Skip to content
Draft. This page is in editorial review and is not indexed yet.

Cybersecurity Operations

Email Security: from Spam Filters to AI agents

Email security moved from hand-tuned spam filters and on-prem gateways to cloud gateways, then to API-based behavioral AI that reads relationships instead of signatures. Since 2024, agents from Microsoft, Sublime and Abnormal triage user-reported phishing and remediate whole campaigns, while analysts approve the consequential calls. Next comes verifiable sender identity.

Verified Updated Oct 9, 2026By Deepak Gupta
3.2

Autonomy level

3.2 of 5 · Agents with approvals

launch score

Projected 4.2 by 2031

Tasks automated
3.2
Approval load
3.0
Production maturity
3.4

Overall is the mean of the three sub-scores. How scores work

Autonomy by era: On-prem 0.5, SaaS and cloud 1.2, AI-assisted 2.0, Agentic 3.2, Next 5 years 4.2.

The same job, five eras

Drag across the eras to see who did the work, with what, and what broke.

Era 1 · 1996-2007

On-prem

0.5
Who did the work
A mail administrator or two owned the filter and the appliance, tuning rules and clearing the quarantine by hand. Security was a side duty, not a team.
Tools
Apache SpamAssassinIronPort appliancesBarracuda Spam FirewallPostiniDNS blocklists (RBLs)
Representative product
Apache SpamAssassin
What broke
Rules and signatures only stopped attacks someone had already catalogued. False positives buried real customer mail in quarantine.

Autonomy 0.5/5 · Manual

Era 2 · 2007-2018

SaaS and cloud

1.2
Who did the work
A messaging or security engineer managed the gateway policy, the quarantine and the allow lists. User-reported phishing landed in a shared abuse mailbox that an analyst worked through manually.
Tools
Proofpoint Email ProtectionMimecast Secure Email GatewayGoogle PostiniExchange Online ProtectionOffice 365 ATP
Representative product
Proofpoint Email Protection
What broke
MX rerouting made every gateway change a mail-flow risk. Payload-free BEC messages passed reputation and sandbox checks.

Autonomy 1.2/5 · Tool-assisted

Era 3 · 2018-2023

AI-assisted

2.0
Who did the work
Security operations owned email, with analysts triaging flagged messages and user reports and a separate awareness function running simulations. Mail admins handled authentication records.
Tools
Abnormal SecurityMaterial SecuritySublime SecurityMicrosoft Defender for Office 365Proofpoint TAP and TRAP
Representative product
Abnormal Security
What broke
ML flagged suspicious mail but an analyst still made every call. User reports grew faster than the team that reviewed them.

Autonomy 2.0/5 · Copilot

Era 4 · 2024-2026

The Agentic Shift

3.2
Who did the work
Analysts stop working the abuse mailbox message by message and start reviewing agent verdicts, tuning feedback, and handling true positives. Detection engineers approve agent-written rules instead of writing every one.
Tools
Microsoft Security Copilot Phishing Triage AgentSublime ASA and ADÉAbnormal AI Security MailboxProofpoint Satori AgentsMaterial Security
Representative product
Microsoft Security Copilot Phishing Triage Agent
What broke
Agent verdicts on true positives still wait for an analyst. Agents need privileged, scoped identities that most teams have never governed.

Autonomy 3.2/5 · Agents with approvals

Era 5 · 2027-2031

Next 5 years

4.2
Who did the work
A small team supervises triage agents, owns sender authentication and payment-verification policy, and governs the agents that read and act on mail. Awareness work shifts from spotting typos to verifying requests.
Tools
Autonomous triage and remediation agentsSigned sender and payment verificationAgent identity and scope governancePrompt-injection inspection for inbox assistants
Representative product
Autonomous triage and remediation agents
What broke
AI-written lures remove the spelling and tone cues people were trained on. Deepfake voice and video break the call-back check.

Autonomy 4.2/5 · Exception-only

What job does email security software do?

