# Sublime Security

> Email security via API with programmable rules, per mailbox, for Microsoft 365 and Google Workspace.

Sublime Security is an AI-powered email security platform for Microsoft 365 and Google Workspace, priced from 76 dollars 20 cents per mailbox per year with a free tier covering 100 mailboxes (checked September 2026). Listing updated 6 September 2026. Checked by MSP Software 5 September 2026.

- Page: https://mspsoftware.net/software/sublime-security
- Vendor: Sublime Security, https://mspsoftware.net/vendors/sublime-security, website https://sublime.security/
- Categories: Email security (primary)
- Free trial: yes. Free version: yes.
- Deployment: cloud. Platforms: web. HQ: United States. Founded: 2019.
- Support: email, knowledge base and community. Training: documentation and webinars.

## From the vendor

Sublime Security is a programmable, AI-powered email security platform sold as a subscription per mailbox, starting at 76 dollars 20 cents per mailbox annually (checked September 2026). The platform integrates with Microsoft 365 and Google Workspace via API without requiring MX record changes or mail routing changes, and combines detection-as-code with transparent threat verdicts to block phishing, business email compromise, credential attacks, malware, email bombing and ransomware delivered via email. Sublime is detection-engineering-first rather than archiving-focused; it stores raw email for five years and structured data for 30 days, making it unsuitable as a primary backup or continuity solution for organisations requiring longer retention or recovery. The platform suits MSPs and enterprises wanting transparent, rule-based detection with deep visibility into why emails were flagged, rather than black-box filtering that provides no explanation for its decisions. Transparent detection signals and investigation logs help security teams validate threats quickly and reduce false positives, which is crucial for overloaded security teams. Sublime users report that detection accuracy is strong out of the box with minimal tuning or false positive management, reducing the time spent refining rules after deployment. Threat hunting capabilities and user reporting integrate directly into the platform: employees who report suspicious emails receive feedback on the outcome and the detection logic, reinforcing security awareness without requiring a separate security awareness training platform. Programmable rules via Sublime Query Language allow custom detections for organisation-specific threats, regulatory requirements and email policies without vendor lock-in. Sublime integrates with security operations platforms including CrowdStrike Falcon, Panther SIEM and Elastic, plus dozens of others via webhook and API, making it suitable for organisations already running third-party threat response and security orchestration tools and wanting to add email detection without replacing existing infrastructure. The free tier covers up to 100 mailboxes with core protections including phishing and malware detection, enabling organisations to evaluate the platform risk-free before purchasing licenses.

## Our take

Sublime stands out for transparent, programmable rules and lack of black-box filtering, which appeals to security teams that want to see detection logic. It is not primarily a continuity or archiving platform; for email backup and long-term retention beyond the five-year raw archive, pair it with a backup provider like Veeam Data Cloud or Datto SaaS Protection. Compare with Proofpoint and Mimecast on rule transparency and customisation depth. Evaluate the free tier on your own mailboxes before committing, and check that integration with your existing SIEM or SOAR is documented and matches your deployment model.

## Pricing

Sublime Security starts at US$76.20 per mailbox per year, according to the vendor (pricing page: https://sublime.security/plans/).

## Features

| Feature | Supported | Note |
| --- | --- | --- |
| Phishing and malware filtering | yes | AI-powered detection with transparent verdicts; includes callback phishing and credential phishing |
| Spoofing and impersonation protection | yes | Spoofing and domain lookalike detection using DMARC, DKIM, SPF alignment and WHOIS registration data |
| Email continuity | no | Sublime is detection-focused; email recovery and continuity are not primary features |
| Archiving | yes | 30 day structured data retention plus 5 year raw EML retention; not a primary archiving platform |
| Security awareness training bundle | no | User reporting and feedback loop exist but no bundled security awareness training programme |
| API-based post-delivery scanning | yes | API-native integration with Microsoft 365 and Google Workspace; no mail routing required |
| DMARC monitoring | yes | DMARC, DKIM and SPF monitoring integrated into spoofing and impersonation detection |
| Data loss prevention | yes | Sublime Email DLP protects against accidental or malicious data loss with configurable policies |
| Microsoft 365 integration | yes | Native Microsoft 365 integration via API; multi-tenant and single-tenant deployment options |

