Mimecast kills the API email-security trade-off — but can ICES really replace a secure gateway?

Mimecast is making a bold claim: email security teams no longer need to choose between fast API deployment and deep gateway-grade protection. The company recently announced that its full email-security stack is now available through API deployment for Microsoft 365, without MX record changes or mail-flow modifications.

The pitch lands because the old trade-off has been painful. Traditional secure email gateways inspect mail before delivery, sitting directly in the flow of email traffic. API-based integrated cloud email security, or ICES, connects to the email platform and scans messages after they have been processed by the platform.

Mimecast’s own support documentation describes this as post-delivery analysis that can quarantine suspicious messages or alert administrators after detection.

That distinction matters. 

Gateways are strong at pre-delivery control. API tools are faster to deploy and can use mailbox context, behavioural signals and updated intelligence to pull back threats that initially looked clean.

Mimecast’s argument is that its API deployment now brings the same detection engines used in its gateway product, including URL inspection, malware analysis, behavioural AI, business email compromise (BEC) protection and account takeover detection.

The real question is replacement, not deployment

The market need is clear. 

Mimecast’s State of Human Risk 2026 report found that 53% of organisations saw increased phishing volume, 48% saw rising BEC attacks, and 64% said native collaboration security controls were insufficient. The same research found 42% of organisations reported an increase in malicious insider incidents over the past year.

That makes email security less about inbox filtering and more about human risk

Mimecast says its AI-driven engines are trained across 24 trillion data points and used across 42,000 organisations, with customers catching three times more BEC and credential-phishing attacks than traditional detection methods.

Can ICES replace a secure gateway? In some Microsoft 365 environments, yes, especially where speed, low disruption and rapid proof-of-value matter. But replacement should be risk-led. Organisations with strict pre-delivery controls, complex routing, legacy compliance workflows or layered data loss prevention requirements may still prefer a gateway or hybrid model.

Mimecast has weakened the old ICES objection. It has not eliminated the need for architectural judgement.

Kihara Kimachia
Kihara Kimachia

Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.