Email security exists to make sure the message in front of an employee is what it claims to be, and to pull it back fast when it is not. That covers spam, malware, credential phishing, and the expensive one: business email compromise, where a polite message with no link and no attachment asks finance to change a bank account. The FBI's 2024 IC3 report put reported BEC losses at about $2.77 billion for that year alone, and the CEO fraud pattern still works because it targets people, not software.

The second half of the job is cleanup. Every company tells staff to report suspicious mail, and every security team then drowns in those reports. Most of them are harmless. I still point people to the basics in my guide to spotting phishing scams, but the volume problem is what the agentic era is actually solving.

Era 1 · Before SaaS · 1996-2007

How did email security work before SaaS?

Verified

Email security started as a spam problem. Mail admins ran filters on their own servers: Apache SpamAssassin, first released in April 2001, scored each message with hundreds of hand-written rules, DNS blocklists, and later a Bayesian classifier. If the score crossed a threshold, the message went to a junk folder.

As volume grew, the filter moved into a box. IronPort, Barracuda and others sold appliances that sat in front of Exchange or Lotus Notes, checked sender reputation, ran antivirus signatures, and dropped or quarantined mail before it reached the server. Cisco bought IronPort for $830 million in 2007, which tells you how central the gateway had become.

What broke was the model itself. Rules and signatures only caught what someone had already seen. Spammers rotated domains and wording faster than admins could write rules, and nothing in SMTP proved who actually sent a message. SPF in 2006 and DKIM in 2007 were the first attempts to fix that, and adoption was thin for years.

  1. SpamAssassin first released by Justin Masonsource
  2. SPF published as experimental RFC 4408source
  3. Cisco agrees to acquire IronPort for $830 millionsource

Era 2 · The Cloud Move · 2007-2018

What changed when email security moved to the cloud?

Verified

The gateway moved to the cloud. Postini already filtered mail as a hosted service, and Google bought it in 2007 for $625 million. Mimecast and Proofpoint built cloud secure email gateways: you pointed your MX records at them, and every message passed through their data centers before reaching your mailbox.

When companies moved to Office 365 and Google Workspace, Microsoft added its own layer. Exchange Online Advanced Threat Protection, announced in 2015, brought sandboxed attachments and click-time link checks to the mailbox itself. DMARC, published as RFC 7489 the same year, finally let a domain owner tell receivers what to do with mail that failed SPF or DKIM.

The attackers adapted. Malware got detonated in sandboxes, so they sent clean messages instead: a fake invoice, a wire request from the "CEO", a credential page hosted on a trusted cloud service. The gateway saw a well-formed email from a domain with decent reputation and let it through. When an account did get taken over, the damage spread from inside the tenant, which is why my checklist for a hacked email account starts with sessions and forwarding rules, not passwords alone.

  1. Google agrees to buy Postini for $625 millionsource
  2. DMARC published as RFC 7489source
  3. Microsoft announces Exchange Online Advanced Threat Protectionsource

Era 3 · The Copilot Years · 2018-2023

What did AI copilots change in email security?

Verified

The next shift was where the product sat. Instead of rerouting mail, a new wave of vendors connected to Microsoft 365 and Google Workspace through APIs and read mail after delivery. Abnormal, Material and Sublime built baselines of who normally talks to whom, how a vendor usually writes, and what a normal payment request looks like, then flagged the message that broke the pattern.

This caught what gateways missed: the payload-free BEC email, the compromised vendor account, the internal account sending odd requests. Because the products sat inside the tenant, they could also pull a message back out of every inbox after the fact. The category got a name, integrated cloud email security, and the incumbents consolidated: Thoma Bravo took Proofpoint private for $12.3 billion in 2021 and Permira bought Mimecast for $5.8 billion in 2022.

Machine learning still scored and suggested; people still decided. Analysts reviewed the flagged queue, worked the abuse mailbox, and ran awareness training on a quarterly calendar. I wrote about building a phishing defense framework in this period, and the hard part was always the human queue, not the filter. Then Google and Yahoo moved authentication from good practice to requirement: from February 2024, bulk senders to Gmail needed authentication, one-click unsubscribe and a low spam rate.

