In my current situation, I have been using Microsoft ATP and Microsoft APP for the protection on the endpoints. This system is effective with Microsoft Defender being employed for additional security. Comparing the performance with the Sophos Email, I find it equally effective and efficient. As for the version, I use the latest available from the official website or the Sophos Central platform. It's connected to our admin system for seamless integration.
Team Lead, Infrastructure, Security & Service Management at a financial services firm with 5,001-10,000 employees
Ensures that there is maximum security enabled for our communication processes
Pros and Cons
- "There are many features that are important, but among those, the spam protection feature is very valuable. It help us to safeguard the email against phishing and ensures that there is maximum security enabled for our communication processes. It has a huge role in protecting our emails from potential threats."
- "Sophos Email has few improvements to implement, including the handling of incoming emails in the systems. It needs to add additional feature that helps in enhancing the scanning processes of these emails. While adding these features, it should work towards improving the current features also."
What is our primary use case?
How has it helped my organization?
The overall experience has been improved since I started using the Sophos email. Before shifting to Sophos, I was using Microsoft and faced various challenges with certain functions of the system. Regarding the issues, I used to frequently contact Microsoft Support, which was very difficult. However, the shift to Sophos Email has been easy, it is more user-friendly and efficient to use. The issues with Microsoft Defender are no more in Sophos and it is a much more secure option to protect email systems.
What is most valuable?
There are many features that are important, but among those, the spam protection feature is very valuable. It help us to safeguard the email against phishing and ensures that there is maximum security enabled for our communication processes. It has a huge role in protecting our emails from potential threats.
What needs improvement?
Sophos Email has few improvements to implement, including the handling of incoming emails in the systems. It needs to add additional feature that helps in enhancing the scanning processes of these emails. While adding these features, it should work towards improving the current features also.
Buyer's Guide
Sophos Email
January 2026
Learn what your peers think about Sophos Email. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
For how long have I used the solution?
I've been using Sophos Email for about four years now as a customer.
What do I think about the stability of the solution?
The stability of Sophos Email has been quite impressive. It serves as a fundamental tool for routine tasks, especially in terms of data management. The company relies on it for various aspects, indicating its stability and integral role in daily operations.
I would rate it 8 out of 10.
What do I think about the scalability of the solution?
Sophos Email has proven to be effective in countering phishing and scam attempts, making it a reliable software for email security. Overall, it has been a positive experience, and I would rate it 8 out of 10.
How are customer service and support?
There has been issues when I have interacted with the support in the past, especially regarding technical issues. I have found them responsive for basic queries, but when I have raised issues for complex issues, there is a delay in the response from the support team. During the initial setup, when I faced challenges, the support team took a lot of time to address the issue and escalate it to the required personnel. In another issue raised, I was trying to confirm the status of a domain name. The support team was not able to help me out and provide with the necessary information. I suggest that there should be improvement in the support team towards handling such complex issues and technical concerns.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
It seems there were challenges with the previous security solution, particularly in handling phishing and spam emails, and the settings didn't provide the desired capabilities. After exploring Microsoft Defender for Office 365, it wasn't deemed suitable, prompting a switch to Sophos Email, which has proven to be more effective. The decision was driven by the need for improved security measures and a solution that aligns with specific requirements.
How was the initial setup?
It was difficult for me. The deployment process for Sophos Email was straightforward. After agreeing on payment, a consultant facilitated the configuration and routing of the product. In my case, using Mapusoft, the product was integrated, reported, and directed to Sophos before reaching Microsoft. The deployment team involved three to four people, but this depends on the user database.
What was our ROI?
Implementing Sophos Email has positively impacted our metrics. We've seen improvements in efficiency, reduced employee needs, and cost savings, particularly in the aspects of security and data protection.
What's my experience with pricing, setup cost, and licensing?
I would rate the pricing of Sophos Email as a six. It is considered affordable as a standalone product, and there are no additional costs besides licensing. The pricing is fixed.
What other advice do I have?
I wouldn't recommend Sophos Email protection based on my experience. My advice is to explore other options like Microsoft Defender and Forcepoint to see how they perform and compare them. For someone considering implementing this solution, I suggest looking into alternatives as I find them to be better in certain aspects.
I would rate Sophos Email as a seven.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Director at a tech services company with 1-10 employees
Automatically scans messages and attachments for sensitive data, with encryption that integrates seamlessly
Pros and Cons
- "The filtering capabilities are precious and far superior to others I've used. It's intuitive in what it pushes to quarantine, and users can quickly review, free, or delete items without needing an administrator, making it ideal for a multi-user environment."
