I've used IRONSCALES in multiple scenarios. I first used the solution in the Asia-Pacific region to review suspicious phishing emails in the mailbox instead of reviewing them manually. The primary goal was to have an automated solution for suspicious or weird emails. It automatically reviews them and maybe provides some kind of response. That was our first goal with the product. It reviews the emails, attachments, and links at the same time.
There is an automated piece where people can send an email or forward the email to a review team. It adds an additional mailbox layer on top of our spam quarantine. IRONSCALES captures everything our existing spam quarantine couldn't capture. It also helps us with additional phishing campaigns. 
Director, Information Security at a pharma/biotech company with 501-1,000 employees
Reviews suspicious emails, helps with phishing campaigns and has excellent employee awareness training
Pros and Cons
- "I would say the most valuable feature is what they call Themis. It's like a virtual analyst that uses the decisions that system admins make to generate a score for whether an email is legitimate, spam, or phishing. It gets better based on the decisions that we make over time. The automation piece is great as well. The integrated approach of email security combined with employee awareness training is excellent."
- "In addition to integrated training, they should also have personalized training that you don't have to do as part of a phishing campaign or a simulation."
What is our primary use case?
How has it helped my organization?
IRONSCALES has what they call a "911 mailbox" that lets your organization share information about threats. It sets up an address like phish@whateverorganization.com where everyone in the company can forward suspicious emails. IRONSCALES has access to that account to review the emails. All of the phishing emails or anything suspicious goes in that queue.
IRONSCALES will automatically categorize mail if something looks legitimate based on what the admins have already reviewed. It saves us a lot of time. We previously had a regular mailbox to accept suspicious mail from members of organizations. It was tough because everything was all manual, and we had to review a ton of emails some days. Now, people just send everything to the 911 mailbox or click on the "report phishing" button.
If employees have any other questions, they can message or call me. IRONSCALES saved me tremendously because I don't have to worry about manually reviewing that mailbox anymore. Sometimes, the email doesn't reach the queue, and I wonder what's going on. It's probably due to multiple forwards. The phishing campaign assimilation also helps.
What is most valuable?
We like IRONSCALES because it's easy to use and saves us some time. The reporting is good because it has all these tracking features and metrics. It's still evolving, but it's great to have information about automated detection and response, phishing campaigns, simulations, etc.
I would say the most valuable feature is what they call Themis. It's like a virtual analyst that uses the decisions that system admins make to generate a score for whether an email is legitimate, spam, or phishing. It gets better based on the decisions that we make over time. The automation piece is great as well. The integrated approach of email security combined with employee awareness training is excellent.
The AI and machine learning capabilities have come a long way since I first started using the solution. At the same time, any technology is only as good as the team's ability to use it. It's still evolving, and I think machine learning will become increasingly helpful because the more it does, the more accurate it'll be. In the beginning, there will be a lot of false positives, but it will become better as you provide more feedback and I think a lot of security teams are trying to do more of that too.
Integration is also crucial because there isn't a one-size-fits-all solution. Right now, I need to go to 10 different portals to check something, like a security incident. Integration with everything is always useful.
IRONSCALES has made improvements to its automated detection and response. If your company gets a targeted phishing email, there are two options. You have the option to leave comments and feedback in a form, and that's only limited to the people in the company. There's also a secondary form that's can be externally shared with existing customers or anyone with access to the IRONSCALES API.
Automated detection and response are good, but it depends on the specific email that comes in. I can only speak for my company. which is in the field of life sciences and healthcare, but we get all the typical phishing emails.
Microsoft has many domains, like outlook.com, live.com, microsoft.com, and 365 office support. A lot of phishing campaigns use these domains. They know nobody can block these domains as most people use Microsoft, UEX, or Mac shop. Phishers disguise themselves using a compromised legitimate business email account and start sending emails that say: "Please log in here." It looks like it's going to the organization's Office 365 website, but it's going to the other compromised organization. People are more likely to trust that. 
IRONSCALES also has a mobile app on Android and iOS. We mostly used it when we had a bigger team. I've been using it since the earliest version when they only had a web interface but not the official Apple or Android or mobile version. It's great for following up when you may not have access to a desktop computer or laptop. 
