Harder in 2026

Email remains the number one entry point for attackers, and the FBI’s own numbers show why security teams are under pressure to modernize. In the 2024 Internet Crime Report, business email compromise ranked as the second-costliest crime category the bureau tracks, with 21,442 complaints and $2.77 billion in losses — out of $16.6 billion in total reported cybercrime losses that year, according to Abnormal AI’s breakdown of the FBI IC3 report. A year earlier, in 2023, the FBI logged 21,489 BEC complaints worth $2.9 billion. The cumulative exposure is staggering: the FBI’s own public service announcement puts domestic and international BEC losses at $55.5 billion between October 2013 and December 2023, with $20.09 billion of that hitting U.S. victims specifically, per the FBI IC3 “Business Email Compromise: The $55 Billion Scam” advisory.

What changed the calculus for buyers in 2026 isn’t just the dollar figure, it’s the attack style. Traditional secure email gateways (SEGs) were designed to catch known-bad senders, malicious URLs, and infected attachments. Modern BEC and vendor email compromise (VEC) attacks frequently carry no payload at all — just a convincingly worded request sent from a compromised or spoofed mailbox that has never appeared on a blocklist. That’s the exact gap that pushed Gartner to create an entirely new category, the Magic Quadrant for Email Security Platforms, which folded in AI-native, API-based vendors like Abnormal alongside legacy gateway players like Proofpoint and Mimecast for the first time in 2024. The market itself is expanding fast to match the threat: Market Research Future estimates the global email security market at $6.83 billion in 2025, growing to $23.37 billion by 2035 at a compound annual growth rate of 13.08%, according to its Email Security Market report. A separate analysis from Market.us puts the 2025 figure at $6.36 billion, climbing to $27.58 billion by 2035 at a 15.8% CAGR, per its Global Email Security Market report. The vendor field is crowding to match that growth: the Cyber Vendor Guide counted 19 distinct email security tools on the market as of February 2026, including the Abnormal AI platform, and Bitdefender entered the fray in April 2026 with GravityZone Extended Email Security, built on its 2025 Mesh acquisition to unify two previously separate protection layers into one. Investor money is still chasing that growth too — a Security, Funded brief logged $5.8 million invested into email security across a single deal in the week ending September 11, 2026, a reminder that Proofpoint, Abnormal, and Mimecast aren’t competing in a static category but one that keeps attracting new entrants and fresh capital.

Proofpoint, Abnormal Security, and Mimecast at a Glance

Before diving into architecture and pricing, here’s how the three platforms stack up on the metrics that matter most to a buying committee: scale, ownership, detection philosophy, and analyst recognition. Worth noting: the broader secure-mail-server market hasn’t stood still either — Xeams shipped version 10.2 (Build 6432) on May 18, 2026, following version 10.0 in January 2026, itself an iteration on version 9.8 from July 2025 and version 9.6 from February 2025, a steady release cadence that underscores how competitive and fast-moving email security tooling has become even outside the Proofpoint-Abnormal-Mimecast tier.

AttributeProofpointAbnormal SecurityMimecast
Founded2002 (Sunnyvale, CA)2018 (San Francisco, CA)2003 (London / Lexington, MA)
Core architectureSecure email gateway (SEG) + Targeted Attack ProtectionAPI-based, integrated cloud email security (ICES), behavioral AISecure email gateway + human risk management suite
Detection philosophyThreat intelligence, sandboxing, URL/attachment rewritingBehavioral baselining of identity and relationship graphsSignature and reputation filtering plus archiving/continuity
OwnershipThoma Bravo (private, since 2021)Venture-backed; Series D led by Wellington ManagementPermira (private, since 2022)
Organizations protected2.7 million+ organizations claimed; ~10,000 large enterprises; ~14,000 core enterprise accounts per credit-rating filings4,500+ organizations, including over 25% of the Fortune 50042,000+ organizations
End users protectedNot separately disclosedNot separately disclosed27 million end users
2024 Gartner MQ status (inaugural)LeaderLeaderLeader
2025 Gartner MQ statusLeader (2nd consecutive year)LeaderLeader
Pricing modelQuote-based, per user license and contract termQuote-based, per mailbox/employee per yearQuote-based, tiered by organization size
Deployment styleGateway (MX record change) or API mode via Proofpoint PrimeAPI-only, no MX record change requiredGateway (MX record change)
Notable 2026 moveReportedly in talks to acquire Varonis Systems; acquired Hornetsecurity for European reachRaised $250M Series D at $5.1B valuation; CEO has flagged IPO ambitionsContinues expanding Human Risk Management platform under Permira ownership
Best known forDepth of threat intelligence in high-volume, threat-heavy environmentsCatching payloadless BEC, VEC, and account takeover that gateways missOperational simplicity, archiving, and lower total cost of ownership

