Abnormal - Cloud Email Security (EU) logo

    Abnormal - Cloud Email Security (EU)

    Abnormal is the AI-native cloud email security platform that protects businesses from the most advanced and costly attacks while fully automating security operations. Unlike traditional SEGs, which rely on disruptive inline processing and static rules, Abnormal deploys in minutes via a three-click API integration with Microsoft 365 and Google Workspace. The solution ingests tens of thousands of signals unique to each customer, and uses behavioral AI to precisely detect and remediate business email compromise (BEC), account takeovers, invoice fraud, and supply chain attacks in real time. Abnormal delivers unmatched efficacy and a seamless experience, reducing security teams operational overhead by 95%. Recognized as a "Leader" in the Gartner Magic Quadrant for Email Security Platforms, Abnormal is celebrated for its innovation, customer centric approach, and 99% "Would Recommend" rating on Gartner Peer Insights.

    Ratings and reviews

    4.8
    92 ratings
    3 star
    1 star
    88%
    11%
    0%
    1%
    0%
    0 AWS reviews
    |
    92 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (92)
    Scott D.

    Timesaver and protector

    Reviewed on Aug 25, 2026
    Review provided by G2
    What do you like best about the product?
    I like that I am protected by Abnormal and the Graymail addon has boosted the productivity of the office.
    What do you dislike about the product?
    Haven’t found anything yet to be upset about
    What problems is the product solving and how is that benefiting you?
    Protecting the business from malicious emails and improving productivity with Graymail.
    Gulsan P.

    Eliminates alert fatigue and automates phishing triage

    Reviewed on Aug 25, 2026
    Review provided by G2
    What do you like best about the product?
    Working in the SOC, dealing with the daily avalanche of user-reported suspicious emails used to be a massive time sink. Abnormal completely transformed this workflow. The AI Security Mailbox feature is incredible—it autonomously triages every user-reported email, categorizing them as malicious, spam, or safe. Instead of me manually extracting headers, firing up a Kali Linux VM to sandbox suspicious payloads, or running various penetration testing tools to validate a malicious link, the behavioral AI engine does the heavy lifting instantly. I also really appreciate the API-native deployment. We integrated it directly with our Microsoft 365 environment in minutes without having to mess with MX records or complex mail routing. Because it analyzes thousands of behavioral signals rather than just static threat signatures, it catches advanced Business Email Compromise (BEC) and vendor fraud that our legacy secure email gateway (SEG) consistently missed.
    What do you dislike about the product?
    While the behavioral AI is highly effective, it can occasionally feel like a "black box." When the system flags an internal email as anomalous or blocks a seemingly legitimate vendor communication, explaining the exact rationale to end-users can be tricky because the decision is based on complex behavioral deviations rather than a simple blocked IP address or malicious URL. Additionally, while the dashboard is clean, it could offer more customizable reporting widgets for the highly specific metrics our team needs to present during weekly security briefings.
    What problems is the product solving and how is that benefiting you?
    The primary problem it solves is the immense operational burden of manual email investigation. By automating the triage process and instantly removing malicious emails across all mailboxes (while also finding unreported emails in the same campaign), it frees up hours of my day. This allows our team to focus strictly on proactive threat hunting and complex identity threats instead of being buried in a queue of low-level phishing reports. It has drastically reduced our mean time to respond (MTTR) to email-based attacks.
    Krish P.

    Highly capable of mail security through an API, will search asynchronously, but there's a gotcha.

    Reviewed on Aug 21, 2026
    Review provided by G2
    What do you like best about the product?
    I'm a Cyber Security Engineer at a medium size financial services company. Our motive for using Abnormal Security is to defend our Microsoft 365 tenant against sophisticated phishing and Business Email Compromise (BEC) attacks, as well as vendor impersonation attacks, that our normal Secure Email Gateway (SEG) could not defend against. Our SOC team also uses its automated remediation capabilities to deal with the huge volume of emails that are reported to them with suspicious content.The best thing about Abnormal is the deployment itself is so simple. Since it integrates directly using Microsoft 365 APIs rather than needing intricate MX record modifications, it was up and running in our environment in just a matter of moments. The AI engine's ability to grasp the nuances of communication and To ensure the proper setting for what's considered the norm in employee performance is extremely precise. Commonly discovers highly advanced attacks and forgery of vendor invoices with no visible malicious links or attachments. Prior to Abnormal, at least half of a security analyst's day would be spent manually examining reported email or ramping through their inboxes, one by one. With the platform's auto-remediation, though, nearly all of that is done in the background, and that's a giant timesaver for our small team. It is indeed a high dollar solution to use Abnormal Security versus traditional email security, but for our team, the ROI has been 100% worth it. The per-mailbox pricing model seemed like a bit of an "up front investment" for a medium size user base. This combination of user-provided policy and the overwhelming number of engineering hours our SOC analysts put in taking care of user-reported phishing tickets weekly makes the platform self-funding not just in recovered productivity, but in recovered time. Most important of all, denying one costly vendor scam or bogus wire transfer message eradicates the entire yearly position. Automation and risk reduction are worth a lot for asecurity team faced with heavy workload and members who can't keep up with threats in their inbox all day.
    What do you dislike about the product?
    Abnormal works through the API (asynchronously, not within the mail flow itself as a traditional gateway would be) so scanning processes are not synchronous. This implies a malicious e-mail will appear in a user's inbox for a few seconds in between the AI system analyzing it and retriving it. There's a very fine margin for error if someone is focused on their inbox and presses the keys really rapidly. Also, there are instances when the system is a bit too strong in money related emails; it may mistake for example a genuine invoice or a message from a collaborator for ‘graymail' and perhaps even ‘potential threat'. Succumbing to these false positives takes some time as it isn't always readily possible to just whitelist a trusted domain without a bit of a hoop-jumping exercise.
    What problems is the product solving and how is that benefiting you?
    The danger of account takeover and targeted VIP spoofing was huge as our CEO would be involved in emergencies calls for wire transfers under fake names. Our previous gateway only protected on a threat signature basis and had no protection against text only attacks. But in Abnormal they realized that our executives really do write and communicate. It recently thwarted a dishonest vendor who asked our finance department to wire funds to another account for a bill worth hundreds of thousands of dollars. So, by automating the triage on our abuse mailbox and preventing these zero day social engineering attacks, it has cut our organisational risk even down to the next level and allowed us to direct our security team's efforts towards proactive threat hunting as opposed to copious amounts of email management.
    Kirpalsinh R.