It's great for getting a sense of what specific phishing or incidents or events are coming into the IRONSCALES dashboard portal. When you need to do more digging, you probably don't want to look at the application on the phone because it's too small, and you have to dive in to see the email headers. I use it for limited purposes, like quickly checking an email to see if it looks legitimate, so I can re-categorize it. I need to go into the computer if it's anything more.
What needs improvement?
In addition to integrated training, they should also have personalized training that you don't have to do as part of a phishing campaign or a simulation. It could be launched separately as a learning management system, a squirm file, or something like that. IRONSCALES is working on that, so hopefully, we'll have that soon.
In the last four or five months, we started a new security operation center. We had to train and onboard the employees. We tried to get IRONSCALES audit logs into our SIM, rather than it going from cloud to cloud, but it does not work right now. I would like to see this as a new feature.
Buyer's Guide
IRONSCALES
October 2025

Learn what your peers think about IRONSCALES. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,008 professionals have used our research since 2012.
For how long have I used the solution?
I've been using IRONSCALES for more than five years. I was one of the first 100 IRONSCALES customers, and they've added a lot of the features that I requested.
What do I think about the stability of the solution?
IRONSCALES is highly stable. It's a growing ecosystem for this company. IRONSCALES plans to introduce integrations with learning management systems and various malware companies, like CrowdStrike and Carbon Black. Now, they also use their own algorithm to determine malicious payloads. That will be a useful feature. 
How are customer service and support?
I rate IRONSCALES support nine out of ten. I think they've improved greatly. I've been with them since the beginning and worked with all the founding members of the company. There's one person I still work with who is pretty high up in the company now. She created most of the documentation. I work with many of the same salespeople and support.
Many years ago, they had no U.S. office, so we had to contact them in Israel, and there was a significant time difference. They opened an office in Atlanta, and they've developed an official knowledge base. They also have a customer portal and designated customer success managers.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I used a few solutions and did some PoCs back in the day. Most of the solutions I've used were basic spam filters. I was the one who introduced IRONSCALES to our company. We used Mimecast for spam quarantine and our primary and secondary MX records. It does its job.
We used Mimecast for spam filtering and email archives. It's tough if you need to troubleshoot across different infrastructures or technology. That's the advantage of IRONSCALES. In the past, I had to go through every system and check the Microsoft Outlook program to see if it was 32-bit or 64-bit and install it one by one. It's straightforward just like any other company that uses Office 365 extensions. You only need a standard account that can install additional applications on Office 365, and you can define users. After that, you can do that to all global users.
How was the initial setup?
I was involved in the deployment from the beginning, from the architecture design and gathering requirements to the final setup. When I first deployed it, I was working in China, so anything that relies on Google wasn't going to work. It works in Hong Kong, but it doesn't work in mainland China because of the Great Firewall. This was eight years ago when IRONSCALES was extremely new. When I originally deployed it, we wanted to get this to every user.
At the time, we didn't have the option to deploy this through Microsoft Office 365. We had to go to every machine or a software installer to deploy it. That took a little more time. It didn't prevent the project plan, but it was an issue because installing the wrong extensions in Outlook can crash the program. This was back in the day, but now it's easy. 
When we didn't have the Microsoft Office 365 plugin capability or an API mailbox layer, it probably took us about a week to test it because we had to install it on all the computers. With the Office 365 capabilities, we could probably do it in a day or two because it's all tied to Office 365, and we can define it according to the group.
IRONSCALES doesn't require us to touch the client assets anymore. We had to install it one by one in the past, but now we only need to have administrative rights on Office 365 and we can just deploy it as a new application. We can select a few users or deploy it to all users.
Which other solutions did I evaluate?
A few years ago, I looked at two other alternatives, but the market has probably changed since then. I checked out other Mimecast solutions because we had Mimecast deployed. They didn't have some features that IRONSCALES has. They might have similar features now, but I don't trust them until I actually try them myself. Mimecast has many of the features that IRONSCALES offers, like automated detection and response as well as the phishing campaign, but I don't know if it works as well as IRONSCALES.
Even though Mimecast is based closer to home in Lexington, Massachusetts, it was tough to get tasks done in terms of feature requests. When I first evaluated it about four years ago, Mimecast didn't have as much functionality. Mimecast works by scrambling every link. That's how they do their threat response. It's encrypted, so you need to decrypt or read anything Mimecast sends. I was the one who worked with IRONSCALES and Mimecast to unencrypt everything.
