Mimecast review — email security & business continuity

last reviewed 24 march 2026
how we review

We start with direct ratings from our readers, then look at what real users are saying in practitioner forums and community spaces. We pair that with search demand data and profession-level persona analysis.

full methodology →

Editorial note: this was originally published in august of 2024

quick take

  • Best for: mid-to-large orgs needing email security, continuity, and archiving in one contract
  • Skip if: you're a small team without dedicated IT staff to handle false positive tuning
  • £Best value: Protect Plan for threat detection only; Protect Plus only if email continuity is a genuine business continuity requirement
½3.5/ 5 — editorial rating

based on real user feedback, community sentiment, pricing value, and fit for target audience. see our full methodology

used Mimecast? we'd love to know your thoughts

reader ratings shape our score

Mimecast is a cloud-based email security platform that combines threat protection, archiving, and email continuity into a single contract rather than requiring separate vendors for each function. CISO/Security Leaders and Compliance Officers in regulated industries get the clearest value from the compliance reporting and centralised visibility. The tradeoff is real: the security detection layer is solid, but the admin console is genuinely dated and the false positive burden means Security Administrators will spend meaningful time on maintenance, not just deployment.

Pricing isn't public, but Mimecast operates on annual contracts across three tiers: Protect (core AI-powered email security), Protect Plus (adds continuity and data protection), and a Custom Plan for archiving and DMARC management. It's available as a cloud service integrating with Microsoft 365 and Google Workspace. Before you sign, run a trial and track false positive volume in your environment, because that tuning cost will determine whether the total cost of ownership is actually justified versus a Microsoft-native alternative you may already be paying for.

how popular is Mimecast?

monthly search interest

40.5k/mo now

023.1k46.2k70k2023202420252026
peak interest61k/moMar 2023
searches now41k/moFeb 2026
1-month change18%vs prev month

Mimecast's search volume has been slowly declining since a 2022-2023 peak, with the drop more pronounced through late 2024 and into 2025. This pattern is typical of an established enterprise tool that's lost some ground to native platform security options, particularly Microsoft Defender, as organisations reassess what they're already paying for in their Microsoft 365 contracts. It's not a product in freefall, but the trajectory suggests you're evaluating a mature, stable product rather than a growing one.

who is Mimecast for?

Whether Mimecast is worth it depends heavily on your role and what part of the platform you'll actually own day-to-day. Pick your role below to see the honest breakdown.

overall sentiment

select your role to see what people like you are saying

CISO/Security Leader

positive

Mimecast gives you the compliance reporting and centralised email security visibility that regulated industries need, and the phishing and malware detection holds up. The cost is the sticking point: annual contracts aren't cheap, and you'll need to account for the admin overhead of false positive tuning when making the case to finance. If you're primarily buying for compliance coverage alongside threat protection, it justifies itself. If you just need threat detection, Microsoft Defender Plan 2 may already be partly paid for.

strengths

  • Strong phishing and malware detection with URL protection and attachment sandboxing
  • Comprehensive compliance reporting for GDPR, HIPAA, and regulatory requirements
  • Centralized visibility and control across organization's email security posture
  • Reliable integration with Microsoft 365 and Google Workspace

concerns

  • High total cost of ownership, difficult to justify for budget-conscious executives
  • Outdated admin console UI requires significant learning curve for team management
  • False positives and aggressive filtering create ongoing tuning burden

what users are saying

mimecast secure messaging is a pretty cheap add-on, but for internal messages it just sends an email with a 'secure messaging' footer, it doesn't actually send it to a secure portal.

Reddit r/mimecast

Online reviews of Mimecast are predominantly negative, sitting below 2 stars across dozens of reviews on commercial platforms. The most consistent criticism centres on customer service quality, billing disputes, and contract inflexibility rather than the security technology itself. On Reddit's r/mimecast, active administrators surface more specific frustrations: the awareness training system draws sharp criticism, with one thread describing the campaign management as near-unusable due to confusing retry logic when employees fail quizzes. A separate thread questions whether Mimecast's secure messaging feature actually does what it claims, noting that internal messages sent via the add-on remain fully visible in standard Outlook clients rather than routing to a secure portal. Users who've installed the product on managed laptops also raise privacy concerns in the subreddit about what data the agent collects. The false positive rate is a recurring theme across all sources: legitimate emails getting quarantined creates a steady drip of support tickets that IT teams didn't budget for.

