Sublime Security is an AI-powered email security platform for Microsoft 365 and Google Workspace, priced from 76 dollars 20 cents per mailbox per year with a free tier covering 100 mailboxes (checked September 2026).
Listing updated . Checked by MSP Software .
Sublime Security is a programmable, AI-powered email security platform sold as a subscription per mailbox, starting at 76 dollars 20 cents per mailbox annually (checked September 2026). The platform integrates with Microsoft 365 and Google Workspace via API without requiring MX record changes or mail routing changes, and combines detection-as-code with transparent threat verdicts to block phishing, business email compromise, credential attacks, malware, email bombing and ransomware delivered via email. Sublime is detection-engineering-first rather than archiving-focused; it stores raw email for five years and structured data for 30 days, making it unsuitable as a primary backup or continuity solution for organisations requiring longer retention or recovery.
The platform suits MSPs and enterprises wanting transparent, rule-based detection with deep visibility into why emails were flagged, rather than black-box filtering that provides no explanation for its decisions. Transparent detection signals and investigation logs help security teams validate threats quickly and reduce false positives, which is crucial for overloaded security teams. Sublime users report that detection accuracy is strong out of the box with minimal tuning or false positive management, reducing the time spent refining rules after deployment. Threat hunting capabilities and user reporting integrate directly into the platform: employees who report suspicious emails receive feedback on the outcome and the detection logic, reinforcing security awareness without requiring a separate security awareness training platform. Programmable rules via Sublime Query Language allow custom detections for organisation-specific threats, regulatory requirements and email policies without vendor lock-in. Sublime integrates with security operations platforms including CrowdStrike Falcon, Panther SIEM and Elastic, plus dozens of others via webhook and API, making it suitable for organisations already running third-party threat response and security orchestration tools and wanting to add email detection without replacing existing infrastructure. The free tier covers up to 100 mailboxes with core protections including phishing and malware detection, enabling organisations to evaluate the platform risk-free before purchasing licenses.
Sublime stands out for transparent, programmable rules and lack of black-box filtering, which appeals to security teams that want to see detection logic. It is not primarily a continuity or archiving platform; for email backup and long-term retention beyond the five-year raw archive, pair it with a backup provider like Veeam Data Cloud or Datto SaaS Protection. Compare with Proofpoint and Mimecast on rule transparency and customisation depth. Evaluate the free tier on your own mailboxes before committing, and check that integration with your existing SIEM or SOAR is documented and matches your deployment model.
| Feature | Supported | Note |
|---|---|---|
| Phishing and malware filtering | yes | AI-powered detection with transparent verdicts; includes callback phishing and credential phishing |
| Spoofing and impersonation protection | yes | Spoofing and domain lookalike detection using DMARC, DKIM, SPF alignment and WHOIS registration data |
| Email continuity | no | Sublime is detection-focused; email recovery and continuity are not primary features |
| Archiving | yes | 30 day structured data retention plus 5 year raw EML retention; not a primary archiving platform |
| Security awareness training bundle | no | User reporting and feedback loop exist but no bundled security awareness training programme |
| API-based post-delivery scanning | yes | API-native integration with Microsoft 365 and Google Workspace; no mail routing required |
| DMARC monitoring | yes | DMARC, DKIM and SPF monitoring integrated into spoofing and impersonation detection |
| Attachment sandboxing | unknown | Not explicitly documented in available sources |
| Data loss prevention | yes | Sublime Email DLP protects against accidental or malicious data loss with configurable policies |
| Email encryption | unknown | Encryption mentioned in general email security best practices but not confirmed as Sublime feature |
| Microsoft 365 integration | yes | Native Microsoft 365 integration via API; multi-tenant and single-tenant deployment options |
| Self-service quarantine | unknown | User reporting functionality exists but self-service quarantine access not explicitly documented |
Sublime Security is priced from 76 dollars 20 cents per mailbox per year, billed annually, with a free tier for the first 100 mailboxes that includes core phishing and malware protection. This per-mailbox model differs from gateway-based email security products like Proofpoint and Mimecast, which typically charge per user and often require separate licensing for advanced features such as DMARC monitoring or DLP. Sublime's free tier lets organisations evaluate the platform on real mail before committing, and the transparent pricing appears on Sublime's website rather than quote-only, making cost comparison straightforward without needing to speak with a sales representative.
No, Sublime Security integrates via API with Microsoft 365 and Google Workspace without any MX record changes or mail routing redirection. This API-native approach means deployment takes minutes and does not interrupt existing email flow or require gateway hardware such as on-premises appliances. Organisations running Microsoft 365 or Google Workspace can enable Sublime by granting Global Admin consent to the Microsoft or Google application within their directory, making it faster to deploy than gateway-based competitors that require DNS and network changes.
Sublime Security uses transparent, programmable detection rules instead of black-box filtering, which means security teams can see exactly why an email was flagged and the investigation signals that triggered the decision. The platform is detection-engineering-first, allowing custom rules via Sublime Query Language without vendor lock-in to Sublime's proprietary rule engine. AI agents automate threat triage and investigation, showing verdicts with supporting signals, attack indicators and timelines so teams can validate findings quickly. User reports feed directly into detection improvement and remediation automation, creating a feedback loop where reported threats trigger organisation-wide cleanup and rule updates.
Sublime Security stores structured data for 30 days and raw email for five years, but it is not primarily an archiving, continuity or backup platform. Organisations needing long-term email recovery, backup for compliance or disaster recovery, and advanced archiving features should pair Sublime with a dedicated backup provider such as Veeam Data Cloud for Microsoft 365 or Datto SaaS Protection, while using Sublime for threat detection and response. This separation keeps costs down by letting each tool specialise in what it does best.
Sublime Security integrates with major SIEM and SOAR platforms including CrowdStrike Falcon, Panther, Elastic and dozens of others via API and custom webhooks that organisations can configure. Security teams can automate threat response across their existing tools by pushing enriched telemetry from email investigations and triggering playbooks in their security orchestration platform, without replacing existing security infrastructure or retraining teams on a new console. Sublime also offers an open API reference for building custom integrations to tools not listed in the integration directory, making it flexible for organisations with non-standard tooling.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review