The invoice email has no link and no attachment. It just asks for a new bank account — Darktrace Email learns how your own staff and suppliers communicate and flags the phishing, fraud and account takeover that break the pattern, from outside the mail flow — Microsoft 365, Google Workspace, Exchange, Teams, Slack, Zoom and SharePoint.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Darktrace Email — the email product, with the separate DMARC SKU folded in. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
It learns how your organisation normally communicates and flags mail that breaks that pattern, even with no bad link.
What consolidation actually replaces, dimension by dimension.
| Dimension | A signature filter and user reports | Darktrace Email |
|---|---|---|
| How fraud is spotted | Signatures and sender reputation alone | Deviation from how your own people write |
| Deployment | An MX cut-over to a new gateway | API connectors and journaling, MX untouched |
| A hijacked mailbox | Noticed when customers complain | Flagged by Identity Protection in the same product |
| Links sent in chat | Outside the mail filter’s view | Teams, Slack, Zoom and SharePoint in scope |
| User training | A yearly course, unrelated to live attacks | Banners and simulations from the same vendor |
| What it is NOT | — | A gateway, an MX filter, or a published price |
The cheapest test is one tenant: connect by API with journaling, leave MX alone, and compare what it flags with what your users report.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Darktrace links to Microsoft 365, Google Workspace or Exchange through their APIs, so it reads messages and acts on them without ever becoming a hop in the delivery path.
A journal copy of mail is added to the API link, which Darktrace recommends: analysis gets every message while delivery carries on untouched, so no MX change is needed.
The hosted service runs on Azure or AWS in a region the customer chooses; Darktrace’s storage schedule keeps data in that region except as needed. None of the regions is in India.
For on-premises Exchange, the contract specification supplies the product on dedicated hardware, so that part of the deployment sits on your own site rather than in a Darktrace region.
API connectors and a journal feed outside the mail flow — analysis in an Azure or AWS region you pick, or on hardware for Exchange.
Darktrace Email judges each message against how your own organisation normally communicates — from outside the mail flow.
Adaptive AI builds a picture of how your people, partners and suppliers normally write, then scores every message against it.
A fake bank-change request or a CEO lookalike carries no link or file; behavioural scoring is aimed squarely at such requests.
Darktrace’s own case videos show it catching a spoofed Zoom invite, a Dropbox phishing scam and impersonation aimed at HR.
Identity Protection, one of the product’s listed capabilities, watches mailboxes and SaaS logins for signs an account is hijacked.
Email DLP is listed under DLP & Collaboration Tools, one of the four capability areas on Darktrace’s email product page.
Darktrace says it offers a unified quarantine with Defender for Office 365 and an email analysis agent for Security Copilot.
Coverage reaches past the inbox to Microsoft Teams, Slack, Zoom and SharePoint, where phishing links now turn up as well.
Adaptive Security Awareness Training assigns courses, shows just-in-time warning banners and runs phishing simulations.
The DMARC product is its own SKU, bought self-service on Azure Marketplace and hosted in one of four Azure regions.
A short 2026 spot for the product, then three Darktrace case videos from 2023 and 2024: a spoofed Zoom invite, impersonation aimed at HR, and a fake Dropbox share. All from Darktrace’s official channel.
A 30-second spot for the email product under its current 2026 branding.
Two minutes on a spoofed Zoom invitation and how the attack was stopped.
About three minutes on impersonation emails aimed at HR departments.
A short case study of a phishing email disguised as a Dropbox share.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Filters lean heavily on what the wider world has already seen. Darktrace Email models how your own staff, partners and suppliers usually communicate, so an odd payment request from a known supplier, or a first-time sender posing as the finance head, stands out even when there is no bad link.
It runs through API connectors plus a journaling feed, outside the delivery path, so MX records stay put and Microsoft 365 or Google filtering keeps working. On-premises Exchange is covered too, on dedicated hardware supplied under the contract, which keeps that part of the deployment on your own site.
Account takeover, email DLP, Teams, Slack, Zoom and SharePoint coverage, and awareness training all appear in the product’s own capability list, with DMARC as a sister SKU. Gartner placed Darktrace as a Leader for Email Security Platforms in 2025, up from Challenger in the 2024 first edition.
It is not a gateway: no MX filtering, outbound encryption or continuity, so a native or gateway filter stays in front. Pricing is quote-only, the DMARC price is not published, and whether awareness training is bundled has to be confirmed. No Darktrace hosting region is in India.
List tenants, Exchange servers and the Teams, Slack, Zoom and SharePoint workspaces in scope, and who owns each one.
Pick the Azure or AWS region for Email Cloud, note it in your DPDP register, and agree on API plus journaling.
Add the connectors and journal feed, leave MX alone, and give the model time to learn normal mail before judging alerts.
Compare flagged mail with user reports, agree which actions run on their own, and link quarantine to Defender if used.
Turn on awareness banners and simulations, then decide whether the separate DMARC SKU belongs in the contract.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We kept Defender as the filter and added Darktrace by API. A fake supplier bank-change request was caught in week two.”