- "However, the setup was tricky, particularly with the DNS routing between Microsoft Exchange Online and Sophos cloud services. It took me about four attempts to get it working correctly. Despite that, Sophos Email does everything we need, so we don't require any additional capabilities now."
What is our primary use case?
We use it with Microsoft Exchange Online for all our email scanning. Microsoft Exchange Online pushes the emails to Sophos, which scans and classifies them before sending them to us. Once it's set up, it's a seamless and efficient solution.
How has it helped my organization?
Sophos Email has significantly improved security in our organization, which is critical as a defense subcontractor. It provides much better protection than just using Microsoft's products alone.
What is most valuable?
The filtering capabilities are precious and far superior to others I've used. It's intuitive in what it pushes to quarantine, and users can quickly review, free, or delete items without needing an administrator, making it ideal for a multi-user environment.
What needs improvement?
However, the setup was tricky, particularly with the DNS routing between Microsoft Exchange Online and Sophos cloud services. It took me about four attempts to get it working correctly.
Despite that, Sophos Email does everything we need, so we don't require any additional capabilities now.
For how long have I used the solution?
I've been working with Sophos Email for about eighteen months.
What do I think about the stability of the solution?
I’d give it a nine for stability—it’s very stable, which is crucial for us and the main reason we chose it.
What do I think about the scalability of the solution?
I rate the scalability of Microsoft Exchange Online a ten out of ten. It's a pure enterprise solution. We have about twenty users since we’re a micro-business, but if the company expands, we will increase usage.
How are customer service and support?
Regarding technical support, it was a great experience, although I know others may havedifferent experiences. Before using Microsoft Exchange Online, we were using Microsoft’s product, but we needed something more robust and stable. We evaluated several options and chose Microsoft Exchange Online because it offered a strong industry presence.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup process for Sophos Email was quite challenging, and I would rate it a three or four out of ten. However, it wasn’t a nightmare. Once the DNS setup was correct, the deployment became straightforward. It’s deployed in the cloud, and the initial deployment took less than a week. After configuring DNS, it was mainly self-deployed and integrated with Microsoft Active Directory, making it easy to add users.
I handled the deployment with help from Sophos and completed
Their Accreditation Training helped me get up to speed quickly. In terms of manpower, only two people were involved in the deployment process. Now that it's set up, the system is robust and self-maintaining. Reporting is configured on the Sophos appliance and integrated with monitoring tools. If an issue arises, the system attempts to fix itself, and if it can’t, it notifies both us and Sophos automatically. Overall, it’s very low maintenance.
What was our ROI?
In terms of return on investment, while I can’t put a financial figure on it, the product has significantly reduced unsolicited emails and strengthened our security. It’s been critical, especially for our government contracts.
What's my experience with pricing, setup cost, and licensing?
The pricing is affordable, so I’d rate it around a four out of ten on the pricing scale. We pay about fifty pounds a month, including hardware so that costs may differ without it.
What other advice do I have?
I’d rate Sophos Email a nine for our use case, as I haven’t found a better
solution. My advice for new users is to work with an authorized Microsoft dealer to get direct support. Many resellers sell licenses, but having a primary dealer ensures better technical support, which is invaluable. It may be more expensive, but the benefits outweigh the costs.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sophos Email
January 2026
Learn what your peers think about Sophos Email. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Sales Manager at a tech services company with 11-50 employees
Prevents phishing emails and other cybersecurity attacks
Pros and Cons
- "Our client recently received many emails, and their employees didn't realize these emails were phishing attempts. Consequently, they clicked on them and fell victim to the attack. Therefore, it is important to secure their system with Sophos Email Security."
What is our primary use case?
The solution prevents phishing emails and other cybersecurity attacks.
How has it helped my organization?
Our client recently received many emails, and their employees didn't realize these emails were phishing attempts. Consequently, they clicked on them and fell victim to the attack. Therefore, it is important to secure their system with Sophos Email Security.
What is most valuable?
Sophos Email protection is very active. It has updated signatures for phishing and email attacks. Additionally, it can also send alerts regarding ransomware.
For how long have I used the solution?
I have been using Sophos Email since June last year.
What do I think about the stability of the solution?
Sophos gives good results and good feedback from clients.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
Support is excellent. They do have some delays.
How would you rate customer service and support?
Positive
How was the initial setup?
We also handle the implementation. I manage the branch, sales, and operations. Additionally, we have other roles, such as the technical team and support engineers, to ensure smooth operation for our clients. The deployment requires two technical personnel, including one certified support engineer.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is reasonable.
What other advice do I have?