  1. Thoma Bravo completes $12.3 billion Proofpoint acquisitionsource
  2. Permira completes $5.8 billion Mimecast acquisitionsource
  3. Google announces bulk sender authentication rules for Gmailsource

Era 4 · The Agentic Shift · 2024-2026

The Agentic Shift: What do AI agents do in email security today?

Verified

The agentic era started in the abuse mailbox, because that is where the toil was. Abnormal's AI Security Mailbox, announced in May 2024, judges every user-reported email, bulk-removes the unreported copies from the same campaign, and replies to the employee with a verdict. Microsoft's Phishing Triage Agent in Defender, announced in March 2025 and now generally available, runs when a user reports a message, detonates files and links, classifies the alert, and closes false positives on its own. Microsoft says each report could take an analyst up to 30 minutes.

Sublime Security went furthest on autonomy. Its Autonomous Security Analyst (ASA) investigates reported and flagged messages, usually within about a minute, and in Autonomous Mode applies whatever remediation you configured per verdict. Its Autonomous Detection Engineer (ADÉ) writes and backtests new detections, then submits them for analyst approval. Proofpoint announced Satori Agents, including an Abuse Mailbox Agent, with phased availability from 2026.

The limits are real and the vendors say so. Microsoft's agent resolves false positives but leaves true positives open for an analyst. Sublime ships ASA inactive and recommends a week or two in a passive mode first, and unknown verdicts always go to a human. The agents also need identities: Microsoft's setup wizard creates an Entra Agent ID with scoped read permissions. That is the point I keep making in AI agents don't have passwords: an agent that can quarantine mail across a tenant is a privileged identity and needs to be governed like one.

One more change: email is now an attack path into AI assistants. Proofpoint and others warn that prompts hidden in email can steer a copilot that reads the inbox, and Material now sells guardrails that keep agents away from password resets and magic links.

  1. Abnormal launches AI Security Mailbox for autonomous report triagesource
  2. Microsoft announces Security Copilot Phishing Triage Agentsource
  3. Sublime releases Autonomous Security Analyst (ASA)sourcebeing verified
  4. Sublime announces Autonomous Detection Engineer (ADÉ)source
  5. Proofpoint announces Satori Agents, including an Abuse Mailbox Agentsource
  6. DMARC moves to the IETF Standards Track as RFC 9989source

Era 5 · The Next Five Years · 2027-2031

What will email security look like by 2031?

Verified

My bet: by 2031, agents handle user-reported and flagged mail end to end at most mid-size and large companies, and the analyst's job is reviewing exceptions and the agents themselves. Triage is already mostly solved. The open problem is that AI makes a convincing lure free to produce, in any language, in the voice of your actual CFO.

That pushes the industry from "does this look like phishing" to "can this sender prove who they are". DMARC on the Standards Track is a start for domains, but the bigger shift is verifiable identity on the request itself: signed payment instructions, out-of-band confirmation that an agent can trigger, and provenance for voice and video. The $25 million deepfake case is the warning: once a video call can be faked, an email "confirmed on a call" proves nothing.

The second shift is that many emails will be written and read by agents, not people. Email security then has to inspect machine-to-machine requests, block instructions hidden in mail aimed at assistants, and check that the agent acting on a message had the scope to do so. Mimecast's Agent Risk Center, planned for general availability in January 2027, is an early sign of that convergence.

My prediction · by 2031 · medium confidence

By 2031, agents will resolve most user-reported and flagged email end to end at mid-size and large companies, and the main control against phishing will shift from detecting suspicious content to verifying sender and request identity.

