Sold by
Abnormal - Cloud Email Security
Abnormal is the AI-native cloud email security platform that protects businesses from the most advanced and costly attacks while fully automating security operations. Unlike traditional SEGs, which rely on disruptive inline processing and static rules, Abnormal deploys in minutes via a three-click API integration with Microsoft 365 and Google Workspace. The solution ingests tens of thousands of signals unique to each customer, and uses behavioral AI to precisely detect and remediate business email compromise (BEC), account takeovers, invoice fraud, and supply chain attacks in real time. Abnormal delivers unmatched efficacy and a seamless experience, reducing security teams operational overhead by 95%. Recognized as a "Leader" in the Gartner Magic Quadrant for Email Security Platforms, Abnormal is celebrated for its innovation, customer centric approach, and 99% "Would Recommend" rating on Gartner Peer Insights.
Reviews (99)
Anonymous
Protect Yourself and Your Inbox
Reviewed on Sep 02, 2026
Review provided by G2
What do you like best about the product?
I enjoy the protection Abnormal AI provides for my inbox. Once it's set up it prevents scams and phishing emails to come through to your inbox which alleviates stress from wondering if the conversations coming to my inbox are legit or not. Lastly, I enjoy how it provides reports so you can build self awareness to continue to protect yourself.
What do you dislike about the product?
There are not many drawbacks, but some simple attacks can make it's way to your inbox which can be a downfall, but the more you familiarize yourself with the scams its easier to see through it.
What problems is the product solving and how is that benefiting you?
As a non-profit we receive hundreds of communications a day. This program vets emails before it hits our inbox so we can efficiently collaborate with people who have genuine interest.
Corey C.
Seamless Office 365 Integration with Strong Threat and Phishing Protection
Reviewed on Sep 01, 2026
Review provided by G2
What do you like best about the product?
It easily integrates with Office 365, is very good at identifying threats, spam, phishing scams, and other threats,
What do you dislike about the product?
I wish there was the ability to implement custom graymail categories for smart filtering. Currently there only exists "Promotional", however it would be nice to add additional categories if we wanted, ie social media, etc.
What problems is the product solving and how is that benefiting you?
Abnormal AI has given us an intelligent email filter that can keep up with new risks that are developing. This is one of the important cybersecurity layers for our organization.
Jigi P.
Behavioral AI Detects Advanced Email Threats.
Reviewed on Sep 01, 2026
Review provided by G2
What do you like best about the product?
Abnormal Alerted us to sophisticated phishing emails, business email compromise, and account takeover attempts. Instead of relying on rules to detect email threats, its behavioral AI analyzes how people and systems communicate and behave to uncover suspicious emails. We also had better visibility into why an email was flagged, which was valuable during our security investigation and response efforts.
What do you dislike about the product?
Performs well once configured. The Abnormal platform works well for securing enterprise email, however it takes time to learn how it detects threats and properly tune it to meet your organization's needs. Your security team may require a learning curve when integrating with your incident response processes.
What problems is the product solving and how is that benefiting you?
Helped us better handle targeted email attacks. Abnormal reduced the risk of phishing emails, business email compromise attacks, and compromised accounts. It also decreased our reliance on heavily staffing email investigations by automating threat analysis and remediation.
Matthew P.
Keeps My Inbox Clean with Smart Email Sorting
Reviewed on Aug 27, 2026
Review provided by G2
What do you like best about the product?
I appreciate the fact that it sorts your emails based on your preferences. This feature keeps my inbox cleaned up while allowing me to look at less pertinent emails easily and on my own time.
What do you dislike about the product?
It can be a distraction when it sorts emails into folders. For a split second, all emails show up in my main inbox before disappearing to their sorted folders. It takes some getting used to, and even at that it can be annoying.
What problems is the product solving and how is that benefiting you?
We use Abnormal AI as our email security program filtering out malicious and spam emails as well as sorting emails by potential importance. It's not just providing email security, it's also saving us time.
Legal Services
Virtually Zero-Touch Email Security That Learns as It Scans
Reviewed on Aug 27, 2026
Review provided by G2
What do you like best about the product?