    Fast API-based email security that drastically cuts down manual alert triage

    Reviewed on Aug 20, 2026
    Review provided by G2
    What do you like best about the product?
    As a SOC analyst, user-initiated phishing reports and account takeover detection take a lot of time to process, and I spend the whole shift looking at them. In my opinion, the most attractive feature of Abnormal AI is the speed of detection of Microsoft 365 account compromise compared to traditional secure email gateways. The software was installed via API for Microsoft 365 or Google Workspace, so it did not require much time and did not affect the mail delivery in any way. The dashboard named Threat Log allows me to get more information about the suspicious email activity, including details of the detected attack vectors, and the specific vendors involved in the incident. The automation of response to detected threats by removing the suspicious email from all the user’s inboxes or downing the compromised account significantly reduces the workload compared to using only PowerShell to remove the emails. Additionally, I find the ability to track all the user-initiated phishing reports and automatically reply to them helpful, as it saves a lot of time on ticketing and closing the incidents that do not require any further action.
    What do you dislike about the product?
    While I find the detection engine to be very accurate, the user interface may cause some frustration when dealing with multi-step queries. For example, when I am trying to sift through a ton of information in the threat logs, my selected filters do not carry over when I open up an alert and have to navigate back. This causes me to have to re-filter what I am looking at and slows down the overall process of incident response.
    What problems is the product solving and how is that benefiting you?
    It is mainly eliminating false positives through automated triage instead of spending hours on end checking them manually, which we had to do before without any success. It also helps by removing credential theft attempts and business email compromise by stopping targeted spear-phishing before it reaches the inbox, so our SOC team can concentrate on proactive threat hunting and not just responding to false positives.
    Sayed M.

    AI-Powered Email Protection with Minimal False Positives & Effective AI-Driven Phishing Protection

    Reviewed on Jul 02, 2026
    Review provided by G2
    What do you like best about the product?
    Abnormal Security stands out for its AI-powered detection of advanced phishing, business email compromise (BEC), and account takeover attacks. It provides highly accurate protection with minimal false positives, and it integrates smoothly with existing email platforms.
    What do you dislike about the product?
    Nothing as of now to share related to abnormal security products
    What problems is the product solving and how is that benefiting you?
    Abnormal Security helps stop phishing, business email compromise, and account takeover attacks before they ever reach users. This reduces security risk, cuts down on manual investigations, and improves overall efficiency in email security.
    Information Technology and Services

    Abnormal's AI-Driven Protection Reduces Manual Setup and Human Error

    Reviewed on Jul 01, 2026
    Review provided by G2
    What do you like best about the product?
    Abnormal provides AI driven protection which reduces the amount of manual configuration and potential human error
    What do you dislike about the product?
    There is a dependence on the AI being correct however it is possible to help align any mistakes
    What problems is the product solving and how is that benefiting you?
    Email security has become a major threat to most businesses, and Abnormal reduces the risks caused when employees make simple mistakes.
    Devender K.

    Innovative Company in Email Security

    Reviewed on Jun 30, 2026
    Review provided by G2
    What do you like best about the product?
    The most innovative company in email security.
    What do you dislike about the product?
    Sometimes feedback and implementation of requested features are slow. That can happen with an engineering-driven company focused on AI and ML, but it's not a dislike of their product.
    What problems is the product solving and how is that benefiting you?
    There was a lot of human intervention at each and every step of email security implementation. Abnormal Security resolved this through AI and ML support, helping to make quick decisions and reducing a great deal of time and manual investigation efforts across the implementation process.
    Health, Wellness and Fitness

    Abnormal's AI Delivers Fast, Powerful Automated Investigations

    Reviewed on Jun 30, 2026
    Review provided by G2
    What do you like best about the product?
    Abnormal has brought up considerable amount of AI in all of its products. This makes automated investigation extremely fast and powerful.
    What do you dislike about the product?
    Some automated features in Abnormal security lead to a large number of false positives and that's what I dislike the most
    What problems is the product solving and how is that benefiting you?
    Abnormal security has actually improved legitimate email communications and protection against impersonation has also become extremely powerful
    Transportation/Trucking/Railroad

    Reliable Added Protection Against Advanced Email Threats

    Reviewed on May 21, 2026
    Review provided by G2
    What do you like best about the product?
    It's an added layer or reliable protection against email threats.
    What do you dislike about the product?
    There's been quite a few incidents that got past the Abdormal contain and detection that was a big unnerving at times.
    What problems is the product solving and how is that benefiting you?
    It's helping us against advanced email and human‑targeted attacks.
    Pratyush D.

    Great UI/UX, Fast Website, and Really Good Answers

    Reviewed on May 19, 2026
    Review provided by G2
    What do you like best about the product?
    I think the UI/UX is great, especially considering what you’d expect from the newest technology. The website was fast and worked well overall. The answers were also really good.
    What do you dislike about the product?
    I haven’t been able to find it yet. I’ll keep looking through the other reviews and also check the website.
    What problems is the product solving and how is that benefiting you?
    I have used demo. Not the actual version.