What has to be true

  • Triage agents keep false negative rates low enough that teams move from passive to autonomous modes
  • Agent identities get standard scoping and audit across Microsoft, Google and third-party tools
  • DMARC enforcement and signed payment or request verification become routine, not exceptional
  • Defenses against prompt injection in email mature before inbox assistants get write access to business systems

Projected autonomy 4.2 of 5

  1. Mimecast Agent Risk Center GA planned for Incydr customerssource

Then vs now: who does each step?

The job broken into its steps, and who or what does each one in each era.

Who or what does each step of Email Security, by era
Job stepOn-premSaaS and cloudAI-assistedAgenticNext 5 years
Block known spam and malwareRules, blocklists and signatures on a server or applianceCloud gateway with reputation and sandboxingGateway plus ML scoringAutomated by default; agents handle what slips throughFully automated, invisible to staff
Catch BEC and impersonationNot addressedDisplay-name rules and VIP listsBehavioral AI flags unusual sender relationshipsBehavioral AI blocks; agents investigate the borderline casesSigned sender identity and verified payment requests
Triage user-reported phishingRare; forwarded to the mail adminAnalyst works the abuse mailbox by handAnalyst with ML hints and playbooksAgent classifies and closes false positives; analyst confirms threatsAgent resolves end to end; analyst reviews exceptions
Remove a campaign from every inboxNot possible after deliveryAdmin runs a manual search and purgeOne-click retroactive pull from the consoleAgent removes unreported copies automatically per policyAutomatic, with an audit trail per action
Write new detectionsAdmin writes filter rulesVendor threat team ships updatesDetection engineer writes custom rulesAgent drafts and backtests rules; engineer approvesAgent ships low-risk detections; engineer reviews broad ones
Tell the reporter what happenedUsually nobody didTemplate email, days laterTemplate email from an automationAgent replies with the verdict and answers follow-upsAgent coaches in context, inside the mail client
Train staff on phishingAnnual slide deckQuarterly simulations from templatesRisk-scored simulation programsAgents build simulations from real blocked attacksTraining focuses on verifying requests, not spotting typos

How does the email security team change?

The abuse mailbox analyst is the role that changes most. For a decade that job meant opening each reported message, checking headers and links, and answering the reporter. Agents now do that work in about a minute, so the analyst's queue shrinks to true positives, unknown verdicts and agent mistakes.

The work that grows is supervision and governance: deciding which verdicts an agent may act on, writing feedback that teaches it local context, approving agent-written detections, and treating each agent as a privileged identity with scopes and an audit trail. That matches the operating model I describe in the CISO's AI defense playbook: automate the volume, keep humans on consequential decisions.

Roles that shrink

  • Abuse mailbox analyst triaging reports one by one
  • Quarantine reviewer releasing false positives
  • Rule writer maintaining filter and allow lists by hand
  • Template-driven phishing simulation administrator

Roles that appear

  • Email agent supervisor who sets autonomy levels per verdict
  • Detection reviewer who approves agent-written rules
  • Agent identity owner who governs scopes and audit for security agents
  • Payment and sender verification policy owner

Skills to learn

  • Reading and challenging an agent's reasoning trail
  • Writing precise feedback that agents turn into lessons
  • Least-privilege design for non-human identities
  • DMARC, SPF and DKIM enforcement across sending services
  • Prompt-injection awareness for inbox AI assistants

What gets easier for the humans?

BeforeAfter
An analyst spends up to 30 minutes on each user-reported email, most of them harmlessAn agent classifies the report in minutes and closes false positives with a written rationale
One employee reports a phish while the same campaign sits unreported in hundreds of inboxesThe agent removes every copy from the same campaign once one report confirms it
Reporters hear nothing back and stop reportingThe reporter gets a verdict and can ask follow-up questions by reply
A new attack pattern waits weeks for a hand-written detectionAn agent drafts and backtests the detection; an engineer approves it the same day
Phishing simulations reuse generic templates nobody falls forSimulations are built from attacks the company actually received

Decisions that stay human

  • Approving a change to bank details or any payment instruction
  • Deciding what an email agent is allowed to delete, quarantine or release
  • Handling a confirmed executive or vendor account compromise
  • Contacting customers, partners or regulators after a breach
  • Rejecting agent feedback that would teach it the wrong lesson

Where should agents not act alone?