Sophos is not difficult to maintain. Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Has a good user interface, but its DLP features need enhancement
Pros and Cons
- "It has enhanced our approach to tackling malware and spam. It is a reliable product with a good user interface."
- "Sophos Email could improve DLP features."
What is most valuable?
The product provides valuable performance.
What needs improvement?
Sophos Email could improve DLP features.
What do I think about the stability of the solution?
The platform is stable. However, they could provide more updates to streamline the product. I rate the stability as seven out of ten.
What do I think about the scalability of the solution?
We have 50 Sophos Email users in our organization. It has good scalability.
How are customer service and support?
The technical support team could be faster, more knowledgeable, and more customer-friendly.
Which solution did I use previously and why did I switch?
We are using multiple products as system integrators.
How was the initial setup?
The deployment steps involve simply downloading and executing the links, as it's a cloud-based solution. It requires one engineer to handle the maintenance.
What's my experience with pricing, setup cost, and licensing?
The platform is inexpensive. It offers a cost-effective licensing model. We purchase its yearly license.
What other advice do I have?
We utilize Sophos Email Gateway to protect against phishing in our company. Following the standard recommendation provided by Sophos, we established connectivity between Sophos Email Gateway and Microsoft 365.
It has enhanced our approach to tackling malware and spam. It is a reliable product with a good user interface.
The integration capabilities still need improvement, as some functionalities are not operating properly. Specifically, attention needs to be given to AD integration capabilities, which are crucial for various operations.
I rate it a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Senior Technical Support Engineer at a retailer with 201-500 employees
Robust cybersecurity with advanced attachment and link filtering and affordable fixed pricing
Pros and Cons
- "The most significant aspect is the response filtering concerning attachments and links."
- "The main drawback is regarding the technical support."
What is our primary use case?
Our client specifically opted for it to address attachment-related concerns in both inbound and outbound email traffic. The primary focus lies in leveraging it for scanning and filtering attachments to enhance security measures. The choice is driven by the need for robust link protection, ensuring comprehensive inbound and outbound protection against potential threats associated with email links.
What is most valuable?
The most significant aspect is the response filtering concerning attachments and links.
What needs improvement?
The main drawback is regarding the technical support. Unfortunately, we may not receive immediate assistance, and the resolution process might extend beyond a week. Internal filtering is an additional feature that should be incorporated. I would appreciate having the option for spam blocking.
For how long have I used the solution?
I have been working with it for approximately four years.
What do I think about the stability of the solution?
I would rate its stability capabilities eight out of ten.
What do I think about the scalability of the solution?
Scalability is an area that could be enhanced, particularly in terms of technical aspects related to server maintenance. We lack control over certain aspects, such as policy management and updates, and we do not receive training for these functionalities. I would rate it eight out of ten.
How are customer service and support?
The technical support services should be improved. I would rate it six out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup was relatively straightforward. I would rate it eight out of ten.
What about the implementation team?
Deployment process is managing proposal related.
What's my experience with pricing, setup cost, and licensing?
The pricing is quite reasonable, with a fixed cost and no additional charges. I would rate it four out of ten.
What other advice do I have?
Overall, I would rate it nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
L1 System Engineer at a tech services company with 11-50 employees
Offers good log features but challenges with compatibility, management, and reporting
Pros and Cons
- "The best thing about it is the logs."
- "There have been some issues with compatibility and effectiveness, particularly when integrating it with our firewall. The main challenge has been email protection, especially due to compatibility issues and difficulties with log access and email relay configuration."
What is our primary use case?
We use Sophos Email for various solutions, setting it up for different customer environments as part of our strategy.
What is most valuable?
The best thing about it is the logs.
What needs improvement?
There have been some issues with compatibility and effectiveness, particularly when integrating it with our firewall. The main challenge has been email protection, especially due to compatibility issues and difficulties with log access and email relay configuration.
I would like to see more detailed logs in the future releases. The firewall logs don't show the in-depth logs, so we can only see the software in detail, not the logs themselves. This is a problem we've been facing in customer environments for some time.
Emails go to spam even though there's no legitimate reason for them to be there. There's no summary of the necessary issues, either.
If an email goes to spam, the system will drop it. There should be a certificate email on the query, but support comes and goes, and they might see learning and run the Linux command or show the unrigorous answers.
But if there is some read-only show on the reporting or clear reporting, it would be good for the customers.
For how long have I used the solution?
We use Sophos Email Protection. We've deployed it in various scenarios, either on-premises or using Sophos Cloud Email Protection.
What do I think about the scalability of the solution?
Considering our experience with firewall integration, I'd rate it a five out of ten. I haven't used the cloud solution extensively to comment on that aspect.
