Anti-spam and anti-virus, custom content filtering, imposter protection, URL defense including predictive analysis, attachment reputation and sandboxing, one-click message pull, outbound filtering, advanced business email compromise detection, and warning tags.
billed monthly
Phishing simulations without a cap, short hints and tips, campaigns that run themselves, a report button in the mail client, tracking of who replied, directory-driven targeting, sector benchmarking, a monthly exposure check, and social engineering indicators.
billed monthly
| Gateway filtering | Anti-spam, anti-virus, and custom content rules |
|---|---|
| Impersonation | Imposter email protection and advanced business email compromise detection |
| Link handling | URL defense with predictive analysis of links not yet known to be hostile |
| Attachments | Reputation scoring plus detonation of unknown files in a sandbox |
| Retraction | One-click message pull to remove delivered mail from every affected mailbox |
| Outbound | Outbound filtering, which is what stops a compromised account becoming your customers' problem |
| User signal | Warning tags on risky mail and a phish alert button that reports rather than deletes |
| Training | Phishing tests without a cap, self-running campaigns, tracking of replies, and benchmarking by sector |
| Directory | Active Directory integration for user and group targeting |
| Billing units | Gateway per mailbox; training per user |
Correlated is not the same as filtered
The Fortify-XDR tiers already read mail telemetry: verdicts, routing, and metadata feed the correlation engine so that a click and the process it spawned appear in one case. That is detection, and it is genuinely useful.
It is not the same as a control sitting inline, deciding whether the message is delivered at all. This family is that control. Buying the detection tier does not buy it, and we would rather say so on the page than let you discover it during an incident review.
What the inline control actually does
The gateway line covers the mechanics: spam and malware filtering, custom content rules, and outbound inspection. The parts that matter against a targeted attack are narrower and worth naming individually.
- Imposter and business email compromise detection. The invoice redirection and payroll change attacks carry no payload at all. There is nothing to scan, only a relationship and a tone to model.
- Predictive URL defense. Campaign infrastructure is frequently clean at the moment of delivery and weaponized minutes later. Judging a link on its properties rather than only its current reputation is what closes that window.
- Attachment sandboxing. Unknown files are detonated and observed rather than pattern-matched.
- One-click message pull. When something does land, the same message is removed from every mailbox that received it, in one action rather than eleven help desk tickets.
Simulation is a measurement instrument, not a punishment
The training line runs unlimited phishing simulations, automated campaigns, and benchmarking against organizations in your own sector. Used well, its output is a number that tells you which departments carry the most exposure and whether that figure is moving in the right direction.
The component we care about most is the smallest one: the phish alert button. It converts a user from a liability into a sensor. A reported message reaches the same operations desk that works your detection queue, and where the gateway line is also in place, one report can trigger a pull of that message from every other mailbox that got it. That is a user population shortening dwell time, which is a better outcome than a slightly improved click rate.
Where these modules stop
Neither line is mail backup or archiving. Message pull removes mail; it does not preserve it, and neither module protects you against a mailbox being deleted or a tenant being wiped. That is Microsoft 365 or Google Workspace backup, priced separately and for good reason.
The gateway line requires mail routing changes on your side and a short cutover window. Training requires that somebody in your organization owns the program: campaigns nobody reviews generate reports nobody reads, and the exposure number stops meaning anything.