The email comes into Mimecast and goes to IRONSCALES because IRONSCALES is on the API. We started to get emails from Mimecast that were encrypted and couldn't read the link. We could do it when working with both IRONSCALES and Mimecast and now they do that for all the customers.
What other advice do I have?
I rate IRONSCALES nine and a half out of ten. Before deploying any solution, we always research user feedback, check Gartner, etc. Ultimately, it all depends on how much you can afford, but Gartner's gives you a good list to choose from.
You can also ask IRONSCALES directly for some customer references. Of course, you don't want to only talk to customers who have positive feedback on IRONSCALES. Ask other users in your own network: "Hey, why did you stop using IRONSCALES?" That's what I like to do, but I often ask the vendor to arrange that.
I worked with IRONSCALES for about eight years and they've grown in size. There were only around 25 to 50 people at the company when I started working with them. After more than doubling in size, they're still highly responsive to feature requests. I also occasionally speak with their product development teams. If you ask for a feature based on your needs or environment, they'll usually add it fairly quickly— sometimes within three to six months depending on the feature request.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

Vice President of Information Technology at MENIN HOTELS LLC
Allows other users to flag an email as spam, has excellent detection capabilities, and is easy to deploy and manage
Pros and Cons
- "The fact that it is set-and-forget is valuable. Once you turn it on, you very rarely have to micromanage it, whereas, with a lot of spam filters, you have to go in very often."
- "Its UI could be improved. My pet peeve with a lot of these cloud-based systems is that a lot of times, the interface for the management is a little clunky. If you live and breathe IRONSCALES all day long, you'll obviously know where everything is just from muscle memory, but the system is not designed for people to be in it all day long. You're only supposed to occasionally look at it. When things get moved around, it is not necessarily that intuitive. I'm an IT guy, and I can pretty much take the worst UI and figure it out, but the menus and the options in the interface could be a little cleaner graphically. If you have a quick problem that you want to resolve, it takes a little bit of digging in the admin console, whereas it should take a few clicks up front."
What is our primary use case?
It is a glorified email spam filter. IRONSCALES catches whatever the built-in Microsoft spam filter doesn't catch. Its intelligence is different. Microsoft spam filters are only strong to a certain extent, and IRONSCALES catches what falls through the cracks, which is super important. It checks the links and other things, and our mailboxes are much cleaner.
How has it helped my organization?
Every company is different. In our company, it is helpful because it lets people know what to look out for. The reason we got IRONSCALES was that you can train all day long, but not everyone is going to get it. That's just the nature of working in the industry. It helps to remind people from time to time, but the scams evolve, and IRONSCALES has also evolved. So, the training is much less important than it used to be in terms of how to determine what's what in the malicious message, whether it is phishing, etc.
Its artificial intelligence and machine learning capabilities are the most important pieces. It is just good to know that it is watching when we don't have to watch. I can go to sleep, and it is still working. The AI knows what to pick up on. It learns from other companies. The key is that it is not just our tenants that it is examining; it is examining all the tenants. So, it can take what it learns from a different company that has nothing to do with us and apply it to our mailbox. So, the whole system gets smarter overall.
It provides the ability to customize the automated detection capabilities. The system is set up for that when you start, and there is not a whole lot of going back in and reteaching it after the fact. Only when we're doing the training, to teach people what to look out for, we intentionally do white list certain messages that are designed to be spammed. This way we can go back, look and find out which employees need a refresher on how to find a malicious email because they opened the wrong email or clicked the wrong link. That's the only time that we would go and update anything. Most of the time you leave it alone.
It enabled us to spend more time on other activities. Previously, when we had very strong spam filters, a lot of things were positive. It took a lot of digging. Every time somebody would send an email saying that they are missing something, we'd have to go back and release it. IRONSCALES doesn't do that. The messages that are legit go through because the false positive rate is very low. It seems to catch real problems, and it lets the clean ones through, which is what it is supposed to do. The only time we have an issue is when people word an email poorly, it might be considered a SPAM message, whereas it is not. It is legit. In such a case, I just have to release it, and it is fine.
What is most valuable?
The fact that it is set-and-forget is valuable. Once you turn it on, you very rarely have to micromanage it, whereas, with a lot of spam filters, you have to go in very often.