Two numbers jump out immediately. Mimecast’s 42,000-plus protected organizations dwarf Abnormal’s 4,500, a roughly 9x gap in customer count that reflects Mimecast’s two-decade head start as a gateway and archiving vendor versus Abnormal’s newer, higher-touch enterprise focus. Meanwhile Proofpoint claims the broadest total reach at 2.7 million organizations worldwide, though Fitch Ratings’ credit analysis narrows that to roughly 14,000 core enterprise customers when you strip out the long tail of smaller accounts, according to Proofpoint’s own Gartner Magic Quadrant announcement.

How Proofpoint Detects Phishing and BEC

Proofpoint built its reputation as a secure email gateway vendor, and that heritage still shows in how the platform is architected. Mail typically routes through Proofpoint’s infrastructure via an MX record change, where it passes through layers of reputation filtering, sandboxing (detonating attachments and links in an isolated environment), and its Targeted Attack Protection (TAP) module, which specifically hunts for spear-phishing and credential-harvesting links. Proofpoint markets itself as a “human-centric security” company, meaning its detection stack tries to correlate who inside an organization is most likely to be targeted (its Very Attacked People, or VAP, scoring) with what kind of attack they’re facing, rather than treating every mailbox as an equal-risk target.

The company has also been pushing toward an API-based deployment model called Proofpoint Prime, which layers additional AI-driven detection on top of (or instead of) the traditional gateway, partly in response to competitive pressure from API-native challengers like Abnormal. Proofpoint’s own newsroom states the company is “trusted by more than 2.7 million organizations worldwide” and claims its platform “blocks 99.99% of all email attacks,” a vendor-reported figure rather than an independently audited benchmark, according to its 2025 Gartner Magic Quadrant Leader announcement. For security teams that already run a heavy stack of Proofpoint products — data loss prevention, insider threat management, security awareness training — the email security module plugs into a single console and a single vendor relationship, which is a meaningful operational advantage at large enterprises with dozens of point tools to manage. Buyers evaluating that awareness-training layer specifically should also look at how Proofpoint’s own training product stacks up against dedicated players, a question we cover in KnowBe4 vs Proofpoint vs Hoxhunt.

The tradeoff is complexity. Proofpoint’s rule-based and sandbox-driven detection requires meaningful tuning to avoid false positives, and organizations moving off a legacy SEG often report a multi-week runway to get filtering policies dialed in correctly. Proofpoint’s recent moves — reported talks to acquire Varonis Systems and its completed purchase of Hornetsecurity to expand into Europe and the SMB segment, according to Thoma Bravo’s Proofpoint portfolio page — suggest the company is trying to broaden beyond pure email security into a wider data-security and human-risk platform, similar to the direction Mimecast has already taken. That consolidation instinct isn’t unique to Proofpoint — it mirrors the broader wave of platform-building acquisitions reshaping the sector, which we tracked in our look at the cybersecurity M&A wave reshaping the security industry.