Risks and failure modes, through a security and identity lens.

  1. 01

    Over-scoped agent identities

    A triage agent that can read and purge mail tenant-wide is one of the most privileged identities you own. Give it a dedicated agent identity, least-privilege roles, and an owner, and never run it under a shared admin account.

  2. 02

    Prompt injection through the message under review

    The agent reads attacker-controlled text by definition. Hidden instructions in an email can try to talk an LLM-based classifier into a benign verdict or steer an inbox assistant. Treat message content as untrusted input and keep verdicts tied to tool evidence, not just model judgment.

  3. 03

    Silent false negatives

    Auto-closing a report as a false positive removes the human who might have noticed. Sample closed verdicts every week, and route unknown or low-confidence results to an analyst by default.

  4. 04

    Poisoned feedback

    Agents that learn from analyst feedback can be taught a bad rule, such as trusting a sender domain an attacker controls. Restrict who can teach the agent, review lessons, and keep the feedback log auditable.

  5. 05

    Missing audit trail

    Every quarantine, deletion and release an agent makes needs to be logged with the identity, the evidence and the policy that allowed it. Without that, you cannot explain an outage of legitimate mail or prove control to an auditor.

  6. 06

    Payments approved on an email alone

    No agent should approve or release a payment change because a message passed authentication. Compromised real accounts pass SPF, DKIM and DMARC. Bank detail changes need out-of-band human verification.

Who is building agentic email security?

Incumbents adding agents vs agent-native entrants. Capability lines are checked against each vendor's own site.

Incumbents

  • Security Copilot Phishing Triage Agent classifies user-reported phishing, resolves false positives itself, and leaves true positives open for analysts, running under a scoped Entra Agent ID.

    Checked Oct 9, 2026Compare

  • Announced Satori Agents, including an Abuse Mailbox Agent for user-reported email, with phased availability beginning in 2026, plus detection of AI exploits delivered by email.

    Checked Oct 9, 2026Compare

  • Announced Managed Threat Response, pairing AI-driven triage with analyst-confirmed remediation, and Agent Risk Center in beta for discovering and governing AI agents.

    Checked Oct 9, 2026Compare

Agent-native

  • AI Security Mailbox triages user-reported phishing, bulk-remediates unreported copies of the campaign, and replies to the reporter; AI Phishing Coach builds simulations from blocked attacks.

    Checked Oct 9, 2026Compare

  • ASA investigates reported and flagged messages and, in Autonomous Mode, applies the remediation configured per verdict; ADÉ drafts and backtests detections for analyst approval.

    Checked Oct 9, 2026

  • API-based protection for Google Workspace and Microsoft 365 that automates the threat lifecycle from user report through remediation, with guardrails that keep AI agents away from sensitive mail.

    Checked Oct 9, 2026Compare

Open source

  • MIT-licensed detection, hunting and DLP rules in Message Query Language; no agent features on their own, but the rule format ADÉ writes into.

    Checked Oct 9, 2026

  • No agent features. Rule, blocklist and Bayesian scoring that still runs on many self-hosted mail servers.

    Checked Oct 9, 2026

Side-by-side comparisons: Top 5 Email Security Platforms of 2026.

Questions people ask

How is AI changing email security?

It moved detection from signatures to behavior, and now it is taking over cleanup. Behavioral AI flags messages that break normal sender patterns, and agents from Microsoft, Sublime and Abnormal triage user-reported phishing, remove matching campaign emails, and reply to reporters, with analysts approving the consequential calls.

Will AI agents replace SOC analysts who handle phishing?

They replace the repetitive part, not the role. Agents now classify most reported emails and close false positives. Analysts still handle confirmed threats, account compromises, unknown verdicts, and the governance of the agents themselves, including what each agent may delete or release.

