Spam and virus filtering
Mimecast Advanced Email Security privacy rating
Cloud email security service that filters inbound and outbound mail for spam, phishing, malware and impersonation. It runs as a gateway in front of the mail server or connects by API to Microsoft 365 and Google Workspace.
Summary
Mimecast Advanced Email Security scores 28 out of 100 (grade F) on the spam and virus filtering criteria. It meets 1 of 8 criteria: tells users about requests. It partly meets no ads or data sales, independent audit, TLS configuration and security headers. It does not meet open source, no trackers or telemetry and transparency report. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B.
Score 28 out of 100. How scoring works
Criteria
- No
-
No
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The website loads Google Tag Manager, and the privacy statement describes Google Analytics with remarketing that shows Mimecast ads on other sites.
-
Partial
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Paid business service with no ads, and Mimecast says it does not sell or rent personal data, but website cookies are used to target its own ads on third-party sites.
-
Partial
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
The trust center lists ISO/IEC 27001 certification and a SOC 2 Type 2 report, but no full audit report is published on the website.
-
No
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
No transparency report or government request policy is published. The privacy statement only says data may be shared to cooperate with law enforcement, judicial orders and regulatory inquiries.
-
Yes
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
The service agreement requires reasonable prior written notice to the customer before confidential information is disclosed under a law or judicial or administrative order, where lawfully permitted.
Automated tests
-
Partial
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A-
-
Partial
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade B (70/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.