Sold by
Sublime Email Security for Security Hub Extended
Complete email security platform that stops advanced attacks, automates abuse mailbox triage, and adapts defenses quickly with AI agents. Our agentic platform protects, adapts, and responds in real-time, eliminating vendor bottlenecks.
Reviews (32)
Information Technology and Services
Tailored, Transparent Email Security That Delivers Peace of Mind
Reviewed on Sep 17, 2026
Review provided by G2
What do you like best about the product?
I've been using Sublime's agentic platform to safeguard my emails, and it's been quite impressive. They genuinely provide the transparency and automation needed to tackle advanced threats without all the hassle. This isn't just another generic security solution. It's truly tailored to the specific threats my organization encounters, cutting down on false positives and giving me peace of mind. Their AI agents work seamlessly, giving my team way more flexibility and efficiency. Definitely a trusted and proactive solution!
What do you dislike about the product?
Nothing so far has pushed me away from the platform
What problems is the product solving and how is that benefiting you?
Email security with automation and high fidelity detections and response
Mike M.
Fantastic Architecture and Easy UI, Backed by a Super Responsive Team
Reviewed on Sep 11, 2026
Review provided by G2
What do you like best about the product?
The architecture is fantastic, the rules engine and how the platform is laid out is really solid. UI is easy to use. Can't wait for the MCP interface to make it even better! The sales and services team are fantastic, super responsive and really knowledgeable.
What do you dislike about the product?
Their Graymail feature is not full featured yet. They don't have an MCP interface yet.
What problems is the product solving and how is that benefiting you?
Layered email security.
Computer Software
Transparent, Editable Detection Rules with Fast Onboarding and Strong Phishing Coverage
Reviewed on Sep 09, 2026
Review provided by G2
What do you like best about the product?
The detection logic is fully transparent and editable, and that's the thing I'd point to first. Every rule is human-readable, so when we see a new phishing pattern we can fork an existing rule, tune the conditions, and have it live the same day instead of filing a vendor ticket and waiting a release cycle. The rules live as code, which means we version control them and code review them like any other engineering work.
Onboarding was genuinely fast. It connects to our mail tenant over API rather than sitting inline, so there were no MX changes, no mail flow risk, and no added delivery latency. We were reviewing real detections within days of signing, and we could run in observation mode first to see what it would have caught before letting it take action on anything.
The verdict detail is what changed our day-to-day workflow the most. Instead of a black-box risk score, we get the specific signals behind a detection along with full message and attachment analysis, so triage on a reported message takes a couple of minutes rather than a manual header-and-link investigation. Being able to query historical mail with a real query language means email is now something we can actually hunt across, which we didn't have before.
Integrations have held up well. The API is complete enough that we pipe detections into our own SIEM and automation rather than living in one more console.
Detection quality on business email compromise, vendor and executive impersonation, credential phishing, and QR-code lures has been consistently strong. Support is responsive and technically credible, with direct access to people who know the product instead of a tiered queue.
Onboarding was genuinely fast. It connects to our mail tenant over API rather than sitting inline, so there were no MX changes, no mail flow risk, and no added delivery latency. We were reviewing real detections within days of signing, and we could run in observation mode first to see what it would have caught before letting it take action on anything.
The verdict detail is what changed our day-to-day workflow the most. Instead of a black-box risk score, we get the specific signals behind a detection along with full message and attachment analysis, so triage on a reported message takes a couple of minutes rather than a manual header-and-link investigation. Being able to query historical mail with a real query language means email is now something we can actually hunt across, which we didn't have before.
Integrations have held up well. The API is complete enough that we pipe detections into our own SIEM and automation rather than living in one more console.
Detection quality on business email compromise, vendor and executive impersonation, credential phishing, and QR-code lures has been consistently strong. Support is responsive and technically credible, with direct access to people who know the product instead of a tiered queue.
What do you dislike about the product?
1. Built-in reporting and dashboards are the weakest part of the product. For the metrics leadership asks for, we end up exporting data into our own tooling rather than using what ships in the console.
What problems is the product solving and how is that benefiting you?
The core problem it solves is that our previous email controls caught commodity spam and known-bad indicators but missed the attacks that actually cause damage: business email compromise, vendor and executive impersonation, payment fraud attempts, and credential phishing that carries no malware and no known-bad URL. Those messages were landing in inboxes, and we were finding out about them from user reports rather than from a detection.