“Journaling took an afternoon with our Exchange team, and nobody touched the MX record, which kept the change board calm.”
“A hijacked sales mailbox began sending invoices internally. Seeing the odd login beside the mail saved us hours.”
“Chat coverage mattered more than we expected; two phishing links last quarter arrived in Teams, not in email.”
“Auditors asked where mail data lives. The region is outside India, so we recorded it in our DPDP register up front.”
“Detection is strong, but the quote took three rounds and we still had to ask whether training was included.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the email security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only; a Gartner ESP Leader in 2025.
The grid nobody publishes — how many ways a product can be deployed against your mail vs how much it covers past the inbox: account takeover, chat apps, training and DMARC.
API, journaling or Exchange hardware; ATO, DLP, chat, training, DMARC SKU.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Abnormal Inbound Email Security, Proofpoint Email Protection, Mimecast Email Security, Check Point Harmony Email & Collaboration and Trend Vision One Email & Collaboration Security — on deployment, detection, account takeover, chat apps, training, DMARC, price and India.
| Dimension | Darktrace Email | Abnormal Inbound Email Security | Proofpoint Email Protection | Mimecast Email Security | Check Point Harmony Email & Collaboration | Trend Vision One Email & Collaboration Security |
|---|---|---|---|---|---|---|
| What it is | Behavioural email AI | Behavioural API layer | Gateway with intel depth | Gateway or API filter | API mail + collab suite | Vision One email layer |
| Deployment | API + journaling, no MX | API only, no MX change | Gateway, API, appliance | Cloud Gateway or API | API with inline prevent | Gateway or API |
| Mail platforms | M365, Google, Exchange | M365 and Google only | Any platform via MX | Any mail server via MX | M365 and Google | M365, Google and more |
| Detection approach | Learns your own normal | Identity behaviour model | Intel plus behaviour AI | AI/ML, URL and sandbox | AI plus sandboxing | Content, sender, intent |
| Account takeover | Identity Protection | Separate add-on | In Prime bundle | Not documented | Seen from inside | Not on TechBag’s page |
| Collaboration apps | Teams, Slack, Zoom, SPO | Slack, Teams, Zoom | Covered; check the SKU | Add-on SKU | Widest app list | Collab in Vision One |
| Gateway functions | Not a gateway | Augments, no SEG | Full gateway + DLP | Archive and continuity | Inline block, no MX | Gateway available |
| Awareness training | Listed; bundling unclear | None | Separate SKU | Engage, separate SKU | No awareness SKU | Phish Insight included |
| DMARC | Separate DMARC SKU | Not in the guide | Email Fraud Defense | DMARC Analyzer | No DMARC row | None listed |
| Pricing model | Quoted per estate | Per employee, yearly | Per user, tiered | Per user, S1–S3 | Per user, yearly | Per user or credits |
| Published entry price | Not published | ~$15–35/employee/yr | $2–5.86/user/month | ~$5–15/user/month | ~$15–40/user/year | ~$60/user/year |
| India data region | No India region | Not documented | India data centre | APAC is Singapore | India not documented | No India region listed |
| Lock-in and exit | Unplug the connectors | Revoke API access | MX cut-back to plan | Archive is the anchor | Disconnect the API | Tied to Vision One |
| Best fit | Behaviour-first estates | BEC-heavy cloud mail | India-resident gateway | Archive + gateway buyers | Collab-heavy tenants | Vision One estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Darktrace Email is one of 30 email security products TechBag carries. The Email Security guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (mailboxes you protect; analyst-hour cost). Estimates model the analyst time spent triaging user-reported mail, chasing impersonation attempts and cleaning up hijacked accounts, at an assumed 1.5 hours per mailbox a year, with 70% of it removed by behavioural detection and automated response. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Darktrace publishes no price for its email product and no rupee price; the AWS Marketplace public offer tiers ($30,000, $60,000 and $100,000 a year) are metered on network bandwidth and hosts, so they do not price mailboxes. The DMARC SKU is bought self-service on Azure Marketplace, but its price was not found. Whether Adaptive Security Awareness Training is bundled is not published. TechBag maps your mail and chat surfaces first, then gets the quote itemised in INR with GST.
Best for behavioural detection beside your filter
Best for a broader rollout
Best for getting your own domains to enforcement
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which platforms are in scope — Microsoft 365, Google Workspace, hybrid or on-premises Exchange — and who owns each?
What stays in front as the native filter or gateway? Darktrace Email sits beside it, never in its place.
Which Azure or AWS region will hold your mail data, and will your regulator accept a region outside India?
If Exchange runs on-premises, where will the dedicated hardware sit, and who patches and supports it?
Are Teams, Slack, Zoom and SharePoint in scope from day one, and does the quote name each of them?
Is Adaptive Security Awareness Training inside your quote or an extra line? Get the answer in writing.
Do you need the separate DMARC SKU, and does self-service buying on Azure Marketplace suit your procurement?
What count is the quote priced on, for what term, and with which features? Ask for INR with GST shown.
Map your mail tenants, Exchange servers and chat apps first, or let a TechBag advisor settle the hosting region with your compliance team and get the quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.