The rating reflects the challenges we've faced. These different appliances have more limitations, like reporting limitations. They don't have good reporting, and it's not a good solution.
If there's another issue, we have to go to the CLI and change something to embroider the other issue, which is spam.
If we go and prepare the spam, it gets stuck, and there's no option to understand it on the GUI. There is an option to go to the CLI and run the script. There's a predefined script. There are a lot of things.
How was the initial setup?
The initial configuration isn't difficult, but managing permissions there are some issues. We've encountered issues where some emails are incorrectly flagged or missed, which complicates management.
We're using the on-premises version of Sophos Email Protection. We haven't utilized cloud email protection. Our focus has been primarily on integrating it with the firewall.
What's my experience with pricing, setup cost, and licensing?
There are different price tiers for different customer sizes. I sell the bundle, which includes all the licenses, web protection, and other features.
Which other solutions did I evaluate?
The customers who are using email servers are not using anything else. Most of our new users moved to a better solution, like Fortinet email or other solutions, but they didn't want to move. For the new users, it's combined and deployed by themselves.
What other advice do I have?
It's best to take the POC from the so-called official, test it thoroughly, and then make a decision. If it's compatible with the environment and works well, then keep the POC successfully.
Overall, I would rate the solution a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Pre-sales manager at a tech services company with 51-200 employees
Effective on-premises and cloud, beneficial sandboxing, and advanced AI detection
Pros and Cons
- "When you say email security, it's about everything, incoming email, outgoing email, spam, phishing emails, unwanted marketing emails. You can set rules, but the main feature of Sophos Email is to make sure you don't get hacked. 95% of people who are hacked do not get hacked by typing the router password. They are hacked from the inside out, which means they send you a document that is a zero-day attack, you open it, nothing happens, but technically the attack is running in the background of your computer. This is how they gain access to your PC."
What is our primary use case?
We can use Sophos Email for securing incoming and outgoing emails. Whether your email server is on-premise or on the cloud, you can use Sophos email security to protect your mailboxes from spam, phishing, zero-day attack, such as if somebody sends an email with an attachment that anti-virus cannot detect. For example, today, I can send you a PDF that has inside a virus, and you cannot detect it through the anti-virus. What Sophos Email security does is filters and classifies those emails by using AI in a sandbox. The email comes to Sophos Email security platform first, it opens the email, runs the attachment, and sees the behavior. If normal, the email is passed. If the email has a zero-day attack, and it senses that the PDF is doing something to Windows or Linux, it quarantines and notifies the administrator.
It's the optimal solution for people who needs to secure their email, whether they have on-premise or on the cloud email server, SophosEmail security can be used.
What is most valuable?
When you say email security, it's about everything, incoming email, outgoing email, spam, phishing emails, unwanted marketing emails. You can set rules, but the main feature of Sophos Email is to make sure you don't get hacked. 95% of people who are hacked do not get hacked by typing the router password. They are hacked from the inside out, which means they send you a document that is a zero-day attack, you open it, nothing happens, but technically the attack is running in the background of your computer. This is how they gain access to your PC.
This solution has artificial intelligence. It means it doesn't depend only on the normal definition. It reads the algorithm and analyzes it, so it's something very advanced than other vendors.
Sophos Email is accurate and fast. It does block stealth attacks ransomware if you receive a file, which is hidden. For us, we can see it's a very good solution compared with others.
Overall the solution is easy for management and easy to use in general. It has all the tools, such as active protection for your organization's needs.
The main requirement of this solution is for email security and protection. The settings are easy, very secure, and simple GUI to manage.
For how long have I used the solution?
I have been using Sophos Email for approximately five years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is highly scalable. You can subscribe for 100, 500, 1000, as many as you want. We haven't tried more than 300 users, but it does support as much as you want. When you have thousands of users something else you would need to speak to the service about.
We have approximately 10 organizations using this solution as our customers.
How are customer service and support?
I have not faced many problems. However, if there is a glitch, for example, from the portal, you can usually receive a reply from the Sophos team within four hours.
How was the initial setup?
There is no installation since it is cloud-based. However, you have to open an account, activate it, forward the emails to it, and make sure the emails are coming. The emails then come back to you analyzed. The process is straightforward.
What about the implementation team?
You need skills to operate this solution, if you are not an IT-oriented person, you cannot. You have to be trained on it, but it's easy if you are already a skilled person. For example, it's the concept, when you have a driving license, you have to buckle the seatbelt, check the mirrors, etc. If you are a skilled person, and you have dealt with other products, it's straightforward. There are no deep skills required.