How Abnormal Security’s AI-Native Approach Works

Abnormal Security — which rebranded parts of its marketing to “Abnormal AI” in 2026 — takes a structurally different approach. Rather than sitting in the mail flow via an MX record change, Abnormal connects directly to Microsoft 365 or Google Workspace through an API, giving it visibility into the full graph of who emails whom, how often, in what tone, and from what device or location, without ever having to intercept and re-route mail. That behavioral baseline is the core of its detection engine: instead of asking whether an email matches a known-bad signature, Abnormal asks whether a sender’s behavior deviates from the normal pattern for that specific relationship.

That architecture is specifically built to catch what gateway-based tools tend to miss — payloadless business email compromise, vendor email compromise, and account takeover, where there’s no malicious link or attachment to scan, just a request that looks legitimate on its face. Abnormal’s own positioning leans hard into this distinction, describing its platform as built for the threats secure email gateways miss, and the company says it now protects more than 4,500 organizations, including more than 25% of the Fortune 500, a milestone it highlighted around Black Hat USA 2026, per Yahoo Finance’s coverage of Abnormal AI’s email security expansion.

Abnormal’s momentum shows up in its funding history as much as its customer count. The company closed a $250 million Series D round in August 2024 led by Wellington Management, valuing the business at $5.1 billion and bringing total funding to roughly $546 million, according to the company’s own Series D announcement. Co-founder and CEO Evan Reiser has publicly floated an IPO timeline, though no public offering has been confirmed as of September 2026. Abnormal isn’t the only AI-native challenger pulling in fresh capital: AegisAI closed a $36 million Series A on July 24, 2026, taking its total funding to $49 million to build out its Vanguard AI email agent, xorlab raised a €5 million (roughly $5.5 million) Series A+ on September 1, 2026 to scale its AI-driven email protection across Europe, and StrongestLayer added a $4.1 million seed extension on July 22, 2026, bringing its own total to $9.3 million — a sign investors see room for more than one behavioral-AI winner in this category. For buyers, the practical implication is that Abnormal deploys faster than a gateway swap — often in hours, since there’s no MX record cutover — but it typically runs alongside an existing SEG (frequently Microsoft Defender for Office 365 or Proofpoint itself) rather than replacing it outright, adding a second detection layer instead of consolidating vendors.

How Mimecast Combines Gateway Filtering With Human Risk Management

Mimecast’s architecture looks closer to Proofpoint’s than to Abnormal’s: mail typically flows through Mimecast’s gateway, where it’s filtered for spam, malware, impersonation attempts, and malicious links before reaching the inbox. What distinguishes Mimecast is the breadth of adjacent capabilities bolted onto that core gateway — email archiving, continuity (keeping email flowing if a primary provider like Microsoft 365 goes down), and, more recently, a Human Risk Management layer that scores individual employees on their susceptibility to social engineering and adapts training and controls accordingly.

Scale is Mimecast’s clearest differentiator. The company says its platform protects more than 42,000 organizations and secures 27 million end users around the globe, according to its own Secure Email Gateway product page. That customer base skews smaller and mid-market on average compared to Proofpoint’s enterprise-heavy book, which is part of why Mimecast has built a reputation for lower total cost of ownership and faster time-to-value for IT teams that don’t have a dedicated security operations function. Since Permira took the company private in a $5.8 billion, $80-per-share deal in 2022, Mimecast has continued to invest specifically in the human-risk and awareness side of the business rather than pivoting toward Abnormal-style behavioral AI as its primary detection method, according to Mimecast’s own commentary on its Gartner Magic Quadrant standing.

The gateway-first design does carry the same fundamental limitation Proofpoint has: it’s strongest against payload-based threats (malware, malicious URLs, credential-phishing pages) and weaker, on its own, against the purely social-engineering-driven BEC and VEC attacks that don’t touch a link or attachment. Mimecast has added impersonation-protection and AI-assisted detection modules to close that gap, but organizations facing a high volume of executive-impersonation fraud specifically often layer Mimecast with a behavioral tool rather than relying on Mimecast alone.

Pricing Compared: What Each Platform Actually Costs

None of the three vendors publish a straightforward per-seat list price, which is standard practice in enterprise security but frustrating for buyers trying to build an early budget. Here’s what’s publicly documented, cross-referenced against third-party estimates and marketplace listings, presented conservatively where sources disagree.