Its nicest feature is that other users in our company can flag something as spam, and it'll automatically flag it for everybody else in the company. It'll pull that out of your mailbox before it becomes an issue. This way 50 people don't get the same notice. One person clicks it, and it automatically goes away.
What needs improvement?
Its UI could be improved. My pet peeve with a lot of these cloud-based systems is that a lot of times, the interface for the management is a little clunky. If you live and breathe IRONSCALES all day long, you'll obviously know where everything is just from muscle memory, but the system is not designed for people to be in it all day long. You're only supposed to occasionally look at it. When things get moved around, it is not necessarily that intuitive. I'm an IT guy, and I can pretty much take the worst UI and figure it out, but the menus and the options in the interface could be a little cleaner graphically. If you have a quick problem that you want to resolve, it takes a little bit of digging in the admin console, whereas it should take a few clicks up front. That's about it, and that's a superficial issue. I understand that it is difficult to refine when you have a lot of information to deliver. It is not an easy job. Microsoft gets it wrong too.
For how long have I used the solution?
We went live at the very beginning of this year, but we started using it before that. We had a tenant change in our Microsoft system. So, we waited, and then at the very beginning of this year, we cut over to a new hosted email platform.
What do I think about the stability of the solution?
It just works. We haven't had any outages.
What do I think about the scalability of the solution?
We have a Microsoft Office 365 tenant. In that tenant, there are multiple domains or multiple companies with multiple employees. We don't discriminate or distinguish between the two. We simply apply IRONSCALES to the tenant, and it grabs all the accounts regardless of the domain they are associated with. We don't have anybody who is not being protected. We did not granularly decide who gets what. It was a very simple, shotgun approach. We have one tenant, and we have one IRONSCALES that fits in the tenant, and that was it. We did not decide to tailor it in any particular way.
It is easy to scale. When we grow, it grows with us, and if we run out of seats, I just call our customer service rep and say that we added 10 more people, and we need 10 licenses. It is that simple.
How are customer service and support?
Their service is great. We have a customer service representative. I know they have a tech team, but we haven't really had any tech questions for them since we did the deployment.
For any random question that comes up, I'll just fire off an email to our rep who can decide whether to open up a ticket with their tech team or not. Usually, it is very quickly resolvable just with our customer service representative before it requires opening a ticket. I don't have to open tickets or get a call, which is super helpful for me. I can just shoot a quick email, and they take care of it, and it is done. They can almost be my IT department.
I would rate their service a 10 out of 10. They are friendly and responsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We had Cyren previously. Cyren is great. We routed all of our messages through Cyren first, and it would flag everything, and then it would release whatever we wanted into the mailboxes. The problem was that if we found something that was spam, it was too late to release. IRONSCALES sits in the tenant. It'll pull messages out of the inbox. So, even if something made it through the first time, we can recall it. Instead of tightening up the filter and hoping nothing gets through, with this solution, even if something gets through, after we determine that something is bad, we can remove that. If somebody didn't check their messages today, and we had a spam message, by the time they get to the office, it is gone. It is not sitting in their inbox waiting. That was the major reason. It can pull out even old messages that are in their box, which is very good. It is like a housekeeping service.
Our email provider supplies anti-phishing functionality, but we went with IRONSCALES because Microsoft's spam filtering isn't as sophisticated. It is very clunky to use, and it wasn't available at the time when we signed up with IRONSCALES. Because of the AI of IRONSCALES, it is much easier to look through it, whereas Microsoft's anti-spam Defender filter is a work in progress, and they change its branding all the time. It was easier for us to stick to one that we knew would double-check and catch whatever slips through the cracks of Microsoft. Microsoft doesn't have AI, and they're not necessarily using group analysis. It is only based on whatever its filters think is good or bad. So, I just didn't trust it. I trusted IRONSCALES a little more.
How was the initial setup?
It was very simple. There were a few basic steps, and that was it. When you log into the IRONSCALES site, you set up your tenant, and you set up your domain. After that, you just have to authorize the bot in your mail tenant. Once that's done, it automatically scans your tenant for applicable mailboxes, and you tell it what you want it to do. That's it.