It’s virtually zero-touch. You enable it, it scans your mailboxes and learns, and there’s very little you need to do beyond that—no real setup of policies, groups, definitions, or configuration. Catching even a single Business Email Compromise and we're getting our money's worth. with Abnormal AI since go live, its caught almost 7000!!
What do you dislike about the product?
There’s very little to dislike. The only drawback is that you need to keep monitoring for false positives, although I suppose that’s true of most automated email security systems.
What problems is the product solving and how is that benefiting you?
It helps plug gaps in our Mimecast solution, such as Business Email Compromise and VIP Targeted Threats. It also complements our Entra User Account Compromise coverage.
Anonymous
Effortless Setup, Room for Improvement in Threat Detection
Reviewed on Aug 27, 2026
Review provided by G2
What do you like best about the product?
I like that Abnormal AI allows smaller teams to manage threats with a more hands-off approach, saving time tuning models and reviewing phishing reports. The AI security mailbox is quite good, as we can direct reports there without our internal SOC intervention, saving us invaluable time. Integrating with KnowBe4's PAB and directing reports to the AI security mailbox allows users to report potentially malicious or spam emails for another analysis. I also appreciate the integrations with Rapid7 and Entra, which help detect account takeovers and take automated actions. The upcoming integration with Cyera will likely be invaluable. The initial setup of Abnormal AI was extremely easy.
What do you dislike about the product?
We've found that some quite basic attacks get past Abnormal AI, including BEC and VIP impersonation, which didn't happen before with Darktrace. The model improvements from the D360 team need to be more considered and holistic, as similar attacks continue to get through.
What problems is the product solving and how is that benefiting you?
Abnormal AI helps prevent and detect account takeovers, malicious mail, and spam without SOC intervention, automating reports. It saves us time since we don't manually review phish reports. The AI security mailbox is beneficial for a hands-off threat management approach, integrating well with other tools and reducing false negatives.
Ethan W.
Effortless Email Security with Abnormal AI
Reviewed on Aug 27, 2026
Review provided by G2
What do you like best about the product?
I like the ease of use of Abnormal AI and how it provides alerts when it monitors and finds something unusual in our environment. I also appreciate that it is not information intensive; we only need to provide minimal information initially, and it quickly learns and adapts to our environment. The initial setup was almost too easy, and I was pleased that nothing went wrong during the process.
What do you dislike about the product?
I find setting up the UI a bit cumbersome and it takes effort to get the dashboards to show the information I need.
What problems is the product solving and how is that benefiting you?
I appreciate that Abnormal AI reduces our need for a dedicated security team for data threats and provides ease of use with its alert system for abnormal activities.
Scott D.
Timesaver and protector
Reviewed on Aug 25, 2026
Review provided by G2
What do you like best about the product?
I like that I am protected by Abnormal and the Graymail addon has boosted the productivity of the office.
What do you dislike about the product?
Haven’t found anything yet to be upset about
What problems is the product solving and how is that benefiting you?
Protecting the business from malicious emails and improving productivity with Graymail.
Gulsan P.
Eliminates alert fatigue and automates phishing triage
Reviewed on Aug 25, 2026
Review provided by G2
What do you like best about the product?
Working in the SOC, dealing with the daily avalanche of user-reported suspicious emails used to be a massive time sink. Abnormal completely transformed this workflow. The AI Security Mailbox feature is incredible—it autonomously triages every user-reported email, categorizing them as malicious, spam, or safe. Instead of me manually extracting headers, firing up a Kali Linux VM to sandbox suspicious payloads, or running various penetration testing tools to validate a malicious link, the behavioral AI engine does the heavy lifting instantly. I also really appreciate the API-native deployment. We integrated it directly with our Microsoft 365 environment in minutes without having to mess with MX records or complex mail routing. Because it analyzes thousands of behavioral signals rather than just static threat signatures, it catches advanced Business Email Compromise (BEC) and vendor fraud that our legacy secure email gateway (SEG) consistently missed.