The second problem was that we had no way to act on what we knew. With a traditional gateway, our own threat intelligence and the patterns we saw in our own environment couldn't be turned into a control without opening a vendor ticket. Sublime closed that gap. When we see something new, we write or tune a rule ourselves and it's protecting the whole org that day.
The third was visibility. Email used to be the one major surface our detection team couldn't investigate. We had no way to search historical messages, so questions like "who else received this" or "has this sender pattern shown up before" took hours of manual work or went unanswered. Now that's a query.
The benefits have been concrete. Phishing triage that used to mean manually pulling headers, unpacking attachments, and checking links now takes a couple of minutes per message because the analysis is already done and the reasoning is visible. Fewer malicious messages reach users, so we spend less time on post-delivery cleanup and searching for who clicked. Our detection engineers can own email coverage directly instead of routing everything through IT or the vendor. And because it deploys over API with no mail flow changes, we got all of that without a migration project or any risk to mail delivery.
The second problem was that we had no way to act on what we knew. With a traditional gateway, our own threat intelligence and the patterns we saw in our own environment couldn't be turned into a control without opening a vendor ticket. Sublime closed that gap. When we see something new, we write or tune a rule ourselves and it's protecting the whole org that day.
The third was visibility. Email used to be the one major surface our detection team couldn't investigate. We had no way to search historical messages, so questions like "who else received this" or "has this sender pattern shown up before" took hours of manual work or went unanswered. Now that's a query.
The benefits have been concrete. Phishing triage that used to mean manually pulling headers, unpacking attachments, and checking links now takes a couple of minutes per message because the analysis is already done and the reasoning is visible. Fewer malicious messages reach users, so we spend less time on post-delivery cleanup and searching for who clicked. Our detection engineers can own email coverage directly instead of routing everything through IT or the vendor. And because it deploys over API with no mail flow changes, we got all of that without a migration project or any risk to mail delivery.
Information Technology and Services
Excellent Tool with Strong Admin Functionality and Dedicated Support
Reviewed on Sep 04, 2026
Review provided by G2
What do you like best about the product?
Excellent tool, efficacy right on par with Abnormal. More functionality from administrative perspective.
What do you dislike about the product?
I have not had any issues with the Sublime platform or their professional services! Continued support with dedicated engineer has been excellent.
What problems is the product solving and how is that benefiting you?
Much better efficacy than our previous solution, drastic reduction of phishing emails making it through to end users. The graymail feature is also cleaning up inboxes from excessive marketing emails.
Kyle P.
Crowdsourced Detection Rules That Build Herd Immunity Fast
Reviewed on Aug 13, 2026
Review provided by G2
What do you like best about the product?
I love the idea of crowdsourcing detection rules. You can take a new, novel phishing campaign and quickly turn it into a detection rule, backcheck it, and share it with the community, creating a kind of herd immunity, in a matter of minutes.
What do you dislike about the product?
I genuinely can’t think of anything I dislike.
What problems is the product solving and how is that benefiting you?
With many of the large email security vendors, analysts and engineers are largely at the mercy of the vendor when it comes to detection logic. You get whatever rules and detections they provide, with limited ability to really tune them to your environment.
Sublime completely changes that. As an analyst or engineer, I can build custom detection rules around virtually any property or behavior observed in an email. Those rules aren't limited to stopping future messages either. I can take something I just discovered, write a detection for it, and immediately look back across 30, 60, 90+ days of email to determine whether it ever reached anyone in the organization. If it did, I can remediate it, while also protecting the environment from anything matching that detection going forward.
The addition of AI-assisted and agentic workflows has made this even more powerful. Building and refining custom detections is incredibly fast, without taking away the transparency or control that makes Sublime so useful in the first place.
I've also helped onboard Sublime at multiple companies, and deployment is refreshingly simple. You can connect an environment and start getting meaningful visibility and protection in a matter of minutes rather than turning implementation into a weeks-long professional services project.
That combination of visibility, control, rapid response, and ease of deployment is what makes Sublime stand out for me.
Sublime completely changes that. As an analyst or engineer, I can build custom detection rules around virtually any property or behavior observed in an email. Those rules aren't limited to stopping future messages either. I can take something I just discovered, write a detection for it, and immediately look back across 30, 60, 90+ days of email to determine whether it ever reached anyone in the organization. If it did, I can remediate it, while also protecting the environment from anything matching that detection going forward.
