Sublime Email Security Platform logo

    Sublime Email Security Platform

    Sublime stops more email attacks with less work. Our agentic platform protects, adapts, and responds in real-time, eliminating vendor bottlenecks.

    Ratings and reviews

    4.8
    36 ratings
    3 star
    2 star
    1 star
    92%
    8%
    0%
    0%
    0%
    0 AWS reviews
    |
    36 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (36)
    Computer Software

    Transparent, Editable Detection Rules with Fast Onboarding and Strong Phishing Coverage

    Reviewed on Sep 09, 2026
    Review provided by G2
    What do you like best about the product?
    The detection logic is fully transparent and editable, and that's the thing I'd point to first. Every rule is human-readable, so when we see a new phishing pattern we can fork an existing rule, tune the conditions, and have it live the same day instead of filing a vendor ticket and waiting a release cycle. The rules live as code, which means we version control them and code review them like any other engineering work.

    Onboarding was genuinely fast. It connects to our mail tenant over API rather than sitting inline, so there were no MX changes, no mail flow risk, and no added delivery latency. We were reviewing real detections within days of signing, and we could run in observation mode first to see what it would have caught before letting it take action on anything.

    The verdict detail is what changed our day-to-day workflow the most. Instead of a black-box risk score, we get the specific signals behind a detection along with full message and attachment analysis, so triage on a reported message takes a couple of minutes rather than a manual header-and-link investigation. Being able to query historical mail with a real query language means email is now something we can actually hunt across, which we didn't have before.

    Integrations have held up well. The API is complete enough that we pipe detections into our own SIEM and automation rather than living in one more console.

    Detection quality on business email compromise, vendor and executive impersonation, credential phishing, and QR-code lures has been consistently strong. Support is responsive and technically credible, with direct access to people who know the product instead of a tiered queue.
    What do you dislike about the product?
    1. Built-in reporting and dashboards are the weakest part of the product. For the metrics leadership asks for, we end up exporting data into our own tooling rather than using what ships in the console.
    What problems is the product solving and how is that benefiting you?
    The core problem it solves is that our previous email controls caught commodity spam and known-bad indicators but missed the attacks that actually cause damage: business email compromise, vendor and executive impersonation, payment fraud attempts, and credential phishing that carries no malware and no known-bad URL. Those messages were landing in inboxes, and we were finding out about them from user reports rather than from a detection.

    The second problem was that we had no way to act on what we knew. With a traditional gateway, our own threat intelligence and the patterns we saw in our own environment couldn't be turned into a control without opening a vendor ticket. Sublime closed that gap. When we see something new, we write or tune a rule ourselves and it's protecting the whole org that day.

    The third was visibility. Email used to be the one major surface our detection team couldn't investigate. We had no way to search historical messages, so questions like "who else received this" or "has this sender pattern shown up before" took hours of manual work or went unanswered. Now that's a query.

    The benefits have been concrete. Phishing triage that used to mean manually pulling headers, unpacking attachments, and checking links now takes a couple of minutes per message because the analysis is already done and the reasoning is visible. Fewer malicious messages reach users, so we spend less time on post-delivery cleanup and searching for who clicked. Our detection engineers can own email coverage directly instead of routing everything through IT or the vendor. And because it deploys over API with no mail flow changes, we got all of that without a migration project or any risk to mail delivery.
    Information Technology and Services

    Excellent Tool with Strong Admin Functionality and Dedicated Support

    Reviewed on Sep 04, 2026
    Review provided by G2
    What do you like best about the product?
    Excellent tool, efficacy right on par with Abnormal. More functionality from administrative perspective.
    What do you dislike about the product?
    I have not had any issues with the Sublime platform or their professional services! Continued support with dedicated engineer has been excellent.
    What problems is the product solving and how is that benefiting you?
    Much better efficacy than our previous solution, drastic reduction of phishing emails making it through to end users. The graymail feature is also cleaning up inboxes from excessive marketing emails.
    Vsadalaga Sadalga

    Streamlined email triage has reduced phishing response time and improves investigation clarity

    Reviewed on Aug 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Sublime Security is email security and phishing detection, where I use it to investigate suspicious emails, identify phishing and BEC attempts, analyze malicious links and attachments, and support the triage and remediation process.

