What is our primary use case?
Proofpoint Email Protection is used for the email gateway for spam filtering, malware filtering, malicious email handling, and the secure email relay platform.
Proofpoint Email Protection has a different component called the TAP alert, which has two parts: malicious message defense and URL defense. This component is utilized to check if any URL delivered to users' mailboxes is legitimate or not based on the Proofpoint Email Protection TAP component. When a URL is received, Proofpoint checks it in their sandbox and attempts to execute those URLs. If there is anything malicious, Proofpoint informs us, and based on that, we can act by whitelisting or blacklisting depending upon the Proofpoint Email Protection component.
Proofpoint Email Protection is used with a secure email relay feature that has been purchased. Secure email relay allows external email relay using Proofpoint with authentication, ensuring that no malicious email or flood of spam reaches users' mailboxes.
When receiving lots of emails from a particular vendor or mailing list, quarantine and deliver is used. The mails are delivered, but the copy is quarantined. The quarantine mail in a quarantine folder is available for analysis, where message header analysis and source analysis can be performed, as well as hash checks against static and dynamic malware engines. This approach does not disturb users from getting the emails while also evaluating those emails if any kind of malicious emails are being generated and delivered to users' mailboxes. Quarantine is a great feature.
Proofpoint Email Protection has a smart send feature with an offensive word and dictionary feature. In the dictionary, you can stop the imposter attack to your organization for the VIP users.
What is most valuable?
Proofpoint Email Protection is a market leader for spam defense model and malicious email defense model. First of all, the Proofpoint Email Protection spam engine itself is mature enough to handle this. Apart from that, it provides a brick model where you have a policy route, where you have a condition and where you have the disposition. Based on the severity of the cases, you either need to quarantine, redirect, or reject. You have a quarantine folder where you can do the analysis. Proofpoint Email Protection is a quite well mature product where you will get everything as a security, cybersecurity, email security expert.
Proofpoint Email Protection has saved our infrastructure from any kind of malicious attack. By using its components such as TRAP (Threat Response Auto-Pull) and TAP (Targeted Attack Protection), we are also mitigating those attacks which get delivered to users' mailboxes without any delay. Proofpoint Email Protection is a great security tool that is not only proactive but also reactive on a case-to-case basis and provides all the mature tools that can be utilized for the first layer and second layer message defense.
Our response time has improved because we are using TRAP (Threat Response Auto-Pull), which pulls the emails from users' mailboxes if any malicious email gets delivered. It improved our time. Earlier it was a complete human activity. Now, it's a tool-based activity, and so there is less chance of human error. Proofpoint Email Protection is a human error-free malicious email defense system.
The workload to our SOC has been reduced when we implemented Threat Response Auto-Pull because they are now only focusing on other things. The false positive alerts are also reduced. TRAP and TAP are making a positive impact.
Proofpoint Email Protection is not a normal traditional email protection tool; what it does is know about blacklisted IPs, blacklisted emails, and the behavior of spam. But this is changing day in and day out. Proofpoint Email Protection provides real-time scanning of the mails and real-time scanning of the URLs. If anything is not declared as blacklisted or malicious, it does a sandbox analysis. Based on the sandbox analysis, it triggers an alert that indicates whether the mail may be legitimate or the mail has some malicious activity. TRAP is another tool, which triggers a pull to users' mailboxes. It creates complete user efficiency as a proactive and reactive tool which we achieve through it.
Our malicious response has improved by 90% when we are using the TAP and TRAP together.
What needs improvement?
Proofpoint Email Protection has a limitation regarding third-party tool integration and SIEM integration. Even though it provides a SIEM integration from Sentinel, the reporting is still being evaluated at admin.proofpoint.com where you are getting a nice report. However, if you are using a hosted infrastructure, reporting is also a lagging feature. Additionally, Proofpoint Email Protection is a rule-based system. For every kind of situation, you have to define a rule, and it will not be able to generate defense against generative AI alerts. Nowadays, hackers or spammers use generative AI, so it needs to become mature enough to handle those kinds of things, but Proofpoint Email Protection is working on that.
Modern security challenges, such as AI-related challenges, are areas where Proofpoint Email Protection needs to do better. If you think about rule-based challenges, Proofpoint Email Protection is doing well with its databases. However, if any threat is GenAI related, Proofpoint Email Protection needs to do much better there.
For how long have I used the solution?
I have been working in this current field for the last seven years.
What do I think about the stability of the solution?
Proofpoint Email Protection is a quite stable product, and if we need to add resources, we can add them because it's a Linux-based product.
What do I think about the scalability of the solution?
Proofpoint Email Protection is a scalable product. If you need to add resources, you can add them. It's an appliance, and somehow it is integrated with
Sentinel too. If you need to do any modifications, you need to call Proofpoint support. They join the call, and based on root access, we can modify.
How are customer service and support?
Proofpoint Email Protection supports are quite good. They have outstanding customer support. Whenever they join the call, the engineer knows what to do, what the problem is, and they fix it. They do not route tickets here and there. Their customer support is top-notch.
How was the initial setup?
Proofpoint Email Protection gives you a professional service experience when you choose to set up with Proofpoint engineers. They are quite good, and the licensing is competitive with the market. You need to raise a case with Proofpoint, and their engineer will join the call and will help you to set up each and every component.
What was our ROI?
There is a financial benefit because we are using a single pane of glass where we have all components. We know what capabilities our tools have and how they integrate with each other. Based on that, we subscribe to Proofpoint Email Protection services, which is not only saving money but also enhancing the capabilities of the tool when it works together.
What other advice do I have?
If you want a mature market leader spam and threat detection tool, Proofpoint Email Protection is without a doubt a market leader. I give this product a rating of 9 out of 10.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.