Our take: Mimecast's core email security technology is genuinely solid, and for a mid-to-large organisation running Microsoft 365 or Google Workspace, the phishing detection and email continuity features hold up under scrutiny. But you're paying a premium for an admin console that hasn't kept up, a support experience that community feedback consistently flags as poor, and add-on features like secure messaging that don't quite deliver what the name implies. If you're evaluating alternatives, Proofpoint covers the same threat protection territory with a more polished enterprise admin experience, and Microsoft Defender for Office 365 Plan 2 is worth benchmarking on cost if you're already in the Microsoft stack. Don't sign the contract until you've stress-tested the false positive rate in a trial, because tuning it will become a part-time job.

features

  • Advanced Email Security: Protects organizations from email threats including phishing, malware, ransomware, and business email compromise using AI-powered detection engines, machine learning, and real-time scanning of links and attachments.
  • DMARC Analyzer: Provides email impersonation protection by analyzing and managing DMARC policies to prevent attackers from spoofing your domain.
  • Web Protection: Blocks malicious websites, monitors cloud applications, and provides browser isolation to prevent phishing and malware attacks across network and off-network environments.
  • Data Loss Prevention: Implements predefined templates and policies to secure sensitive information through content control, encryption, and compliance management.
  • Security Awareness Training: Delivers targeted employee training modules to reduce human risk and improve threat recognition through short lessons and simulated phishing tests.
  • Mimecast Administration Console: Offers centralized policy configuration, real-time reporting, and dashboard analytics for managing security across email, web, and collaboration channels.
  • Email Continuity and Archiving: Ensures uninterrupted email access during system outages and simplifies compliance through cloud-based archiving solutions.
  • Threat Intelligence: Uses insights from billions of daily signals to identify and block emerging threats before they reach your organization.

pricing

  • Protect Plan focuses on AI-powered email security with features like AI-enhanced detections, social graphing, and phishing protection.
  • Protect Plus Plan enhances email security with additional features such as email continuity and data protection.
  • Custom Plan provides protection for communications, people, and data, with options for DMARC management and cloud archiving.
  • Exact pricing details are not publicly listed and require direct contact with Mimecast sales representatives for customized quotes based on organizational needs and scale.

frequently asked questions

It depends which tier you're on and how large your organisation is. The Protect Plan covers AI-powered phishing and malware detection, which is the core reason most teams buy it, and that layer works well enough to justify the cost for organisations with 200+ users who face regular phishing attempts. The Protect Plus Plan adds email continuity, which is only worth the uplift if email downtime is genuinely a business-critical risk for you. Exact pricing isn't public, but enterprise-level contracts are typically annual and non-trivial to exit, so treat it as a multi-year commitment, not a monthly SaaS subscription.

Security Administrators and IT Managers at mid-to-large organisations who need consolidated email threat protection, archiving, and continuity in one platform. CISO/Security Leaders in regulated industries get the most out of the compliance reporting and visibility features. It's a poor fit for small teams without dedicated IT staff to manage the false positive tuning and admin console learning curve.

Two stand out. First, the false positive rate: legitimate emails get quarantined regularly, and keeping the whitelist maintained is an ongoing time cost that's easy to underestimate. Second, the admin console is genuinely outdated and unintuitive, meaning routine policy changes take longer than they should. The mobile app is also weak if out-of-office email management matters to your IT team. Some add-on features, like secure messaging, have implementation gaps that make them less useful than advertised.

