Back to main siteBack Contact us
Abnormal Email Security

Abnormal Security

Email Security

Where it sits in your mail flow

Abnormal does not stand in front of your mail. It connects to Microsoft 365 or Google Workspace through the API, learns what normal communication looks like for every person and supplier you deal with, and acts on messages that do not fit, including ones already delivered.

GATEWAY MODEL Internet Gateway Mailbox Sees mail once, on the way past API MODEL Internet Mailbox Behavioural model identity, context, content Pull a delivered message back See internal mail, not just inbound
The problem with one layer

Why current controls miss the expensive attacks

Filtering technology is good at messages carrying something bad. The costly attacks carry nothing bad at all.

No payload

A plain request, well written

A business email compromise message has no attachment, no link and no malware. It is a short note asking for an urgent transfer or a change of bank details. There is nothing for a scanner to find because nothing was hidden.

Real sender

The supplier's account, genuinely

Vendor compromise means the mail comes from the real account, through the real domain, passing every authentication check. Reputation and domain checks all vote yes, and they are not wrong.

Inside the tenant

Internal mail a gateway never sees

Once an account is taken over, the attacker emails colleagues from inside. That traffic never crosses the perimeter, so a product positioned at the perimeter has no view of it.

How it works

What happens between connection and first catch

The mechanism matters here, because it explains both the strength and the limitation.

01

Connect through the API, not the MX record

Integration is an authorisation rather than a mail routing change. Abnormal states this takes around thirty minutes and requires no MX change or policy migration. The practical consequence is that a trial is genuinely reversible, which is rare in this category.

02

Build a baseline of normal communication

The platform models who each person actually corresponds with, from where, in what tone, about what, and which suppliers send which kinds of request. This history is what later makes an unusual message stand out despite being technically clean.

03

Judge identity, context and content together

A message is assessed on all three at once: whether the sender is behaving like themselves, whether the request fits the relationship, and what the language is actually asking for. Any one signal alone produces false positives; the combination is what keeps them down.

04

Remove what is already delivered

Because it operates inside the mailbox rather than in front of it, the platform can withdraw a message after delivery and remediate a whole campaign across every recipient at once. That is the capability a gateway structurally cannot offer.

Coverage across the surface

What it watches beyond the inbox

The same behavioural approach is applied to the accounts themselves and to the collaboration tools attached to them.

AreaWhat it looks for
Inbound emailImpersonation, fraudulent requests, credential phishing without a payload
Internal emailLateral phishing sent from a colleague's compromised account
Supplier relationshipsRequests that break the established pattern with a known vendor
Account takeoverSign-in and mailbox-rule behaviour that indicates a hijacked account
Reported messagesTriage of what users report, with the verdict sent back to them
Honest qualification

Where this is worth the second licence

This sits on top of Microsoft or Google protection rather than replacing it, so you are paying for both. That is the decision to make clearly.

A strong fit

Organizations that move money or handle supplier payment details: finance, construction, legal, logistics, anyone paying invoices on terms. The attacks this catches are the ones that end in a wire transfer rather than an encrypted server.

A weaker fit

A small organization with few external relationships and no payment authority worth stealing faces a different threat mix. If nobody at your company can move money on an email, the case for a second email product is much weaker, and the money is better spent on identity controls.

What to check first

Ask what your Microsoft licence already includes, because parts of the higher tiers overlap. Then ask for a trial measured on your own mail: since the integration is API based and reversible, there is little excuse for buying this on a demonstration alone.

In short

Test it on your own mail before deciding

The useful first question is simple: in the last year, how many messages reached someone here asking for a payment or a change of bank details, and what stopped them. That answer usually settles whether this layer is worth adding.

Get in touch with Your Company

Questions about this solution? Reach us directly.