What's my experience with pricing, setup cost, and licensing?
Sophos Email is a subscription-based pricing model. Any vendor that gives you a service on the cloud is subscription-based, not perpetual, you have to pay annually to continue with the subscription.
The first step is to do sizing. For example, if you have 10 users and because of the second month, you might have two new employees. You always plan forward for how many licenses you want to buy.
The second point is don't look at the price. You have to understand that this is a very rich, secure protection solution. Don't look at the price, and if it's a bit more expensive than others, don't look at it. For example, if this solution is $12, and that other one is $10. You will find a lot of value in this solution and the small difference in price should not matter, it does protect well. Recently, you can have a monthly subscription, but it's more affordable if you have an annual subscription. It's not cheap or expensive, it is a good price for what you're buying.
The pricing could improve by having additional discounts. For example, when customers buy have more than 50 or more users, there should be additional discounts.
What other advice do I have?
I highly recommend Sophos Email. People who are having their email accounts with Office 365 might not be motivated to buy Sophos because Office 365, is already a cloud subscription that includes mailboxes and protection. They might be very happy with that, or might not be. However, the people who are not hosting their email on the cloud should use Sophos Email.
I rate Sophos Email a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
IT Security Engineer at a security firm with 51-200 employees
Makes day to day email management easy with self-management portal
Pros and Cons
- "The tool's most valuable feature is the anti-spam detection filter. Its threat email intelligence features help to identify email data."
- "Sophos Email could better detect fake emails, especially when the domain names are similar. It needs to improve spotting spoofed domains, like when one letter differs in a domain name. It also needs to incorporate AI detection. Barracuda detects suspicious emails better. However, malware scanning is better in Sophos Email."
What is most valuable?
The tool's most valuable feature is the anti-spam detection filter. Its threat email intelligence features help to identify email data.
What needs improvement?
Sophos Email could better detect fake emails, especially when the domain names are similar. It needs to improve spotting spoofed domains, like when one letter differs in a domain name. It also needs to incorporate AI detection. Barracuda detects suspicious emails better. However, malware scanning is better in Sophos Email.
The solution could offer the option to integrate third-party RBL. This would allow users like Omer to use their own RBLS.
For how long have I used the solution?
I have been using the product for one to two years.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
Sophos Email is scalable, but it depends on the licensing.
How are customer service and support?
The tool takes a lot of time to implement the requested new features.
How would you rate customer service and support?
Neutral
How was the initial setup?
The tool's deployment and integration into existing infrastructure is easy and can be completed in a few hours.
What's my experience with pricing, setup cost, and licensing?
I rate the product's pricing a seven out of ten.
What other advice do I have?
Sometimes, email protection products can't guarantee 100% security, whether from Microsoft, Sophos, Barracuda, or others. They typically claim up to 95% or 92% effectiveness. However, spam emails can get through, mainly if attackers use new IP addresses. It takes time for spam filters to recognize and block these new threats. The product is recommended primarily for small and medium businesses.
Previously, the domain anomaly detection feature was limited to detecting anomalies within our domain, such as xoz.com. However, it couldn't detect anomalies in external domains. This limitation resulted in emails from third-party domains potentially slipping through without detection. Other vendors offer better domain anomaly detection, including for third-party domains. Microsoft, for instance, allows users to customize their domain anomaly detection lists.
Day-to-day email management is easy thanks to the tool's user self-management portal. If an email gets blocked for a user, they can release it themselves without contacting IT every time. The tool automatically detects flagged emails, such as those with large attachments, and quarantines them for review. Users can then manage their quarantined emails with minimal training, reducing the burden on IT staff.
I rate the overall product a six out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Download our free Sophos Email Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Popular Comparisons
Microsoft Defender for Office 365
Darktrace
Cloudflare One
Proofpoint Email Protection
Check Point Harmony Email & Collaboration
Cisco Secure Email
Microsoft Exchange Online Protection (EOP)
Mimecast Email Security
Fortinet FortiMail
Avanan
Barracuda Email Protection
Trend Micro Email Security
IRONSCALES
Perception Point Advanced Email Security
TitanHQ SpamTitan
Buyer's Guide
Download our free Sophos Email Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- When evaluating Messaging Security, what aspect do you think is the most important to look for?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- What is the best email encryption software for small enterprises using Office 365?
- What security measures should businesses prioritize to support secure remote work?
- When evaluating Email Security tools, what aspects do you think are the most important to look for?
- Why is Email Security important for companies?
- Which is the best email security gateway?
- Why are Email Security tools important for companies?


