    One example of how I used Sublime Security to handle a real situation is when it flagged a phishing email that appeared to come from a legitimate vendor based on the sender and email content. I used it to investigate the links and other indicators, confirmed it was a phishing attempt, and removed the message from affected mailboxes, which helped prevent users from interacting with it.

    I mainly use Sublime Security as part of my day-to-day email alert triage, which helps me quickly identify suspicious emails, investigate phishing and BEC attempts, and gather useful context before deciding whether to close or escalate an alert. I also find the automation and remediation capabilities helpful for reducing manual work.

    What is most valuable?

    For me, the best features Sublime Security offers are phishing and BEC detection, detailed email analysis, threat hunting, and automated triage remediation. I appreciate that the detections are transparent, allowing me to understand why an email was flagged instead of just receiving a black box verdict. Sublime Security's AI Analyst is particularly useful for automatically investigating user-reported emails and reducing manual triage work.

    Sublime Security's AI Analyst has helped me reduce the amount of manual email triage I need to do because when users report suspicious emails, it analyzes the message, links, attachments, and sender context and provides a verdict with reasoning. This gives me a quick starting point for investigation instead of reviewing everything manually, which saves time especially when there are a large number of user-reported emails. This allows me to focus my attention on cases that actually need deeper investigation.

    I particularly appreciate the combination of detections, threat hunting, and remediation in one platform. The campaign grouping is useful because I can investigate related emails together instead of treating every message as a separate alert. The transparency of the detections is another strong point as it helps me understand why a message was flagged.

    Sublime Security has positively impacted my organization by helping our team reduce manual email triage and respond to phishing and BEC threats faster. The automated analysis and remediation allow analysts to spend less time reviewing routine user-reported emails and more time on higher-risk investigations. It also gives us better visibility into why an email was flagged, making investigations and escalations easier.

    The biggest measurable impact has been reducing the time spent on email triage, handling user-reported phishing emails faster, and reducing the amount of manual investigation required. Although I don't have a specific organization-wide percentage to share, the improvement is noticeable in analyst workload and response time.

    What needs improvement?

    I believe the main areas for improvement for Sublime Security are ease of onboarding and learning, as the platform has many powerful capabilities, making it take some time for new analysts to become comfortable with all the features and detection logic. I would also appreciate continued improvements in customization and integration, especially for fitting it smoothly into different SOC workflows.

    Regarding needed improvements, I think the documentation is generally useful, but I would appreciate more beginner-friendly guidance and practical SOC examples, particularly around setting up detections, tuning rules, and integrating Sublime Security with SIEM and SOAR platforms. The API and integration options are already strong, but clearer step-by-step examples would make it easier for analysts to get started and build more advanced workflows.

    For how long have I used the solution?

    I have been using Sublime Security for 1.5 years.

    What other advice do I have?

    I would recommend Sublime Security to teams that want to strengthen their existing email security and reduce manual phishing triage. I suggest they start with a focused evaluation using real user-reported emails and measure detection quality, false positives, and analyst time saved. I have covered all the relevant points regarding Sublime Security. I give this product a rating of 9.

    reviewer2875785

    Focused email threat workflows have improved phishing investigations and automate remediation

    Reviewed on Aug 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Sublime Security is to detect email threats and respond to them, primarily for investigating phishing and business BEC attempts, analyzing suspicious URLs and attachments, and taking remediation actions on the malicious emails.

    I usually start by reviewing the sender, then proceed with header analysis, URL and attachment review, and analyzing the message content. After that, I check the threat indicators and detection results to understand the risk, and if it is confirmed, I use Sublime Security's remediation capabilities to remove or quarantine the email and document the incident.

    I also use Sublime Security to investigate similar email campaigns and identify patterns across users. Its detection and remediation capabilities help me respond consistently, reducing manual work and improving the overall security posture.

