ICES vs SEG: Which Email Security Approach Fits You
Gateways filter mail before delivery. API-based tools inspect it inside the mailbox. See how they differ, where each fails, and which to run.
Gateways filter mail before delivery. API-based tools inspect it inside the mailbox. See how they differ, where each fails, and which to run.
A secure email gateway sits in front of your mailbox and filters mail before it lands. An integrated cloud email security tool works differently. It connects to the mailbox through an API, then checks mail after it lands, using behavior rather than known-bad signals. Most firms run both, because each catches what the other misses.
Table of Contents
ToggleA secure email gateway, or SEG, changes where your mail flows. You point your MX records at the vendor, so every message passes through them first. The gateway then checks the sender’s record, its signed-sender checks, links, and files. Whatever passes gets delivered.
Industry analysts call this second category integrated cloud email security, and Microsoft documents how API-based tools connect alongside its own filtering. An integrated cloud email security tool, often called ICES, leaves your mail flow alone. Instead, it connects to Microsoft 365 or Google Workspace through an API. It reads messages after they arrive, then removes anything it judges malicious. It also sits inside the mailbox, so it sees internal mail that never crosses the perimeter.
That difference in position explains most of the rest. It also decides which attacks each one catches, for reasons built into where they sit.
| Factor | Secure email gateway | Integrated cloud email security |
|---|---|---|
| Position | Before the mailbox | Inside the mailbox |
| Setup | Change MX records | Connect by API |
| Detection basis | Known-bad signals | Behavior and context |
| Internal email | Not visible | Visible |
| Blocks before delivery | Yes | No, removes after |
| Best against | Bulk spam, malware | Impersonation, account takeover |
Two rows drive most buying decisions. First, a gateway stops mail before it reaches the mailbox, which an API tool cannot. Second, an API tool sees internal mail, which a gateway never does. That matters, because a compromised colleague’s account does its damage inside the tenant.
Discover how Threatcop protects your workforce from modern cyber threats.
Volume is the gateway’s real strength, since most of what reaches your domain is mass-sent rather than aimed at you. It removes bulk spam and common malware before any of it touches your tenant, which keeps noise down and leaves less for anything else to check.
Blocking before delivery matters too. A message the gateway rejects never sits in an inbox at all. With an API tool, a dangerous message stays visible for a short time before removal, and a fast reader can open it in that window.
Gateways also work anywhere, which matters more than it sounds. Much of what arrives is bulk, and filtering it early keeps the rest manageable.
They work in any environment too. If you run your own mail server or a mixed setup, an API tool built for Microsoft 365 or Google Workspace may not fit.
A secure email gateway struggles with targeted attacks, because they are built to look clean. An email from a hacked supplier account passes the sender record and signed-sender checks, since nothing about it is technically wrong.
Payload-free attacks defeat it too. A plain-text message asking to change bank details has no link, no attachment, and no known-bad signal. Threatcop has written about how email filters miss these messages, and the cause is structural rather than a tuning problem.
Then there is internal mail, which the gateway never sees. If an attacker takes over an employee’s account and emails colleagues, that message never leaves the tenant, so the gateway never sees it.
API-based email security is not a complete answer either. Because it checks mail after it lands, a gap always exists before removal, however brief.
These tools also learn what normal looks like, which takes time. They can misjudge unusual but genuine behavior, so a new supplier or a change in work patterns may trigger a false alarm.
Tool choice is not the end of the story, though. Being tied to one platform matters as well. These tools are built for one cloud platform, so a move or a mixed setup makes things harder.
For most firms on Microsoft 365 or Google Workspace, the honest answer is both, with different jobs.
Let your platform’s own filtering and a gateway handle volume. Then add an API-based tool for targeted attacks that look legitimate, especially fake-identity attacks and account takeover. If budget forces a choice, start with what your platform already gives you. Microsoft and Google both filter a great deal before anything else runs, as Google’s own admin documentation describes.
Either way, confirm the foundations first. Signed-sender checks through DMARC stop attackers faking your own domain, and neither tool replaces them. Get those records right before you compare products, because a gap there undermines both.
Whatever you buy, some targeted messages reach people. No vendor claims otherwise, and the honest ones say so plainly in their own documentation. That is by design, not a failure. The attacks that get through are built to look normal to software.
So the last control is a person who notices and says so quickly. That needs two things. Staff must recognize a suspicious request, and the reporting route must be fast enough to matter. Regular practice builds the first, and automated removal of reported mail delivers the second.
Threatcop Phishing Incident Response (TPIR) covers that second half. One-click reporting from email and WhatsApp means the person who noticed does not have to forward anything or find the right contact. The platform then runs the analysis your filters already skipped, including header analysis, link and attachment scanning, IP reputation, and deceptive domain checks inside a sandbox. Its “Who Else” insight lists the other recipients of the same message, so removal covers the campaign rather than one mailbox.
That is the measurable layer neither a gateway nor an API tool provides. A filter reports what it blocked, while reporting data tells you what reached people anyway, and how fast they said so.
Fast reporting is the measurable part. Measure the gap honestly. Count how many real threats staff report, and how fast, rather than the block rate a vendor shows you. A vendor’s block rate describes what it caught, not what it missed, and the second number is the one that matters when you compare tools.
A secure email gateway and an API tool are not rivals. They do different jobs. Gateways cut volume before delivery, so the obvious attacks never reach anyone. API tools catch the convincing messages that pass every technical check, including mail from a colleague’s hacked account.
Choose between them by what your setup supports and where attacks get through now, not by which category sounds newer. Then do the two things neither product does for you. Confirm your signed-sender records are right, because a gap there weakens both tools. And give staff a reporting route fast enough to matter, since the messages built to look normal to software are the ones a person has to catch.
A secure email gateway filters mail before it reaches the mailbox by changing where your mail flows. An integrated cloud email security tool connects by API and checks mail after it lands, including internal messages a gateway never sees.
Many firms do, mainly for volume filtering and pre-delivery blocking. Microsoft’s own filtering handles a great deal, so the real question is what remains after it, and where targeted attacks are getting through.
Sometimes, though it depends on your environment. API tools cannot block mail before it lands, and they only work on certain cloud platforms. So hybrid or self-hosted mail setups often still need a secure email gateway.
API-based tools generally do better against business email compromise, because they judge how a sender behaves. A hacked supplier account passes every technical check a secure email gateway makes, so filters based on sender records have nothing to flag.
No. Targeted attacks are built to look real to both a secure email gateway and an API tool. That is why staff reporting and fast removal of reported mail stay necessary, whichever tools you run.
Sushant Kumar is the AVP – Technology at Threatcop, bringing over a decade of experience in technology leadership and product development. He has worked across technology-driven organizations, including Paytm, and focuses on building scalable solutions that address evolving business and cybersecurity challenges. His areas of interest include cybersecurity technology, AI-driven security, product innovation, and enterprise technology. He is passionate about using technology to solve complex security challenges.
Sushant Kumar is the AVP – Technology at Threatcop, bringing over a decade of experience in technology leadership and product development. He has worked across technology-driven organizations, including Paytm, and focuses on building scalable solutions that address evolving business and cybersecurity challenges. His areas of interest include cybersecurity technology, AI-driven security, product innovation, and enterprise technology. He is passionate about using technology to solve complex security challenges.
Outlook recall only works inside your organization on unread mail. Learn the steps, the limits, and why Undo Send...
Gmail has no true recall, but Undo Send gives you up to 30 seconds. Learn how to set it,...
A phishing simulation is safe practice, not a trap. See how it works step by step, which metrics matter,...
Table of Contents
×