What is our primary use case?
My main use case for Proofpoint Email Protection is working as an anti-spam and phishing analyst, where I need to protect the organization and public users from spam and phishing.
In my daily work, I use Proofpoint Email Protection based on ML models that score each email based on sender reputation, IP reputations, and certain AI ML technologies, allowing us to decide whether an email is phishing, spam, or legitimate.
While Proofpoint is better, I find Abnormal to be much more effective because it uses an advanced AI engine to detect email spams and phishing. In Proofpoint, we observe a false positive rate of ten percent, where out of one thousand users, ten users will be improperly scored, causing their emails to move into spam or junk while occasionally, junk emails mistakenly reach the inbox.
What is most valuable?
The best features that Proofpoint Email Protection offers include its excellent reputation engines, as their IP reputation and PDR reputation are among the best I have encountered due to the daily feeds into their system protecting us from spam and phishing emails from bad IPs and domains.
The specific benefit of those reputation engines in protecting my organization is their capability against zero-day attacks; Proofpoint has an advanced technique that retrieves emails even after they reach the inbox, regardless of whether the user opens them.
I have witnessed a positive impact of Proofpoint Email Protection on my organization, having worked for one of the world's largest organizations that uses Proofpoint consistently for email security.
Most of the time, it removes phishing and spam from email inboxes, but in rare cases, some emails may reach user inboxes. Nevertheless, we can retrieve them using one of the Proofpoint modules.
What needs improvement?
I believe Proofpoint Email Protection can be improved; currently, it does not allow organizations to create their own IP listings, so whatever comes into Proofpoint is what helps to remove spam and phishing, and organizations should be allowed to tune Proofpoint Email Protection engine.
I chose eight out of ten because the remaining two points are for their AI detection, which is way behind and needs improvement; they need to collaborate with AI providers to fine-tune their reputations with the help of AI.
For how long have I used the solution?
I have been using Proofpoint Email Protection for six years.
What do I think about the stability of the solution?
Proofpoint Email Protection is stable.
What do I think about the scalability of the solution?
I rate Proofpoint Email Protection's scalability a ten out of ten.
How are customer service and support?
The customer support is one of the best I have experienced.
I rate the customer support a nine on a scale of one to ten.
Which solution did I use previously and why did I switch?
Before Proofpoint, we solely relied on our internal spam filter. We chose Proofpoint because it is the number one email security provider, although compared to Abnormal, it is less efficient; however, its cost is lower.
What was our ROI?
I have seen a return on investment with Proofpoint Email Protection; it handles most processes independently while only requiring employee rotation for fine-tuning.
Which other solutions did I evaluate?
Before choosing Proofpoint Email Protection, we evaluated O365 spam filter.
What other advice do I have?
Proofpoint Email Protection has affected my SOC analyst workloads because we have built our own internal spam engine that catches what is missed by Proofpoint, though Proofpoint helps us most of the time.
Proofpoint Email Protection provides a good level of visibility into people-based risk within my organization, as it scores emails effectively, but occasionally scores abnormally, so we can raise FN cases with Proofpoint.
I have noticed significant changes in operational efficiency after implementing Proofpoint Email Protection, as it can handle lakhs of emails in a day.
My experience with the Unified Admin Console in Threat Protection Workbench has been beneficial because it helps us release quarantined emails immediately, rescoring them, and we can use those in a whitelist for further processing. The unified UI is effective, especially since they recently improved it, making it easier to find emails and the user list.
My advice for others looking into using Proofpoint Email Protection is to not aggressively score the emails initially; let the ML learn, as it takes around six months to understand the email flow before scoring correctly.
I suggest exploring Abnormal, which is a bit costlier but currently the best solution in the market.
I would rate my overall experience with Proofpoint Email Protection as an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.