We use Sophos Email for various solutions, setting it up for different customer environments as part of our strategy.
L1 System Engineer at a tech services company with 11-50 employees
Offers good log features but challenges with compatibility, management, and reporting
Pros and Cons
- "The best thing about it is the logs."
- "There have been some issues with compatibility and effectiveness, particularly when integrating it with our firewall. The main challenge has been email protection, especially due to compatibility issues and difficulties with log access and email relay configuration."
What is our primary use case?
What is most valuable?
The best thing about it is the logs.
What needs improvement?
There have been some issues with compatibility and effectiveness, particularly when integrating it with our firewall. The main challenge has been email protection, especially due to compatibility issues and difficulties with log access and email relay configuration.
I would like to see more detailed logs in the future releases. The firewall logs don't show the in-depth logs, so we can only see the software in detail, not the logs themselves. This is a problem we've been facing in customer environments for some time.
Emails go to spam even though there's no legitimate reason for them to be there. There's no summary of the necessary issues, either.
If an email goes to spam, the system will drop it. There should be a certificate email on the query, but support comes and goes, and they might see learning and run the Linux command or show the unrigorous answers.
But if there is some read-only show on the reporting or clear reporting, it would be good for the customers.
For how long have I used the solution?
We use Sophos Email Protection. We've deployed it in various scenarios, either on-premises or using Sophos Cloud Email Protection.
Buyer's Guide
Sophos Email
May 2025

Learn what your peers think about Sophos Email. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Considering our experience with firewall integration, I'd rate it a five out of ten. I haven't used the cloud solution extensively to comment on that aspect.
The rating reflects the challenges we've faced. These different appliances have more limitations, like reporting limitations. They don't have good reporting, and it's not a good solution.
If there's another issue, we have to go to the CLI and change something to embroider the other issue, which is spam.
If we go and prepare the spam, it gets stuck, and there's no option to understand it on the GUI. There is an option to go to the CLI and run the script. There's a predefined script. There are a lot of things.
How was the initial setup?
The initial configuration isn't difficult, but managing permissions there are some issues. We've encountered issues where some emails are incorrectly flagged or missed, which complicates management.
We're using the on-premises version of Sophos Email Protection. We haven't utilized cloud email protection. Our focus has been primarily on integrating it with the firewall.
What's my experience with pricing, setup cost, and licensing?
There are different price tiers for different customer sizes. I sell the bundle, which includes all the licenses, web protection, and other features.
Which other solutions did I evaluate?
The customers who are using email servers are not using anything else. Most of our new users moved to a better solution, like Fortinet email or other solutions, but they didn't want to move. For the new users, it's combined and deployed by themselves.
What other advice do I have?
It's best to take the POC from the so-called official, test it thoroughly, and then make a decision. If it's compatible with the environment and works well, then keep the POC successfully.
Overall, I would rate the solution a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:

Senior Technical Support Engineer at Capricot
Robust cybersecurity with advanced attachment and link filtering and affordable fixed pricing
Pros and Cons
- "The most significant aspect is the response filtering concerning attachments and links."
- "The main drawback is regarding the technical support."
What is our primary use case?
Our client specifically opted for it to address attachment-related concerns in both inbound and outbound email traffic. The primary focus lies in leveraging it for scanning and filtering attachments to enhance security measures. The choice is driven by the need for robust link protection, ensuring comprehensive inbound and outbound protection against potential threats associated with email links.
What is most valuable?
The most significant aspect is the response filtering concerning attachments and links.
What needs improvement?
The main drawback is regarding the technical support. Unfortunately, we may not receive immediate assistance, and the resolution process might extend beyond a week. Internal filtering is an additional feature that should be incorporated. I would appreciate having the option for spam blocking.
For how long have I used the solution?
I have been working with it for approximately four years.
What do I think about the stability of the solution?
I would rate its stability capabilities eight out of ten.
What do I think about the scalability of the solution?