What is a phishing triage agent?

An AI agent that investigates a reported or suspicious email the way an analyst would: it inspects headers, detonates links and attachments, checks threat intelligence, then issues a verdict with its reasoning. Depending on policy, it closes the alert, remediates the message, or escalates to a human.

Do I still need a secure email gateway if I use API-based email security?

Many companies now run native Microsoft or Google filtering plus an API-based layer instead of a separate gateway. A gateway still makes sense when you need pre-delivery policy controls, encryption or archiving from one vendor. Compare the trade-offs in our email security platform comparison.

Can AI-generated phishing get past email security?

AI removes the spelling and tone mistakes people were trained to notice, so content-based checks matter less. Behavioral tools still catch unusual sender relationships and requests. The durable fix is verifying identity: enforced DMARC for domains and out-of-band confirmation for payment or credential requests.

What did the Google and Yahoo 2024 sender requirements change?

From February 2024, Gmail required senders of more than 5,000 messages a day to authenticate their mail, offer one-click unsubscribe, and keep spam complaints low. It turned SPF, DKIM and DMARC from good practice into a delivery requirement for bulk senders.

Is it safe to let an AI agent delete emails automatically?

Only with guardrails. Start the agent in a passive mode and compare its verdicts with analysts, give it a dedicated identity with least-privilege scopes, log every action, and send unknown or low-confidence verdicts to a human. Never let it release or act on payment requests alone.

Sources

  1. Apache SpamAssassin (Wikipedia), accessed Oct 9, 2026
  2. RFC 4408: Sender Policy Framework, accessed Oct 9, 2026
  3. RFC 4871: DomainKeys Identified Mail (DKIM) Signatures, accessed Oct 9, 2026
  4. Cisco announces agreement to acquire IronPort, accessed Oct 9, 2026
  5. Google to Buy Security Firm Postini for $625M (eWeek), accessed Oct 9, 2026
  6. Exchange Online Advanced Threat Protection (Redmond Magazine), accessed Oct 9, 2026
  7. RFC 7489: DMARC, accessed Oct 9, 2026
  8. Thoma Bravo Completes Acquisition of Proofpoint, accessed Oct 9, 2026
  9. Permira Completes Acquisition of Mimecast (SEC Exhibit 99.1), accessed Oct 9, 2026
  10. New Gmail protections for a safer, less spammy inbox (Google), accessed Oct 9, 2026
  11. FBI Internet Crime Complaint Center 2024 Report, accessed Oct 9, 2026
  12. AI Security Mailbox (Abnormal), accessed Oct 9, 2026
  13. Abnormal AI announces AI agents and comprehensive email security, accessed Oct 9, 2026
  14. Microsoft unveils Microsoft Security Copilot agents and new protections for AI, accessed Oct 9, 2026
  15. Microsoft Security Copilot Phishing Triage Agent in Microsoft Defender (Microsoft Learn), accessed Oct 9, 2026
  16. ASA: Autonomous Security Analyst (Sublime docs), accessed Oct 9, 2026
  17. Sublime Security enhances threat protection with AI agent (Help Net Security), accessed Oct 9, 2026
  18. Sublime secures $150M to advance agentic email protection (BankInfoSecurity), accessed Oct 9, 2026
  19. Proofpoint Secures Collaboration and Data in the Agentic Workspace, accessed Oct 9, 2026
  20. Material Security email security, accessed Oct 9, 2026
  21. Material Security: Create email guardrails for AI agents, accessed Oct 9, 2026
  22. Mimecast Unveils Agent Risk Center and Managed Threat Response at Black Hat 2026, accessed Oct 9, 2026
  23. RFC 9989: DMARC (IETF Datatracker), accessed Oct 9, 2026
  24. sublime-security/sublime-rules (GitHub), accessed Oct 9, 2026

Published Oct 9, 2026. Last verified Oct 9, 2026. Eras 4 and 5, vendors, and scores are re-checked every six to eight weeks; see the changelog and methodology.