VendorPricing modelPublicly documented reference pointContract structureTypical buyer profile
ProofpointPer user license, tied to contract termNo public per-seat price; budgetary quotes vary by license count and term lengthAnnual or multi-year enterprise agreementLarge enterprises already running other Proofpoint modules (DLP, security awareness, insider threat)
Abnormal SecurityPer mailbox / per employee, per yearThird-party marketplace and reseller estimates range roughly $15 to $80 per user/year depending on tier and add-ons; no official public rate cardTypically annual, sold as an add-on layer to an existing gatewayOrganizations that already have Microsoft 365 or Google Workspace native filtering or a SEG and want a second, behavioral detection layer
MimecastTiered by organization size and module bundleOne AWS Marketplace listing shows a 100-user bundle at $7,500/year (roughly $75/user/year) as a reference point, not a universal priceAnnual, with archiving and continuity often bundled inMid-market and enterprise IT teams wanting gateway plus archiving/continuity in one contract

The practical pattern buyers report: Abnormal is almost always positioned as an additive purchase layered on top of Microsoft’s native Defender for Office 365 or an existing SEG, which means its cost shows up as new spend rather than replacing an existing line item. Proofpoint and Mimecast, by contrast, are usually evaluated as full gateway replacements for each other, competing directly on total contract value across a three-year term. None of the three vendors will quote pricing without a sales conversation and a mailbox count, so budget-conscious teams should treat every public number here as a starting point for negotiation, not a final figure.

Gartner Magic Quadrant 2025: Where Each Vendor Ranks

Gartner’s decision to launch a dedicated Magic Quadrant for Email Security Platforms in 2024 was itself a signal that the category had matured beyond simple spam filtering. In that inaugural report, six vendors were named Leaders: Proofpoint, Abnormal Security, Trend Micro, Mimecast, KnowBe4 (via its Egress acquisition), and Check Point, while Microsoft was ranked as a Challenger rather than a Leader that year.

The 2025 edition reshuffled the board. Proofpoint confirmed it had been named a Leader for the second consecutive year, according to its own 2025 Gartner Magic Quadrant press release. Check Point likewise announced it had been recognized as a Leader in the 2025 Gartner Magic Quadrant for Email Security, per its own press release. Microsoft moved up from Challenger to Leader in the same 2025 report, according to its own Microsoft Security blog post — a notable shift, since it means Defender for Office 365 is now positioned alongside the three vendors in this comparison rather than trailing them. Mimecast also says it was named a Leader again in 2025, according to its own company blog post, and Abnormal has continued to market itself as a Leader in the same report.

Vendor2024 MQ status (inaugural)2025 MQ statusSource
ProofpointLeaderLeader (2nd year)Proofpoint newsroom
Abnormal SecurityLeaderLeaderCompany marketing materials
MimecastLeaderLeaderMimecast company blog
Check Point (Harmony Email)LeaderLeaderCheck Point newsroom
Microsoft (Defender for Office 365)ChallengerLeaderMicrosoft Security blog

The takeaway for buyers isn’t that any single vendor “won” the Magic Quadrant — Gartner’s own methodology explicitly avoids ranking Leaders against each other on a single axis. It’s that the competitive set has widened meaningfully in twelve months, and Microsoft’s jump from Challenger to Leader status means IT teams already paying for Microsoft 365 E5 licensing have a stronger built-in argument for staying with Defender rather than layering on a third-party gateway, even as Proofpoint, Abnormal, and Mimecast all continue to argue their detection depth justifies the extra spend.

Benchmarks and Independent Test Data

Independent, apples-to-apples detection-rate testing across all three vendors is harder to find publicly than vendor marketing pages would suggest — none of the three currently publish a jointly-audited, third-party detection benchmark against each other by name. That gap is itself useful information: security teams evaluating these platforms should ask each vendor directly for recent, dated proof-of-value results from their own environment rather than relying on marketing claims, since none of the available public benchmarks isolate one platform’s numbers against the other two under identical test conditions.