Scalability is an area that could be enhanced, particularly in terms of technical aspects related to server maintenance. We lack control over certain aspects, such as policy management and updates, and we do not receive training for these functionalities. I would rate it eight out of ten.
How are customer service and support?
The technical support services should be improved. I would rate it six out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup was relatively straightforward. I would rate it eight out of ten.
What about the implementation team?
Deployment process is managing proposal related.
What's my experience with pricing, setup cost, and licensing?
The pricing is quite reasonable, with a fixed cost and no additional charges. I would rate it four out of ten.
What other advice do I have?
Overall, I would rate it nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
Buyer's Guide
Sophos Email
May 2025

Learn what your peers think about Sophos Email. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
Information Technology Project Support at Coastal Qatar
Reliable email filtration features, but it needs to update safeguards against phishing
Pros and Cons
- "I found the user interface friendly."
- "The solution has not found a way to block certain kinds of phishing emails."
What is our primary use case?
We use Sophos Email for use cases involving email security, but there are many policies which we have defined. Like, let's say, like, spamming emails which we have defined and encryptions email which we have defined. Filtering emails we have defined, and there are many more.
What is most valuable?
I especially like the filtration. We are filtering what emails need to go out. I also found the user interface friendly.
What needs improvement?
Phishing email is evolving. Sometimes we use tools to send an email. Some companies are using those tools to send an email keeping the face of another company to make it look like that email came from the same person. The solution has not found a way to block these kinds of emails.
For how long have I used the solution?
It's been almost four years that we have continuously worked with it. We use the latest version of the solution because it's on a subscription, that way we always get the updated version.
What do I think about the stability of the solution?
The solution’s stability is good.
What do I think about the scalability of the solution?
The solution has good scalability because I haven't seen any problem which has lasted more than three days.
How are customer service and support?
Maintenance is through on-call support. Whenever we face issues, we raise a complaint to the service provider. They have their own level of support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used to use Symantec. Compared to Symantec, Sophos was giving better facilities and better solutions.
How was the initial setup?
The initial setup is not difficult. The solution takes up to 48 hours to deploy, and up to a week to define all the policies and test them.
What about the implementation team?
We used a third-party integrator to deploy the solution. There was one staff member from our side, and the third-party integrator had three people.
What's my experience with pricing, setup cost, and licensing?
Sophos Email is neither cheap nor expensive. It’s affordable, especially for a company like ours.
Which other solutions did I evaluate?
We found Palo Alto was a bit expensive compared to Sophos. That was the reason we started with Sophos.
What other advice do I have?
I rate Sophos Email a seven to eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Has a good user interface, but its DLP features need enhancement
Pros and Cons
- "It has enhanced our approach to tackling malware and spam. It is a reliable product with a good user interface."
- "Sophos Email could improve DLP features."
What is most valuable?
The product provides valuable performance.
What needs improvement?
Sophos Email could improve DLP features.
What do I think about the stability of the solution?
The platform is stable. However, they could provide more updates to streamline the product. I rate the stability as seven out of ten.
What do I think about the scalability of the solution?
We have 50 Sophos Email users in our organization. It has good scalability.
How are customer service and support?
The technical support team could be faster, more knowledgeable, and more customer-friendly.
Which solution did I use previously and why did I switch?
We are using multiple products as system integrators.
How was the initial setup?
The deployment steps involve simply downloading and executing the links, as it's a cloud-based solution. It requires one engineer to handle the maintenance.
What's my experience with pricing, setup cost, and licensing?
The platform is inexpensive. It offers a cost-effective licensing model. We purchase its yearly license.
What other advice do I have?
We utilize Sophos Email Gateway to protect against phishing in our company. Following the standard recommendation provided by Sophos, we established connectivity between Sophos Email Gateway and Microsoft 365.
It has enhanced our approach to tackling malware and spam. It is a reliable product with a good user interface.
The integration capabilities still need improvement, as some functionalities are not operating properly. Specifically, attention needs to be given to AD integration capabilities, which are crucial for various operations.
I rate it a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
System Integrator IT Manager at Tecnimex S.r.l.