    What is most valuable?

    In my opinion, the best features of Sublime Security are advanced phishing and BEC detection, campaign grouping, threat hunting, and automated remediation. I especially find campaign grouping and remediation useful because they allow me to investigate related emails together and quickly quarantine or remove malicious messages across affected mailboxes, and Sublime Security provides detailed detection reasoning that aids during my investigations.

    Campaign grouping helps us identify similar phishing patterns across multiple users and investigate them as one campaign instead of handling each email separately, which makes it easier to spot common IOCs, understand the attack pattern, and quickly remediate all related messages. This saves our time and improves consistency.

    Sublime Security has improved our email threat detection and response by helping us identify phishing and Business Email Compromise campaigns faster, investigate related emails, and automate remediation, which has reduced our manual effort and improved our response time. This enables us to better protect against email-based threats.

    What needs improvement?

    Sublime Security could be improved by enabling more integration, better customization of alerts, and more detailed reporting. I would also like more flexibility in detection tuning to reduce false positives and make investigations even more efficient.

    For how long have I used the solution?

    I have been using Sublime Security for one year.

    What do I think about the stability of the solution?

    Sublime Security is stable and reliable for our day-to-day email security operations.

    What do I think about the scalability of the solution?

    Its scalability is also good, as it can scale with the number of protected mailboxes or users, or as email volume grows, supporting enterprise development across Microsoft 365 or Google Workspace.

    How are customer service and support?

    Customer support is good. I would rate customer support ten out of ten.

    What was our ROI?

    I have seen a reduction in time saved, and I don't know about the direct cost savings. I estimate that we have improved our efficiency, especially for phishing campaigns where we can handle multiple similar emails together, which has reduced repetitive analyst work and improved our response time. Although I don't have specific metrics to mention, I can confirm it has reduced our time to respond and alert.

    What other advice do I have?

    My advice to others looking into using Sublime Security is to start with a focused use case such as phishing or user-reported email triage, integrate it with your existing Microsoft 365 or Google Workspace environment, tune the detection based on your needs, and then gradually enable automated remediation. I would rate this product nine out of ten.
    Kyle P.

    Crowdsourced Detection Rules That Build Herd Immunity Fast

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    I love the idea of crowdsourcing detection rules. You can take a new, novel phishing campaign and quickly turn it into a detection rule, backcheck it, and share it with the community, creating a kind of herd immunity, in a matter of minutes.
    What do you dislike about the product?
    I genuinely can’t think of anything I dislike.
    What problems is the product solving and how is that benefiting you?
    With many of the large email security vendors, analysts and engineers are largely at the mercy of the vendor when it comes to detection logic. You get whatever rules and detections they provide, with limited ability to really tune them to your environment.

    Sublime completely changes that. As an analyst or engineer, I can build custom detection rules around virtually any property or behavior observed in an email. Those rules aren't limited to stopping future messages either. I can take something I just discovered, write a detection for it, and immediately look back across 30, 60, 90+ days of email to determine whether it ever reached anyone in the organization. If it did, I can remediate it, while also protecting the environment from anything matching that detection going forward.

    The addition of AI-assisted and agentic workflows has made this even more powerful. Building and refining custom detections is incredibly fast, without taking away the transparency or control that makes Sublime so useful in the first place.

    I've also helped onboard Sublime at multiple companies, and deployment is refreshingly simple. You can connect an environment and start getting meaningful visibility and protection in a matter of minutes rather than turning implementation into a weeks-long professional services project.

    That combination of visibility, control, rapid response, and ease of deployment is what makes Sublime stand out for me.
    reviewer2809026

    Advanced email rules have improved spam detection and made daily reviews more efficient

    Reviewed on Jul 03, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Sublime Security is to test how this product works, so I am using this for that purpose.

    For a quick specific example of what I tested with Sublime Security, it detects the emails of the person on this side to check that feature, and there is a feature in Sublime Security that is detection as code, which is an excellent feature that I have noticed in this product. I am talking about eleven hundred, and that detection feature is something where I can explicitly customize mentions of power spam or non-structured email. With our custom permissions, we have it, and getting that notice by word blocking is something very important. It is a great feature that I have been using.