There are five steps to the whole process. The trickiest one is making sure that it has grabbed all mailboxes when it did its pass to make sure it has all the right accounts. As we add employee accounts to our system, it automatically grabs them and sets them up dynamically. So, there are no extra steps that we have to do. After a mailbox is removed from our tenant, it'll automatically get purged from IRONSCALES by itself. It doesn't require a lot of hand-holding.
What about the implementation team?
I was the one who did the work with the IRONSCALES team, but technically from an invoicing perspective, IRONSCALES doesn't bill us. IRONSCALES bills our security company, and we pay the security company. I'm assuming there is some kind of revenue share.
Which other solutions did I evaluate?
I don't remember what they were at the time. Another security company that we work with also recommended IRONSCALES. So, with various vettings and the blessing from our third-party security consultant, it was an easy decision.
What other advice do I have?
I would advise taking the time to learn about it during the installation. You shouldn't just rely on the IRONSCALES team to do it because they can do it in their sleep. The best way to learn how it works is to do the work. It is good to figure out what the menus do, what it means, and what the interface does. I know a lot of IT departments like to farm it out, but don't farm it out. Take the time to see how it is working and how you can best integrate with it. Some people just don't pay attention, but it is something to which you should pay attention.
I would rate it a 10 out of 10.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
IRONSCALES
October 2025

Learn what your peers think about IRONSCALES. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,008 professionals have used our research since 2012.
Information Security Analyst at a sports company with 1,001-5,000 employees
A simple and effective solution for email security and awareness training, and its mobile app makes it easy to manage incidents on the go
Pros and Cons
- "For me, the mobile app is most valuable. All other features are also very useful, but the mobile app makes it really easy for me to manage on the go. I don't have to be at my desk. I could be at the shops, or it could be in the evening when I am out, and I can get a notification on my phone that there is an incident that has been raised. I can sort it out very quickly without having to be at my work PC."
- "There is a feature called Account Takeover, which isn't what I want it to be able to do. I know that they're working on that, but when they first started the Account Takeover feature in incident management, it didn't have much information. It didn't have any usability to it. I already had tools in place that were better."
What is our primary use case?
At the time, we had an email gateway system, but we didn't have something that could remove malicious and unwanted emails from company mailboxes on the fly. That was one of the main draws for using IRONSCALES. It is very simple and easy to remediate malicious emails.
We also didn't have a user awareness training platform. We needed something that we could use to test phishing emails to train the staff in our company and increase cybersecurity awareness. These are the main tools of the platform that we use that we didn't have before.
How has it helped my organization?
By having an integrated approach of combining email security and employee awareness training, they've hit the nail on the head. It is very easy to learn and use the platform for both of those functions.
When I send out phishing campaigns, which is usually once a month or every two months, where we do a different scenario, we calculate all the results. On an ongoing basis, I can see that our reporting rate has gone up over the last six months or so. Running the campaign is obviously having an effect on the awareness of our staff. I can see that in facts and figures. Before me, we didn't have a dedicated role for doing this. In my time, after about three or four campaigns, you start to notice the benefits. After a campaign, I also communicate with each department. I liaise with them, not through IRONSCALES, and I send out the results from the campaign to them, but it is the phishing campaign that has helped. So, you start to realize the benefits after three or four campaigns.
It definitely reduces risk. In email security, the main risk is users. 99% of it is making sure your users don't click things. So, if you're using the platform to teach people, you're reducing that risk. As long as you're doing the incident part of it on a timely basis, your risk is going to be a lot lower. For me, the biggest risk reducer is just educating users.
IRONSCALES’ mobile app notifies me when a new incident is created. Within the settings of IRONSCALES, you have a collaboration app. We work with Microsoft Teams in the company, and I've linked it with that. Every time an incident is raised in IRONSCALES, it sends a notification on my Teams channel and my security channel. It is instant. As soon as an incident is raised, I get a notification in Teams that there is something to look at to review. So, whether I'm at my desk or on my phone, I will get that notification straight away. I can solve something in less than a minute. The notifications are very good and helpful, and I'm happy with this feature. I couldn't suggest any improvement there.
What is most valuable?
For me, the mobile app is most valuable. All other features are also very useful, but the mobile app makes it really easy for me to manage on the go. I don't have to be at my desk. I could be at the shops, or it could be in the evening when I am out, and I can get a notification on my phone that there is an incident that has been raised. I can sort it out very quickly without having to be at my work PC.