Easily integrates into our cloud platform and simplifies backend management
Pros and Cons
- "I find the comprehensive features of Sophos Email most valuable."
- "I would like to see improvements in the initial setup process, ensuring better compatibility with diverse customer infrastructures."
What is our primary use case?
I use Sophos Email as part of our corporate cybersecurity solution to protect our servers, both on-premises and in the cloud, including Microsoft 365 servers.
What is most valuable?
I find the comprehensive features of Sophos Email most valuable. The system easily integrates into our cloud platform and simplifies backend management.
What needs improvement?
I would like to see improvements in the initial setup process, ensuring better compatibility with diverse customer infrastructures. Additionally, in the next release, it would be valuable to have enhanced features for seamless interaction with customer infrastructure, making the setup more user-friendly and efficient.
For how long have I used the solution?
I have been working with Sophos Email for two years.
What do I think about the stability of the solution?
The stability of the solution is good. I would rate it as a ten out of ten.
What do I think about the scalability of the solution?
I would rate the scalability as a nine out of ten. We have around five customers currently using Sophos Email, with a total user count exceeding 100.
How are customer service and support?
Sophos offers technical support, and while it is generally responsive, the speed can vary as it involves opening a ticket and waiting for assistance. Sophos provides a dedicated response team for faster support, but this service may come with an additional cost depending on the customer's plan. Overall, I would rate the support as a nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
Although the setup can be a bit challenging, it is crucial to conduct thorough testing due to the complex environment. I recommend thorough training before use to maximize its effectiveness. The deployment of Sophos Gmail typically takes around a couple of hours, depending on the complexity of the customer's infrastructure. The process involves investigating the customer environment, testing for interoperability, and setting up on the Cloud Platform or on-premises. It is relatively straightforward for a single server, but for cloud environments, careful evaluation of the products involved is necessary. After setup, additional time is spent testing and verifying the system to ensure a smooth operation.
What about the implementation team?
What's my experience with pricing, setup cost, and licensing?
Clients can opt for yearly or monthly payment plans. Recently, Sophos introduced some interesting solutions, especially for those acting as MSPs or resellers with a flexible model. While Sophos provides options through its cloud marketplace, it is often better to rely on another reseller for technical support.
What other advice do I have?
I would recommend Sophos Email. My advice for those starting to use it is to prepare for training and not hesitate to engage with it. The initial phase might seem challenging, but training is key for a smooth transition. Don't be afraid of the learning process; embrace it for better consolidation with the platform. Overall, I would rate Sophos Email as a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
IT- Manager. at a retailer with 51-200 employees
A strong appliance with excellent filtering and an easy setup
Pros and Cons
- "The speed and stability were fine."
- "The solution should be able to support the cloud environment."
What is our primary use case?
We primarily used the solution as an email gateway, for filtering.
What is most valuable?
It was a really good appliance. It filtered most of the spam and junk emails and quarantined them. It was working fine for us.
The speed and stability were fine.
It had good features.
The initial setup was very simple.
What needs improvement?
We didn't have any issues with the solution. It was a good appliance.
The solution should be able to support the cloud environment.
Sometimes, if there is any ransom email or mails are queued, it will take little time to deliver.
For how long have I used the solution?
We used the solution for almost eight or nine years. It was a good appliance. The last time we used it was six to eight months back.
What do I think about the stability of the solution?
The solution was stable and reliable. There are no bugs or glitches, and we never had trouble with it after eight or nine years.
How are customer service and support?
We are closely in touch with our local partners, and our local principals for Sophos. They are also very supportive.
Which solution did I use previously and why did I switch?
Initially, we had an on-premise exchange server. That time, we were using Sophos. After migrating to Office 365, currently, we don't have anything. We are exploring, and we are doing a POC with Antigena, Mimecast, Defender, and then Sophos Email Labs.
How was the initial setup?
The initial setup was very easy.
What's my experience with pricing, setup cost, and licensing?
This is a licensed product.
What other advice do I have?
I'm a customer.
We have decommissioned the solution completely.