What do you dislike about the product?
While the behavioral AI is highly effective, it can occasionally feel like a "black box." When the system flags an internal email as anomalous or blocks a seemingly legitimate vendor communication, explaining the exact rationale to end-users can be tricky because the decision is based on complex behavioral deviations rather than a simple blocked IP address or malicious URL. Additionally, while the dashboard is clean, it could offer more customizable reporting widgets for the highly specific metrics our team needs to present during weekly security briefings.
What problems is the product solving and how is that benefiting you?
The primary problem it solves is the immense operational burden of manual email investigation. By automating the triage process and instantly removing malicious emails across all mailboxes (while also finding unreported emails in the same campaign), it frees up hours of my day. This allows our team to focus strictly on proactive threat hunting and complex identity threats instead of being buried in a queue of low-level phishing reports. It has drastically reduced our mean time to respond (MTTR) to email-based attacks.
Krish P.
Highly capable of mail security through an API, will search asynchronously, but there's a gotcha.
Reviewed on Aug 21, 2026
Review provided by G2
What do you like best about the product?
I'm a Cyber Security Engineer at a medium size financial services company. Our motive for using Abnormal Security is to defend our Microsoft 365 tenant against sophisticated phishing and Business Email Compromise (BEC) attacks, as well as vendor impersonation attacks, that our normal Secure Email Gateway (SEG) could not defend against. Our SOC team also uses its automated remediation capabilities to deal with the huge volume of emails that are reported to them with suspicious content.The best thing about Abnormal is the deployment itself is so simple. Since it integrates directly using Microsoft 365 APIs rather than needing intricate MX record modifications, it was up and running in our environment in just a matter of moments. The AI engine's ability to grasp the nuances of communication and To ensure the proper setting for what's considered the norm in employee performance is extremely precise. Commonly discovers highly advanced attacks and forgery of vendor invoices with no visible malicious links or attachments. Prior to Abnormal, at least half of a security analyst's day would be spent manually examining reported email or ramping through their inboxes, one by one. With the platform's auto-remediation, though, nearly all of that is done in the background, and that's a giant timesaver for our small team. It is indeed a high dollar solution to use Abnormal Security versus traditional email security, but for our team, the ROI has been 100% worth it. The per-mailbox pricing model seemed like a bit of an "up front investment" for a medium size user base. This combination of user-provided policy and the overwhelming number of engineering hours our SOC analysts put in taking care of user-reported phishing tickets weekly makes the platform self-funding not just in recovered productivity, but in recovered time. Most important of all, denying one costly vendor scam or bogus wire transfer message eradicates the entire yearly position. Automation and risk reduction are worth a lot for asecurity team faced with heavy workload and members who can't keep up with threats in their inbox all day.
What do you dislike about the product?
Abnormal works through the API (asynchronously, not within the mail flow itself as a traditional gateway would be) so scanning processes are not synchronous. This implies a malicious e-mail will appear in a user's inbox for a few seconds in between the AI system analyzing it and retriving it. There's a very fine margin for error if someone is focused on their inbox and presses the keys really rapidly. Also, there are instances when the system is a bit too strong in money related emails; it may mistake for example a genuine invoice or a message from a collaborator for ‘graymail' and perhaps even ‘potential threat'. Succumbing to these false positives takes some time as it isn't always readily possible to just whitelist a trusted domain without a bit of a hoop-jumping exercise.
What problems is the product solving and how is that benefiting you?
The danger of account takeover and targeted VIP spoofing was huge as our CEO would be involved in emergencies calls for wire transfers under fake names. Our previous gateway only protected on a threat signature basis and had no protection against text only attacks. But in Abnormal they realized that our executives really do write and communicate. It recently thwarted a dishonest vendor who asked our finance department to wire funds to another account for a bill worth hundreds of thousands of dollars. So, by automating the triage on our abuse mailbox and preventing these zero day social engineering attacks, it has cut our organisational risk even down to the next level and allowed us to direct our security team's efforts towards proactive threat hunting as opposed to copious amounts of email management.