Abnormal Inbound Email Security

Additional Info

CompanyAbnormal Security
Company size (employees)500 to 999
Headquarters RegionNorth America
Type of solutionSoftware


Abnormal Inbound Email Security pairs advanced behavioral science with risk-adaptive detection to stop the full spectrum of malicious email, including business email compromise, supply chain fraud, ransomware, and spam. Using 45,000+ signals to detect the identity of each user, the context of the relationship, and the content of the email itself, the platform baselines normal behavior to detect and prevent abnormal behavior. It remediates malicious emails in milliseconds and offers explainable attack insights with in-depth reviews of each attack.

Business email compromise alone resulted in $43 billion in exposed losses from 2016-2021. Unlike secure email gateways, which have difficulty detecting these attacks, Abnormal natively integrates with Microsoft 365 and Google Workspace to create a behavioral profile for users, partners, and vendors. Because Abnormal detects anomalies across identity, behavior, and content, the platform can stop never-before-seen attacks with no traditional indicators of compromise.

When Abnormal detects a malicious email, it automatically remediates it to a hidden folder within milliseconds, removing the possibility of end-user engagement, and logs a detailed analysis of the attack. The platform provides searchable logs of every email message it categorizes and includes an in-depth Threat Log for messages marked as malicious. Administrators can review high-level trends, deep dive into advanced attacks, or use search and respond capabilities to remediate misdirected messages.

Organizations can get started quickly and easily, since it takes only 60 seconds to integrate Abnormal with the cloud email platform. On average, Abnormal saves 15 hours for security teams each week and provides a 4x reduction in the number of threats that land in employee inboxes. That’s why customers see 278% ROI, as determined by an independent Forrester Total Economic Impact study.

How we are different

- Abnormal takes a fundamentally different approach to threat detection, using machine learning models and behavioral AI to baseline known behavior and detect the emails that deviate from it. This is different from legacy solutions, which require threat intelligence and known bad behavior to detect attacks. And because threat actors are constantly changing their tactics, the old approach no longer works to keep organizations safe.
- The platform includes four Knowledge Bases: AppBase, PeopleBase, TenantBase, and VendorBase, which automatically understand each of the third-party applications, people, tenants, and vendors within the email ecosystem. By providing insight into each of these categories, Abnormal can detect when there are changes across one of them and provide insight into it so security teams can acknowledge the configuration drift and take downstream action as necessary.
- The product works, and the proof is in what our customers say about it! We have over 125 independent reviews on Gartner Peer Insights, with a 4.8 rating and 99% recommendation rate. As one review says, "Abnormal's email security platform delivers on what they state it will do, it effectively removes malicious emails that have made it past Microsoft 365 and Exchange Online Protection without the end user knowing they ever received a phishing link or BEC attack message. The product is very easy to configure and can easily integrate into popular cloud-based email and collaboration suites."