We did not change Sophos to a new product. We migrated on-premise email to Office 365.
I'd want people to know this is a good product. I'd recommend it.
I'd rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Pre-sales manager at National Information Technology Company
Effective on-premises and cloud, beneficial sandboxing, and advanced AI detection
Pros and Cons
- "When you say email security, it's about everything, incoming email, outgoing email, spam, phishing emails, unwanted marketing emails. You can set rules, but the main feature of Sophos Email is to make sure you don't get hacked. 95% of people who are hacked do not get hacked by typing the router password. They are hacked from the inside out, which means they send you a document that is a zero-day attack, you open it, nothing happens, but technically the attack is running in the background of your computer. This is how they gain access to your PC."
What is our primary use case?
We can use Sophos Email for securing incoming and outgoing emails. Whether your email server is on-premise or on the cloud, you can use Sophos email security to protect your mailboxes from spam, phishing, zero-day attack, such as if somebody sends an email with an attachment that anti-virus cannot detect. For example, today, I can send you a PDF that has inside a virus, and you cannot detect it through the anti-virus. What Sophos Email security does is filters and classifies those emails by using AI in a sandbox. The email comes to Sophos Email security platform first, it opens the email, runs the attachment, and sees the behavior. If normal, the email is passed. If the email has a zero-day attack, and it senses that the PDF is doing something to Windows or Linux, it quarantines and notifies the administrator.
It's the optimal solution for people who needs to secure their email, whether they have on-premise or on the cloud email server, SophosEmail security can be used.
What is most valuable?
When you say email security, it's about everything, incoming email, outgoing email, spam, phishing emails, unwanted marketing emails. You can set rules, but the main feature of Sophos Email is to make sure you don't get hacked. 95% of people who are hacked do not get hacked by typing the router password. They are hacked from the inside out, which means they send you a document that is a zero-day attack, you open it, nothing happens, but technically the attack is running in the background of your computer. This is how they gain access to your PC.
This solution has artificial intelligence. It means it doesn't depend only on the normal definition. It reads the algorithm and analyzes it, so it's something very advanced than other vendors.
Sophos Email is accurate and fast. It does block stealth attacks ransomware if you receive a file, which is hidden. For us, we can see it's a very good solution compared with others.
Overall the solution is easy for management and easy to use in general. It has all the tools, such as active protection for your organization's needs.
The main requirement of this solution is for email security and protection. The settings are easy, very secure, and simple GUI to manage.
For how long have I used the solution?
I have been using Sophos Email for approximately five years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is highly scalable. You can subscribe for 100, 500, 1000, as many as you want. We haven't tried more than 300 users, but it does support as much as you want. When you have thousands of users something else you would need to speak to the service about.
We have approximately 10 organizations using this solution as our customers.
How are customer service and support?
I have not faced many problems. However, if there is a glitch, for example, from the portal, you can usually receive a reply from the Sophos team within four hours.
How was the initial setup?
There is no installation since it is cloud-based. However, you have to open an account, activate it, forward the emails to it, and make sure the emails are coming. The emails then come back to you analyzed. The process is straightforward.
What about the implementation team?
You need skills to operate this solution, if you are not an IT-oriented person, you cannot. You have to be trained on it, but it's easy if you are already a skilled person. For example, it's the concept, when you have a driving license, you have to buckle the seatbelt, check the mirrors, etc. If you are a skilled person, and you have dealt with other products, it's straightforward. There are no deep skills required.
What's my experience with pricing, setup cost, and licensing?
Sophos Email is a subscription-based pricing model. Any vendor that gives you a service on the cloud is subscription-based, not perpetual, you have to pay annually to continue with the subscription.
The first step is to do sizing. For example, if you have 10 users and because of the second month, you might have two new employees. You always plan forward for how many licenses you want to buy.
The second point is don't look at the price. You have to understand that this is a very rich, secure protection solution. Don't look at the price, and if it's a bit more expensive than others, don't look at it. For example, if this solution is $12, and that other one is $10. You will find a lot of value in this solution and the small difference in price should not matter, it does protect well. Recently, you can have a monthly subscription, but it's more affordable if you have an annual subscription. It's not cheap or expensive, it is a good price for what you're buying.