The awareness campaign has also been useful. Once you've completed the Phishing Awareness campaign for the users, you get the reporting functionality. You're able to send out training modules, individually or in bulk, to the staff members that need them.
It is very easy to manage. The user interface is very friendly.
What needs improvement?
I speak to the customer success manager regularly, and he does update me on what they're working on. They're always releasing new updates. There is a feature called Account Takeover, which isn't what I want it to be able to do. I know that they're working on that, but when they first started the Account Takeover feature in incident management, it didn't have much information. It didn't have any usability to it. I already had tools in place that were better.
Some elements of the Phishing Awareness campaign need to be improved. When you're creating a campaign, the visibility over some of the user interface options needs to be improved. They're aware of that, and they have worked on some of them. It is by no means bad, but it could be slightly better.
There are no additional features that I would like to be included in the next release.
For how long have I used the solution?
I'm fairly new to security, and I have been using this solution for about eight months, but my company has been using it for three or four years.
What do I think about the stability of the solution?
I've seen the platform being unavailable only a few times. It wasn't for very long, but I haven't had that for a while now. It might have gotten better. So, the availability of it is very good. The bugs in it have been features that were not quite right. They had nothing to do with availability.
What do I think about the scalability of the solution?
It is very easy because it just syncs. If we add new users or disable users, we do that on our end in Office 365 or our IT tenant. It just syncs across. We don't really have to do anything. Once we've got it going, there is literally no maintenance, and it is very easy to scale.
Our IT environment is a hybrid environment where we have a lot of resources on-premises, and we have a lot of resources in the cloud. We deploy this to the whole company. We have about 800 to 900 users with mailboxes. Including all the shared mailboxes that other people access in there for various things, at the moment, there are 1,100 mailboxes. So, there are about 200 shared mailboxes and about 800 to 900 users.
We're going to keep its usage as it is, but there might be new features that we might have a trial of. On the whole, we're happy with how we're using it at the moment.
How are customer service and support?
Their support is good. I haven't had too many issues with it. On the whole, as far as the service desk goes, I don't have too many complaints. Often, the issues that I raised can't be sorted by someone straight away because it might be a bigger bug or something like that, as opposed to just general help. I would rate them an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
This wasn't a replacement for something. This was a new implementation to augment our security. We've got an inbound and outbound platform for all the emails to go through, and this is an extra layer to that to capture any malicious emails.
We run Office 365 here, and they do have a lot of in-built security options for email. We don't take advantage of all of that. For the time being, it is a bit of 50/50, but I still run all the campaigns out of IRONSCALES. We mostly use IRONSCALES for campaigns and incidents. Microsoft doesn't have the alert functionality and mobile app. So, IRONSCALES beats it in that respect.
How was the initial setup?
I didn't implement it, but I assume it was fairly easy. I assume that it is in the cloud because I've never seen an IRONSCALES server within our environment.
In terms of maintenance, it doesn't require any maintenance. I get messages every time there is a new release, but we don't have to schedule any downtime for the updates that they do, and even if it is required, it would just be me managing it. It is simple in that respect. It couldn't get much easier.
What was our ROI?
In security, it is very difficult to quantify the return on investment because it is based on something not happening. However, it definitely has value in terms of improving awareness and reducing my time looking at things.
What's my experience with pricing, setup cost, and licensing?
I don't know about its pricing because I don't run the budget or pay the bills, but if it was extortionate, we probably would be looking to scrap it, and because we are not, I assume its price is okay.
What other advice do I have?
It is great, and I would definitely recommend it, but it is more the case of whether you need the tool and whether your current tools already do these functions. If you're missing one of the two functions of this software, then obviously, I wouldn't recommend it.
I don't have much to compare it against. If this company was a lot bigger, I don't know if it would be a lot harder to manage. Most probably it won't be. It seems fairly good for companies of all sizes.
We have enabled Themis, the AI function, at the moment on an ongoing trial basis. It can automatically remediate things. There are two ways that incidents are raised in IRONSCALES. You've got users reporting emails themselves, and then, you've got the logic of the app or the AI picking it up. It is great. It doesn't pick up everything, but we've got various platforms in place, and not all of them pick up everything.