## Integrations

- Microsoft 365, https://mspsoftware.net/software/microsoft-entra-id
- Google Workspace, https://docs.sublime.security/docs/google-workspace-deployment-model
- CrowdStrike Falcon, https://mspsoftware.net/software/crowdstrike-falcon
- Panther SIEM, https://panther.com/integrations/sublime-security
- Elastic, https://www.elastic.co/docs/reference/integrations/sublime_security

## Alternatives

- Check Point Email Security: API-based email and collaboration security from Avanan, quoted through Check Point partners. https://mspsoftware.net/software/avanan. Compare: https://mspsoftware.net/compare/avanan-vs-sublime-security
- Material Security: Email and workspace security for Microsoft 365 and Google, priced from $4 per user monthly. https://mspsoftware.net/software/material-security. Compare: https://mspsoftware.net/compare/material-security-vs-sublime-security
- Vade: AI email security for Microsoft 365 with bundled contextual security awareness training. https://mspsoftware.net/software/vade. Compare: https://mspsoftware.net/compare/sublime-security-vs-vade
- Barracuda Email Protection: Cloud email security, archiving and awareness training bundled into three tiers, priced by quote only. https://mspsoftware.net/software/barracuda-email-protection. Compare: https://mspsoftware.net/compare/barracuda-email-protection-vs-sublime-security

## FAQ

### How much does Sublime Security cost?

Sublime Security starts at US$76.20 per mailbox per year, according to the vendor, checked September 2026.

### Does Sublime Security offer a free trial?

Sublime Security offers a free trial. There is a genuinely free version.

### What does Sublime Security integrate with?

Sublime Security lists integrations with Microsoft 365, Google Workspace, CrowdStrike Falcon, Panther SIEM and Elastic.

### Is Sublime Security cloud or on-premises?

Sublime Security is cloud-hosted; there is no on-premises version.

### Who is Sublime Security for?

MSPs report using Sublime Security at sizes of 6-15, 16-50, 51-200 and 200+ technicians.

### How is Sublime Security priced compared with traditional email security gateways?

Sublime Security is priced from 76 dollars 20 cents per mailbox per year, billed annually, with a free tier for the first 100 mailboxes that includes core phishing and malware protection. This per-mailbox model differs from gateway-based email security products like Proofpoint and Mimecast, which typically charge per user and often require separate licensing for advanced features such as DMARC monitoring or DLP. Sublime's free tier lets organisations evaluate the platform on real mail before committing, and the transparent pricing appears on Sublime's website rather than quote-only, making cost comparison straightforward without needing to speak with a sales representative.

### Does Sublime Security require MX record changes or mail routing?

No, Sublime Security integrates via API with Microsoft 365 and Google Workspace without any MX record changes or mail routing redirection. This API-native approach means deployment takes minutes and does not interrupt existing email flow or require gateway hardware such as on-premises appliances. Organisations running Microsoft 365 or Google Workspace can enable Sublime by granting Global Admin consent to the Microsoft or Google application within their directory, making it faster to deploy than gateway-based competitors that require DNS and network changes.

### What makes Sublime Security different from traditional email security?

Sublime Security uses transparent, programmable detection rules instead of black-box filtering, which means security teams can see exactly why an email was flagged and the investigation signals that triggered the decision. The platform is detection-engineering-first, allowing custom rules via Sublime Query Language without vendor lock-in to Sublime's proprietary rule engine. AI agents automate threat triage and investigation, showing verdicts with supporting signals, attack indicators and timelines so teams can validate findings quickly. User reports feed directly into detection improvement and remediation automation, creating a feedback loop where reported threats trigger organisation-wide cleanup and rule updates.

### Can Sublime Security archive email long-term or replace email backup?

Sublime Security stores structured data for 30 days and raw email for five years, but it is not primarily an archiving, continuity or backup platform. Organisations needing long-term email recovery, backup for compliance or disaster recovery, and advanced archiving features should pair Sublime with a dedicated backup provider such as Veeam Data Cloud for Microsoft 365 or Datto SaaS Protection, while using Sublime for threat detection and response. This separation keeps costs down by letting each tool specialise in what it does best.

### Which integrations does Sublime Security support for threat response?

Sublime Security integrates with major SIEM and SOAR platforms including CrowdStrike Falcon, Panther, Elastic and dozens of others via API and custom webhooks that organisations can configure. Security teams can automate threat response across their existing tools by pushing enriched telemetry from email investigations and triggering playbooks in their security orchestration platform, without replacing existing security infrastructure or retraining teams on a new console. Sublime also offers an open API reference for building custom integrations to tools not listed in the integration directory, making it flexible for organisations with non-standard tooling.