    Regarding my main use case for testing Sublime Security, it is very good, and I fully specify that detection; it is something very extensive with maximum features.

    What is most valuable?

    The best features Sublime Security offers include detection as code, which gives a very powerful feature for users to write rules, custom objects, and the language provides some syntax that is definitely a good feature. The second one is why it detects spam emails or justifies why this is considered spam, which is the second most valuable feature.

    I use the detection as code feature in my day-to-day life, which usually identifies junk emails and spam emails by default with the conditions and the vast dataset it has. Even if some emails may not get into that machine learning dataset, I can describe if it is from an external source and has rewards; I can remove it since it is considered spam. This feature changes the usual segregation and categorization, helping users not fall for known types of emails that the system may not detect. The explanation of justification, instead of just flagging something as spam, gives the user understanding such as, this is not a Google email; we really cannot click on it. It enhances user security, and even if another user sees this type of content based on gesture events for another email, they think not to use the image correctly.

    Sublime Security has positively impacted my organization.

    What needs improvement?

    I would say there are very minimal changes needed regarding Sublime Security; for first-time users, it can be difficult knowing how to write the tool. Having some templates available would improve the experience.

    My advice for others looking into using Sublime Security is that each edition would be helpful for initial users, and users should set templates in, which can be added; right now, I am not trying anything new, as this is cool.

    For how long have I used the solution?

    I have been using Sublime Security for three months.

    What do I think about the stability of the solution?

    Sublime Security is stable; I confirm this.

    Which solution did I use previously and why did I switch?

    I did switch to Sublime Security; it is part of my style of working.

    Which other solutions did I evaluate?

    Before choosing Sublime Security, I evaluated alternatives such as MyCast and Proofpoint, which I refused before finalizing on Sublime Security.

    What other advice do I have?

    Phishing versus phishing detection is also something I find good, and I have mentioned these things already.

    Since I have been using Sublime Security personally, I have noticed specific improvements like fewer spam emails and improved detection, which saves me time. It helps me segregate emails instead of reviewing all things manually, as it detects spam emails. I do not have to go through every email, which makes me very efficient for other tasks. It also shows if some emails are current, and if I am about to register or receive registration links, it tells me why those emails are separated. I understand better instead of reading all the emails, and it summarizes the words or thumbnails of the emails. If an email is considered good, I continue, making my time more efficient.

    Regarding the AI capabilities of Sublime Security, I think for detection, using ML to analyze content is already a feature present in Sublime Security, which also identifies phishing attempts.

    I think Sublime Security shows false positives. I give this review a rating of nine.

    reviewer2805510

    Advanced email protection has enabled us to safeguard partners and reduce costly phishing risks

    Reviewed on Apr 02, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Our main use case is two-fold. Primarily, as a channel partner, our core focus is channel enablement. We actively pitch, demonstrate, and distribute Sublime Security to our partner network, who then deploy it for end-user organizations. Secondarily, we 'drink our own champagne' by running it internally to protect our own business communications.

    When we position it to our partners, we frame it as an advanced email security platform. It goes far beyond traditional junk filtering by actively hunting the sophisticated threats that bypass native defenses—specifically Business Email Compromise (BEC), CEO fraud, invoice scams, fake login pages, and malware attachments.

    How has it helped my organization?

    As a distributor, the positive impact for us is measured by how well the product performs for our partners and their end-users. Sublime Security has been a major positive because it perfectly fits our criteria for 'best-in-breed' solutions. Specifically, it delivers strong ROI, saves employee time, and significantly reduces risk exposure by preventing expensive breaches. Because it checks all these boxes, we've been able to successfully enable our partners across all our regions to confidently take it to market.

    Another major positive is its deployment model. In today's cybersecurity landscape, 'rip-and-replace' is a massive hurdle for buyers. Sublime works flawlessly with existing tools, enhancing a customer's current stack rather than forcing them to rebuild it.