The pricing could improve by having additional discounts. For example, when customers buy have more than 50 or more users, there should be additional discounts.
What other advice do I have?
I highly recommend Sophos Email. People who are having their email accounts with Office 365 might not be motivated to buy Sophos because Office 365, is already a cloud subscription that includes mailboxes and protection. They might be very happy with that, or might not be. However, the people who are not hosting their email on the cloud should use Sophos Email.
I rate Sophos Email a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
IT Security Engineer at a security firm with 51-200 employees
Makes day to day email management easy with self-management portal
Pros and Cons
- "The tool's most valuable feature is the anti-spam detection filter. Its threat email intelligence features help to identify email data."
- "Sophos Email could better detect fake emails, especially when the domain names are similar. It needs to improve spotting spoofed domains, like when one letter differs in a domain name. It also needs to incorporate AI detection. Barracuda detects suspicious emails better. However, malware scanning is better in Sophos Email."
What is most valuable?
The tool's most valuable feature is the anti-spam detection filter. Its threat email intelligence features help to identify email data.
What needs improvement?
Sophos Email could better detect fake emails, especially when the domain names are similar. It needs to improve spotting spoofed domains, like when one letter differs in a domain name. It also needs to incorporate AI detection. Barracuda detects suspicious emails better. However, malware scanning is better in Sophos Email.
The solution could offer the option to integrate third-party RBL. This would allow users like Omer to use their own RBLS.
For how long have I used the solution?
I have been using the product for one to two years.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
Sophos Email is scalable, but it depends on the licensing.
How are customer service and support?
The tool takes a lot of time to implement the requested new features.
How would you rate customer service and support?
Neutral
How was the initial setup?
The tool's deployment and integration into existing infrastructure is easy and can be completed in a few hours.
What's my experience with pricing, setup cost, and licensing?
I rate the product's pricing a seven out of ten.
What other advice do I have?
Sometimes, email protection products can't guarantee 100% security, whether from Microsoft, Sophos, Barracuda, or others. They typically claim up to 95% or 92% effectiveness. However, spam emails can get through, mainly if attackers use new IP addresses. It takes time for spam filters to recognize and block these new threats. The product is recommended primarily for small and medium businesses.
Previously, the domain anomaly detection feature was limited to detecting anomalies within our domain, such as xoz.com. However, it couldn't detect anomalies in external domains. This limitation resulted in emails from third-party domains potentially slipping through without detection. Other vendors offer better domain anomaly detection, including for third-party domains. Microsoft, for instance, allows users to customize their domain anomaly detection lists.
Day-to-day email management is easy thanks to the tool's user self-management portal. If an email gets blocked for a user, they can release it themselves without contacting IT every time. The tool automatically detects flagged emails, such as those with large attachments, and quarantines them for review. Users can then manage their quarantined emails with minimal training, reducing the burden on IT staff.
I rate the overall product a six out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller

Buyer's Guide
Download our free Sophos Email Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Popular Comparisons
Microsoft Defender for Office 365
Darktrace
Proofpoint Email Protection
Cloudflare One
Microsoft Exchange Online Protection (EOP)
Cisco Secure Email
Mimecast Email Security
Fortinet FortiMail
Avanan
Trend Micro Email Security
IRONSCALES
Perception Point Advanced Email Security
TitanHQ SpamTitan
Barracuda Email Protection
Hornetsecurity 365 Total Protection
Buyer's Guide
Download our free Sophos Email Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- When evaluating Messaging Security, what aspect do you think is the most important to look for?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- What is the best email encryption software for small enterprises using Office 365?
- What security measures should businesses prioritize to support secure remote work?
- When evaluating Email Security tools, what aspects do you think are the most important to look for?
- Why is Email Security important for companies?
- Which is the best email security gateway?
- Why are Email Security tools important for companies?