When it is used in what we call defense-in-depth, it is great, but it doesn't pick up absolutely everything. It does pick up the majority of malicious emails, and it is good for that. There is a module in it that automatically remediates emails. It will look at them in a capacity and make a judgment by itself on what to do with them. At the moment, the logic of that is okay, but it isn't as good as someone who has experience making a judgment on it. It is however good in terms of picking up an incident in the first place.
It can enable you to spend more time on other activities. Most of it comes down to understanding the depth or format of an incident. When I first started, I was new to it. It was not massively complicated, but there was a learning curve for me in security as opposed to me in IRONSCALES. If someone with a lot of experience is using it, it would definitely reduce their time in remediating issues and help them crack on with other tasks.
I would rate it a nine out of ten. There are a few bugs and issues, but they are sorting them. It is not perfect, but it is very good. It has room for improvement, but for what I use it for, it is great.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Reduces manual review time, offers great pricing, and is easy to set up
Pros and Cons
- "For what was being offered with IRONSCALES, I feel like we got an incredible deal."
- "The only thing that I could say is that some of the reporting features could be better."
What is our primary use case?
We purchased the software so that we could have better software to protect our users against phishing attempts.
How has it helped my organization?
We were looking to minimize the amount of time that it took, one, for our users to report incidents and then, two, to do the research and block those different domains and email addresses that were sent to us.
What is most valuable?
We have three companies. The fact that we can put all companies under one umbrella and take care of all three companies in one space is probably the best feature that they have.
We haven't used the employee awareness training as of yet, although we do plan on using it, however, the effectiveness of the email security itself has been tremendous. It's cut down on our time and our employees' time. The ability to have zero-day effectiveness against phishing attempts has been critical to our business.
We do use IRONSCALES' automated detection and response capabilities. It's 99% effective. Not only does IRONSCALES do a great job of detection within the email prior to it actually being received in our users' mailbox, but we also have the whole IRONSCALES community across the world mitigating other phishing attempts, a lot of times we don't even see or it's classified prior to even reaching our users' mailboxes.
The automated detection and response capabilities decrease the time we spend manually reviewing email events by probably a hundredfold. Just by the simple fact that if other community members in IRONSCALES have already seen the email and have already classified it as a phishing attempt or a spam attempt, I then don't have to go in as it's already automated and it's already been resolved by the community. The fact that IRONSCALES software goes and classifies it before I even have to get in has been paramount to the amount of time that we've saved using IRONSCALES.
I use IRONSCALES' mobile app. It does notify you when a new incident is created. It also notifies us when it's been remediated either by the community or by them. It also lets us know if there is a new incident that's been created that it doesn't know how to classify.
The capabilities the mobile app provides us with for alerts that need to be dealt with right away are great. The fact that I can just get onto IRONSCALES right from my mobile device if I'm not home, or if I happen to be in a meeting where I can't get away from the screen that I'm currently in and I can still do it, I can still take care of the issue from my phone itself. Overall, the app works as if I was sitting in front of a computer. I see truly no differentiation between the two, other than the size of the screen that I'm looking at.
What needs improvement?
I really don't see anything to be improved upon just yet. We haven't gotten into the training, although we do plan on using it. As far as email security, as far as community support, I haven't really found anywhere that I feel as though I could comment on making a change for the better.
The only thing that I could say is that some of the reporting features could be better. If I could have just a separate section for specific reports or have the ability to maybe create reports and put them down that left-hand navigation to be able to access them a little bit easier would be great.
For how long have I used the solution?
We've been on IRONSCALES for four months now.
What do I think about the stability of the solution?
We haven't seen this solution go down once, and it's definitely made our lives easier.
What do I think about the scalability of the solution?
IRONSCALES is completely scalable with what we have. The simulation and the training that they offer are great. While I've seen the demo of it, I haven't used it personally, the ability for us to provide training to our users, as well as upload our own individual videos, if we create them, is useful. I know that recently they upgraded to some other partners to be able to provide training, so the scalability of it looks pretty fantastic.
As our business grows, we will increase usage. With new users and new people being onboarded, we're going to be using it more and more. Towards the end of July, we're going to start our training and test simulations to roll out to our users so that we can make sure that they understand what phishing is and how to catch it when it does come in.
How are customer service and support?
I've only used technical support once and they were able to fix the issue within ten minutes.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we were using Microsoft Exchange Server Email Defender.