What is independently verifiable comes from analyst recognition rather than lab testing. All three vendors’ Leader status in Gartner’s Magic Quadrant for Email Security Platforms reflects Gartner’s own scoring of Ability to Execute and Completeness of Vision criteria, based on customer reference surveys and product capability assessments, rather than a raw phishing-catch percentage. Forrester has similarly built out research covering attack surface visibility and unified vulnerability management that increasingly folds in the exposure-management context around email risk, signaling that analyst firms are treating this as a maturing, well-instrumented category rather than a commodity spam-filter market. Until a neutral third party publishes a head-to-head detection-rate study naming all three vendors, the most defensible approach for security teams is to run a live pilot against real inbound mail for 30 to 60 days before signing a multi-year contract, since vendor-reported catch rates like Proofpoint’s claimed 99.99% block rate are self-measured and not verified against a shared, public test corpus.

SEG vs API-Native Detection: The Architecture Debate Explained

The single biggest technical fork in this market is whether a tool sits in the mail flow or watches it from the side. Secure email gateways — the model Proofpoint and Mimecast both use — require a change to your domain’s MX records so every inbound message physically passes through the vendor’s servers before it reaches Microsoft 365 or Google Workspace. That positioning gives a gateway the power to quarantine, rewrite, or outright block a message before a human ever sees it, and it’s why gateways remain the strongest option against malware attachments and malicious links that need to be detonated in a sandbox before delivery.

Integrated cloud email security (ICES) tools like Abnormal instead connect through an API after mail has already been accepted by the native platform, then use read/write permissions to retract or quarantine a message after the fact if it’s flagged as malicious. That’s a meaningfully different risk model: a gateway blocks before delivery, while an API-native tool typically acts within seconds to minutes after delivery. For fast-moving malware, that gap matters. For BEC and VEC, where the “payload” is a request rather than a file, the tradeoff mostly disappears, because there’s nothing for a sandbox to detonate in the first place — the entire attack is the wording and context of the message itself, which is exactly what behavioral baselining is built to catch.

This architectural split is also why so many enterprises run two tools rather than one. It’s common to see Microsoft 365 E5’s native Defender for Office 365 filtering, plus a gateway for deep content inspection, plus an API-native behavioral layer for BEC — three products stacked because each is strongest against a different threat category. Security teams evaluating this stack should also budget time for basic employee training; a technical control catches most attacks, but the ones that get through still rely on a human clicking “reply” or wiring money, which is why practical guidance like our step-by-step walkthrough on how to detect phishing emails remains a useful complement to any of these three platforms rather than a replacement for them.

Compliance, Data Residency, and Deployment Considerations

Regulated buyers rarely choose an email security vendor on detection rate alone. Data residency, retention, and audit trail requirements often carry equal or greater weight, particularly for financial services and healthcare organizations subject to frameworks like GLBA, HIPAA, or regional data protection law. Proofpoint’s gateway architecture, paired with its DLP and insider-threat modules, gives compliance teams a single pane of glass for e-discovery requests and retention policy enforcement, which is a large part of why the platform remains dominant in heavily regulated verticals despite the added tuning overhead. Mimecast’s archiving heritage plays a similar role, and its bundled continuity feature — keeping mail flowing during an outage of the primary provider — is frequently a hard requirement in industries where email downtime itself creates regulatory exposure.

Abnormal’s API-only model raises a different set of questions during procurement: because the platform requires broad read/write OAuth scopes into a live mailbox environment, security teams need to scrutinize exactly what data the vendor can access, how long it’s retained, and what happens to that access if the contract ends. This is the same category of due diligence that applies to any AI-driven security tool granted deep access to internal communications, and it’s worth running through the same vendor-risk checklist used for adjacent categories like exposure management and attack surface visibility — see our breakdown of Defender EASM vs CyCognito vs Tenable ASM for how that broader exposure-management market approaches similar third-party access questions. None of the three vendors publish a fully public SOC 2 Type II report or ISO 27001 certificate scope on their marketing pages, which means procurement teams should request current attestations directly during the sales process rather than assuming compliance from brand reputation alone.