The addition of AI-assisted and agentic workflows has made this even more powerful. Building and refining custom detections is incredibly fast, without taking away the transparency or control that makes Sublime so useful in the first place.
I've also helped onboard Sublime at multiple companies, and deployment is refreshingly simple. You can connect an environment and start getting meaningful visibility and protection in a matter of minutes rather than turning implementation into a weeks-long professional services project.
That combination of visibility, control, rapid response, and ease of deployment is what makes Sublime stand out for me.
Kyle B.
Effortlessly Blocks Malicious Emails, Saves Time
Reviewed on Feb 23, 2026
Review provided by G2
What do you like best about the product?
I like that the Sublime Email Security Platform is highly automated, which saves us time. We've significantly cut down the hours we used to spend reviewing emails and reported emails, reducing our annual effort by 400 hours. The initial setup was extremely easy.
What do you dislike about the product?
I have no complaints at this time.
What problems is the product solving and how is that benefiting you?
I use Sublime Email Security Platform to prevent malicious emails, solving the problem of phishing emails reaching users. It's highly automated, saving us time and reducing our email review effort by 400 hours annually.
Maryam S.
Robust Malware Protection with Seamless Setup
Reviewed on Feb 18, 2026
Review provided by G2
What do you like best about the product?
I appreciate the Sublime Email Security Platform for its detection and automation features, especially behavior and content-based detection. The initial setup was great and seamless, making the transition from Minecast very smooth.
What do you dislike about the product?
Na
What problems is the product solving and how is that benefiting you?
I use Sublime Email Security Platform for malware protection, benefiting from its detection and automation features like behavior and content-based detection.
Jack G.
Flexible Detection Rules with Sublime Email Security
Reviewed on Feb 17, 2026
Review provided by G2
What do you like best about the product?
I appreciate how user-friendly both the UI and API of the Sublime Email Security Platform are, which allows me to create in-depth detections and automations easily. I like that Sublime MQL facilitates deep customization when creating detection rules, capturing specific scenarios with various email attributes. The platform provides complex detection rule creation that would be challenging with other solutions, and it's impressive how the functions in MQL allow for intricate rule construction, down to prevalence within the configured tenant. The powerful language of Sublime provides extensive coverage with its rules, which is another aspect I find valuable.
What do you dislike about the product?
Availability of ASA via the Sentinel integration? Allowing the summary to be forwarded to Sentinel.
What problems is the product solving and how is that benefiting you?
I use Sublime Email Security Platform for creating complex detection rules efficiently with MQL. The user-friendly UI and API enable seamless detection and automation, and the platform's powerful customization allows specific email scenarios to be captured.
Jonathan C.
Powerful and Intuitive Email Security Solution
Reviewed on Feb 11, 2026
Review provided by G2
What do you like best about the product?
I like how the Sublime Email Security Platform is really intuitive and offers a lot of functionality. The API backend is robust, letting us expand capabilities and add automation. The reporting, hunting, and rule creation journey are great. I also appreciate that the initial setup is really easy.
What do you dislike about the product?
Nothing.
What problems is the product solving and how is that benefiting you?
I use Sublime Email Security Platform to handle detections and manage coverage effectively. It fills gaps where other tools can't, with powerful MQL for custom rules tailored to our needs.
John H.
Accurate Out of the Box, Transparent Detections, and Powerful Automations
Reviewed on Feb 11, 2026
Review provided by G2
What do you like best about the product?
I like that Sublime has a high degree of accuracy out of the box negating a long tuning process. The regular updates to existing and creation of new core detections keeps us well protected. The ability to create custom detection, create bespoke automations is a massive plus point. I like that the detection logic is transparent, so you always know why something was flagged. The API features also make it simple to integrate into existing workflows and remove repetitive manual tasks.
What do you dislike about the product?
Sublime develops and releases new valuable features regularly that we would love to use. Unfortunately, inconsistencies in regional hosting outside of the direct control of Sublime can mean that sometimes these valuable new features don’t appear in our region right away.
What problems is the product solving and how is that benefiting you?
Sublime greatly strengthens our overall detection stack by adding defence in depth, its automated remediation of threats and it's automated analysis and remediation of user‑reported phishing significantly reduces manual investigation time whilst maintaining or improving response quality.