Proofpoint is the stronger choice if your primary concern is a polished admin experience and enterprise-grade threat intelligence with a mature support model. Mimecast wins if you need email continuity and archiving bundled into the same contract alongside security, rather than managing separate vendors. For Microsoft-heavy organisations, Microsoft Defender for Office 365 Plan 2 is worth a serious cost comparison before committing to either: native integration removes a layer of friction, and the licensing may already be partly included in your M365 agreement.

Yes, this comes up consistently. The scanning process introduces noticeable delays, particularly on attachments going through sandboxing. For most organisations it's measured in seconds, not minutes, but users in time-sensitive roles will notice and raise tickets. It's worth flagging this expectation internally before rollout rather than treating it as a configuration problem to fix after complaints start.

tools for
humans

toolsforhumans editorial team

Reader ratings and community feedback shape every score. Since 2022, ToolsForHumans has helped 600,000+ people find software that holds up after launch. how we research →

other tools to check out

Box screenshot
online buzz550k
trend (1M)steady
3.5based on real user feedback, community sentiment, pricing value, and fit for target audience. see our full methodology

Box

Box is a cloud-native content management platform that enables secure storage, collaboration, and content management. It offers features including security controls, AI-driven insights, workflow automation, and integrations across business applications. With scalable solutions for individuals, teams, and enterprises, Box helps organizations manage, share, and protect their digital content.

best deal

Try Box free with 10GB storage or get 30% off Enterprise plans when billed annually

Barracuda screenshot
online buzz165k
trend (1M)steady
3.5based on real user feedback, community sentiment, pricing value, and fit for target audience. see our full methodology

Barracuda

Barracuda Networks is a cybersecurity company founded in 2003, offering AI-powered solutions for email, network, and data protection through its BarracudaONE platform. The product suite includes email gateway defense, web security, firewalls, cloud backup services, and managed XDR with multimodal AI threat detection.

best deal

Free trials available for email protection and other products

PimEyes screenshot
online buzz165k
trend (1M)18%
3.5based on real user feedback, community sentiment, pricing value, and fit for target audience. see our full methodology

PimEyes

PimEyes is an advanced online facial recognition search engine that uses AI to perform reverse image searches across publicly accessible websites. It helps users monitor their digital presence, find instances of their face online, and provides tools for privacy protection, including image removal assistance and alert systems. Available through various subscription plans, PimEyes searches an index of 3.5 billion photographic images and focuses specifically on facial features rather than entire images.

best deal

Get 25% off annual plans: PROtect for $26.24/month or Advanced for $224.99/month

FaceCheck.ID screenshot
online buzz41k
trend (1M)18%
3.0based on real user feedback, community sentiment, pricing value, and fit for target audience. see our full methodology

FaceCheck.ID

FaceCheck.ID is an AI-powered facial recognition search engine that allows users to upload a photo to find matching faces across social media, news sites, blogs, mugshot databases, sex offender registries, and criminal news for identity verification and safety checks. The platform scans over 763 million public images and returns results in seconds with confidence scores and source links.

best deal

Try FaceCheck.ID free with basic search, or start with 36 credits for just $6

Vanta screenshot
online buzz33k
trend (1M)18%
3.8based on real user feedback, community sentiment, pricing value, and fit for target audience. see our full methodology

Vanta

Vanta is a compliance and security platform that automates up to 90% of compliance work for major security frameworks like SOC 2 and ISO 27001. It offers automated evidence collection, policy management, access control, and AI-powered tools to help businesses streamline compliance processes, strengthen security, and build stakeholder trust.

best deal

Free trial available with no credit card required. Core plan starts at $7,500 annually.

LogicGate screenshot
online buzz22k
trend (1M)steady
3.5based on real user feedback, community sentiment, pricing value, and fit for target audience. see our full methodology

LogicGate

LogicGate is an AI-powered Governance, Risk, and Compliance (GRC) platform offering the Risk Cloud solution. The platform helps organizations manage cyber risk, third-party risk, compliance controls, and operational resilience through a no-code interface with built-in Spark AI features that automate evidence testing, form completion, and risk analysis.

best deal

Get started with Risk Cloud from $13,765/year and automate your compliance process with AI-powered features