Real-World Use Cases: 5 Scenarios and Which Platform Fits

Vendor selection in email security tends to follow the shape of the organization far more than any single feature checkbox. Here are five recurring deployment scenarios and how each platform typically performs against them.

  • A 15,000-employee financial services firm already running Proofpoint DLP and security awareness training. Consolidating email security onto Proofpoint’s platform keeps everything under one console and one vendor relationship, which simplifies compliance reporting for regulators who want a single audit trail.
  • A 300-person SaaS company on Microsoft 365 that has been hit by three CEO-impersonation wire-fraud attempts in the last year. This is Abnormal’s core use case: layering behavioral, API-based detection on top of Microsoft’s native filtering to catch payloadless BEC attempts that Defender’s signature-based rules let through. Social engineering doesn’t stop at email either — the same pretext-based tactics fueled the voice-phishing campaign behind the Abbott vishing breach, a reminder that email controls are one layer of a broader human-risk problem.
  • A mid-market manufacturer that needs email archiving for legal discovery alongside spam and phishing filtering. Mimecast’s bundled continuity and archiving heritage make it a natural fit for organizations that would otherwise need a separate archiving vendor entirely.
  • A healthcare network migrating off an end-of-life on-premises Exchange gateway. Both Proofpoint and Mimecast offer established migration playbooks for gateway-to-gateway cutovers; Abnormal is typically added afterward as a second layer rather than used as the sole replacement.
  • A private equity-backed portfolio company standardizing security tooling across a dozen recently acquired subsidiaries with different existing email stacks. Mimecast’s scale (42,000+ organizations already onboarded) and Proofpoint’s enterprise-grade policy management both suit rapid, templated rollouts across multiple tenants better than a single-tenant, deeply customized Abnormal deployment.

Migration Guide: Switching Email Security Platforms

Migrating email security is riskier than most SaaS switches because a misconfigured cutover can silently drop legitimate mail or, worse, open a filtering gap that lets an active attack through. The steps below apply broadly whether you’re moving toward Proofpoint, Mimecast, or layering in Abnormal.

  1. Inventory your current mail flow, including every third-party sender (marketing platforms, payment processors, internal apps) that relies on SPF/DKIM authorization tied to your existing gateway.
  2. Run the new platform in monitor-only or shadow mode alongside your existing gateway for at least two to four weeks before any MX record change, so you can compare flagged messages without affecting delivery.
  3. For gateway migrations (Proofpoint or Mimecast), update SPF, DKIM, and DMARC records to reflect the new sending infrastructure before changing MX records, not after.
  4. For API-based additions like Abnormal, complete the OAuth authorization to Microsoft 365 or Google Workspace and confirm read/write scopes match what’s needed for automated remediation, such as auto-quarantine of confirmed BEC attempts.
  5. Migrate policy rules in phases: start with your highest-risk groups (finance, executive assistants, HR) rather than a company-wide cutover on day one.
  6. Lower the MX record TTL to 300 seconds at least 48 hours before the actual cutover, so DNS propagation delays don’t extend an outage window.
  7. Change MX records during a low-volume window and monitor mail queues in real time for the first 24 hours.
  8. Re-enable any previously allow-listed senders and internal mail flow rules that may not carry over automatically from the old platform.
  9. Run a controlled phishing simulation within the first week to validate the new platform’s detection is actually active in production, not just configured.
  10. Decommission the old gateway’s MX priority only after a full week of clean mail flow, keeping it as a fallback in case of unexpected issues.