    What is most valuable?

    The standout features of Sublime Security revolve around its ability to catch advanced threats that bypass native defenses. Specifically, it excels at blocking malware attachments and stopping Business Email Compromise (BEC), such as CEO fraud and invoice scams.

    A major advantage is its fast time-to-value because it isn't a rip-and-replace solution. Instead, it acts as a 'smarter layer' that enhances existing protections like Microsoft 365 or Google Workspace. While native security catches the obvious junk, Sublime uses flexible, customizable detection logic to catch the highly sophisticated attacks that easily slip through standard filters.

    Finally, the platform gives you deep visibility and fast search capabilities across all email activity. Without a tool like this, investigations take far too long, and teams lack visibility into what actually breached the inbox. Sublime solves this by offering rapid detection, automated response actions, and the ability to quickly remove malicious emails in bulk.

    What needs improvement?

    Based on the feedback we receive from our partners and their end-users, there are two main areas for improvement: the learning curve and pricing for smaller organizations. First, while the platform is incredibly powerful, it isn't simply 'plug-and-play.' Security teams need to invest time into learning the product to extract its full value.

    Second, the cost can feel a bit steep for small-to-medium-sized businesses (SMBs). However, we always caveat this by looking at the ROI: a single breach could put a small company completely out of business. While the upfront cost might seem high to them, preventing just one catastrophic breach means the tool instantly pays for itself.

    For how long have I used the solution?

    I have been using the solution for eighteen months.

    What other advice do I have?

    On a scale of one to ten, I rate Sublime Security a nine out of ten because I believe there are a couple of negatives regarding scalability for catering to enterprise and small to medium enterprises. Additionally, the product requires a learning phase, and it is not readily usable right away.

    Sublime Security merits this rating because of a couple of changes that need to be addressed. If it catered to both small and enterprise businesses on a pricing scale, it would receive a ten, but it is not far away.

    Kyle B.

    Effortlessly Blocks Malicious Emails, Saves Time

    Reviewed on Feb 23, 2026
    Review provided by G2
    What do you like best about the product?
    I like that the Sublime Email Security Platform is highly automated, which saves us time. We've significantly cut down the hours we used to spend reviewing emails and reported emails, reducing our annual effort by 400 hours. The initial setup was extremely easy.
    What do you dislike about the product?
    I have no complaints at this time.
    What problems is the product solving and how is that benefiting you?
    I use Sublime Email Security Platform to prevent malicious emails, solving the problem of phishing emails reaching users. It's highly automated, saving us time and reducing our email review effort by 400 hours annually.
    Maryam S.

    Robust Malware Protection with Seamless Setup

    Reviewed on Feb 18, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate the Sublime Email Security Platform for its detection and automation features, especially behavior and content-based detection. The initial setup was great and seamless, making the transition from Minecast very smooth.
    What do you dislike about the product?
    Na
    What problems is the product solving and how is that benefiting you?
    I use Sublime Email Security Platform for malware protection, benefiting from its detection and automation features like behavior and content-based detection.
    Jack G.

    Flexible Detection Rules with Sublime Email Security

    Reviewed on Feb 17, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate how user-friendly both the UI and API of the Sublime Email Security Platform are, which allows me to create in-depth detections and automations easily. I like that Sublime MQL facilitates deep customization when creating detection rules, capturing specific scenarios with various email attributes. The platform provides complex detection rule creation that would be challenging with other solutions, and it's impressive how the functions in MQL allow for intricate rule construction, down to prevalence within the configured tenant. The powerful language of Sublime provides extensive coverage with its rules, which is another aspect I find valuable.
    What do you dislike about the product?
    Availability of ASA via the Sentinel integration? Allowing the summary to be forwarded to Sentinel.
    What problems is the product solving and how is that benefiting you?
    I use Sublime Email Security Platform for creating complex detection rules efficiently with MQL. The user-friendly UI and API enable seamless detection and automation, and the platform's powerful customization allows specific email scenarios to be captured.