A basic DNS check to confirm your DMARC policy is correctly published before or after a migration looks like this:

dig TXT _dmarc.yourdomain.com +short

# Expected output resembles:
"v=DMARC1; p=quarantine; rua=mailto:[email protected]; pct=100"

Keep the DMARC policy at p=none during the shadow-mode monitoring phase so you can observe authentication failures without accidentally blocking legitimate mail, then tighten to p=quarantine or p=reject only after the new platform has been live and stable for a full reporting cycle. That tightening is happening more broadly across the industry: Valimail’s DMARC report, published February 25, 2026, found that global DMARC enforcement (policies set to quarantine or reject rather than none) rose seven points in 2025, climbing from 35% to 42% of domains, which suggests more organizations are finally completing this last step rather than leaving DMARC parked in monitor-only mode indefinitely.

Proofpoint: Pros and Cons

  • Pros: Deep threat-intelligence bench, mature sandboxing, strong fit for organizations already using other Proofpoint modules like DLP and security awareness training, extensive compliance and audit tooling for regulated industries.
  • Cons: Quote-based pricing with no public rate card makes budgeting hard, gateway-based architecture requires more tuning time than API-native tools, weaker out-of-the-box against purely payloadless BEC compared to behavioral-AI competitors.

Abnormal Security: Pros and Cons

  • Pros: API-only deployment with no MX record change, fastest time-to-value of the three, purpose-built for BEC, VEC, and account takeover that signature-based tools miss, strong momentum with 4,500+ organizations including over 25% of the Fortune 500.
  • Cons: Typically an additive cost layered on top of an existing gateway rather than a full replacement, smaller company with less two-decade track record than Proofpoint or Mimecast, no confirmed public pricing benchmarks make cost comparisons difficult.

Mimecast: Pros and Cons

  • Pros: Largest customer base of the three at 42,000+ organizations, bundled archiving and continuity reduce the need for a separate vendor, generally lower total cost of ownership for mid-market buyers, established migration playbooks.
  • Cons: Gateway-first architecture shares the same payloadless-BEC blind spot as Proofpoint, behavioral AI capabilities are less mature than Abnormal’s purpose-built engine, Permira ownership since 2022 means product roadmap is shaped by private-equity return timelines.

Which Platform Should You Choose?

There isn’t a single correct answer here, because the three platforms aren’t strictly substitutes for one another — Abnormal in particular is frequently bought as a complement rather than a replacement. Large enterprises with an existing Proofpoint footprint across DLP, insider threat, and awareness training should default to keeping email security consolidated on Proofpoint unless a specific BEC incident proves the gateway has a detection gap. Organizations already standardized on Microsoft 365 that want a fast, low-friction way to close the payloadless BEC gap without ripping out existing infrastructure should evaluate Abnormal first, given its API-only deployment and behavioral detection focus. Mid-market companies that need archiving, continuity, and gateway filtering bundled into a single, cost-predictable contract are generally best served by Mimecast, particularly if IT operates without a dedicated security engineering team to manage a more complex, multi-vendor stack.

Regulated industries — healthcare, financial services, insurance — should weigh Proofpoint’s compliance tooling and long enterprise track record most heavily, since audit and e-discovery requirements often matter as much as raw detection rate. Fast-growing SaaS and technology companies that are frequent targets of executive-impersonation wire fraud, but don’t want to disrupt existing mail flow with a gateway swap, are the clearest fit for Abnormal. And organizations juggling multiple subsidiaries or recent M&A integrations, where a fast, templated, low-customization rollout matters more than bleeding-edge AI detection, tend to gravitate toward Mimecast’s established multi-tenant deployment model.

The Verdict

Judged purely on scale, Mimecast wins by a wide margin — 42,000-plus protected organizations versus Abnormal’s 4,500 is roughly a 9x gap, and its bundled archiving and continuity make it the most operationally simple choice for teams without a dedicated security function. Judged on detection philosophy for the specific threat driving $2.77 billion in annual losses — payloadless BEC and VEC — Abnormal’s API-native, behavioral architecture is the more purpose-built tool, even though it usually arrives as a second layer rather than a full gateway replacement. Judged on enterprise depth, compliance tooling, and ecosystem breadth, Proofpoint’s position as a Thoma Bravo-backed platform reportedly shopping for acquisitions like Varonis suggests it intends to keep expanding beyond email into a broader human-risk and data-security suite.

The most defensible buying pattern for 2026, based on what all three vendors’ own numbers show: large, already-consolidated enterprises should stay with their existing gateway vendor (Proofpoint or Mimecast) unless a documented BEC incident proves a detection gap, and any organization on Microsoft 365 that hasn’t yet layered in a behavioral tool should treat Abnormal’s growth to 4,500-plus customers and 25% of the Fortune 500 as a signal worth a serious pilot. None of the three is objectively best in the abstract — the data says the right choice depends entirely on what’s already in the stack and which specific loss scenario keeps the CISO up at night.

Frequently Asked Questions

Is Abnormal Security a replacement for Microsoft Defender or Proofpoint?
No. Abnormal is almost always deployed as an additional, API-based detection layer on top of an existing gateway or native email platform like Microsoft 365, not as a full replacement. It catches behavioral anomalies that signature-based tools tend to miss, rather than duplicating spam and malware filtering.

Who owns Proofpoint and Mimecast in 2026?
Proofpoint has been owned by private equity firm Thoma Bravo since a $12.3 billion take-private deal in 2021, and the company is reportedly in talks to acquire Varonis Systems as of September 2026. Mimecast has been owned by Permira since a $5.8 billion, $80-per-share deal completed in 2022.

How much does Abnormal Security cost compared to Proofpoint and Mimecast?
None of the three vendors publish official per-seat pricing. Third-party marketplace and reseller estimates put Abnormal in a range of roughly $15 to $80 per user per year depending on tier, while Proofpoint and Mimecast pricing is quote-based and tied to license count, contract term, and bundled modules like archiving or DLP.

Which platform is best for stopping business email compromise (BEC)?
Abnormal Security’s API-based, behavioral detection model is purpose-built for payloadless BEC and vendor email compromise, which don’t contain malicious links or attachments for traditional gateways to scan. Proofpoint and Mimecast have both added impersonation-protection modules to address the same threat, but their core architecture remains gateway-first.

Did all three vendors get named Leaders in Gartner’s 2025 Magic Quadrant for Email Security?
Yes. Proofpoint, Abnormal Security, Mimecast, Check Point, and Microsoft were all positioned as Leaders in the 2025 report. Microsoft’s inclusion as a Leader is notable since it was ranked only as a Challenger in the inaugural 2024 report.

Can I run Abnormal Security alongside Proofpoint or Mimecast at the same time?
Yes, and it’s the most common deployment pattern. Because Abnormal connects via API rather than an MX record change, it can run in parallel with an existing Proofpoint or Mimecast gateway without conflicting, adding a second, behavioral detection layer rather than requiring a full cutover.

How big is the global email security market in 2026?
Estimates vary by research firm. Market Research Future puts the 2025 market at $6.83 billion, growing to $23.37 billion by 2035 at a 13.08% CAGR, while Market.us estimates $6.36 billion in 2025 climbing to $27.58 billion by 2035 at a 15.8% CAGR.

What’s the biggest difference between a secure email gateway and an API-based email security tool?
A secure email gateway like Proofpoint or Mimecast requires changing your domain’s MX records so mail routes through the vendor’s infrastructure before reaching your inbox, enabling deep sandboxing and content filtering. An API-based tool like Abnormal connects directly to your existing mailbox platform without rerouting mail, trading some of that upfront filtering depth for faster deployment and richer behavioral context on internal communication patterns.

Related Coverage

Elias Virtanen

Elias Virtanen

Cybersecurity Analyst

Elias Virtanen is the Cybersecurity Analyst at Tech Insider, bringing hands-on expertise from his background in penetration testing and security consulting. He previously worked as a security researcher at F-Secure in Helsinki, where he focused on threat intelligence and vulnerability disclosure. Elias covers ransomware trends, zero-trust architecture, and the evolving regulatory landscape including NIS2 and the EU Cyber Resilience Act. He holds a CISSP certification and an MSc in Information Security from Aalto University.

View all articles