On average, our users were getting at least 15 to 20 phishing attempts per day. When you equate that to the time it took for them to send over the phishing alert and then for either myself or my colleague to do the research, trace the message, do the background on the IP address of the sender, and then either add or allow the email, it was just too time-consuming for us to do on a daily basis.
How was the initial setup?
The deployment was done in three integration points - one for each business, and it was three lines of code. It was extremely simple.
We support a total of 326 mailboxes across three companies that are 90% remote. Everything goes through Office 365, and IRONSCALES sits outside of our Office 365. Everything gets remediated either at the point of entry to our Office 365 instance. Or, if something does get through and it is a phish, it's then remediated and all the mailboxes are removed until such time that we determine it either to be safe or removed completely if we determine it to be phishing or spam.
What about the implementation team?
The setup was handled by myself, my colleague, and, I believe, somebody from IRONSCALES.
What was our ROI?
We have easily seen a return on investment. According to one of our reports, in the past 30 days, we've saved over two and a half hours of time. If a company can just equate that to what my time costs, what our users' time costs, and the amount saved, there is just incredible ROI.
What's my experience with pricing, setup cost, and licensing?
The pricing is right down to what we wanted to spend. Obviously, time is money. The amount of time that we were spending per day was costing us effectiveness, was costing our users' time, and was costing us money due to the time that it took out of our day. For what was being offered with IRONSCALES, I feel like we got an incredible deal.
Which other solutions did I evaluate?
Before choosing this product, we did evaluate other options. Unfortunately, I can't remember some of the names as I was already on board with IRONSCALES when we did the demo. I will say that for some of the other options that we had to choose from, the cost was a big issue for us. Some of them were more expensive than what we needed as a smaller business. I could see some of their benefits if we were tenfold, however, it wasn't cost-effective for us to go with some of the other ones. It was too much for what we needed.
Also, one of the downsides of most of the other ones that we found was that they would still allow the email to reach the user's mailbox and sit there until we actually remediated the issue.
There was only one other company we evaluated before IRONSCALES that actually provided a mobile solution for us so that if we needed to be on our phone and remediate some of these phishing attempts, we would only be able to do it either through IRONSCALES or the other company.
What other advice do I have?
I'd rate the solution ten out of ten. There isn't one thing I don't like.
If a company is looking for something that is extremely robust, that has the ability to catch zero-day incidents, and they're not looking to spend an arm and a leg, there's no other choice. It's got to be this product.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Endpoint Cyber Security Analyst at a tech company with 51-200 employees
The automated detection and response feature handles most of the job 
Pros and Cons
- "The biggest benefit is that we get fewer phishing and spam emails, so using IRONSCALES has made our environment much safer."
- "There's room for improvement in the campaign management. IRONSCALES has many built-in templates that I use, but you can also build templates from scratch. However, the interface for creating custom templates needs to be updated."
What is our primary use case?
Phishing emails and spam are challenges companies of all sizes face. IRONSCALES acts as a second layer on top of the Microsoft mail relay we use. It scans every email coming into our organization and automatically checks the validity. We also check manually in some cases.
While we mainly use it for the mail relay, IRONSCALES can also act as a phishing campaign simulator. We can send simulated phishing emails to our colleagues to test their readiness. 
Our entire organization uses IRONSCALES across many locations worldwide in South America, Asia, Europe, and North America. All sites use the system to protect the mailboxes and just act as a mail relay. We have about 8,000 users.
How has it helped my organization?
The biggest benefit is that we get fewer phishing and spam emails, so using IRONSCALES has made our environment much safer. While I wasn't here when they deployed the system, I believe they saw benefits right away.
What is most valuable?
The feature I use the most is the main relay. IRONSCALES was designed around that, but phishing simulation management is also a handy tool that I don't see often. Combining these features enables a user to be more comfortable with the simulations.
For example, one of IRONSCALES' features is an Outlook extension that lets you report phishing emails and other stuff that looks malicious. In our training, we encourage our colleagues to click this button to report as many emails as possible. Reporting suspicious emails should become part of our employees' everyday routine. The training campaign usually helps us catch our colleagues outside their comfort zone to see if they're paying attention to all these suspicious emails they receive.
AI and machine learning are essential components of the product. It automatically can identify phishing emails and classify them according to several factors. I'm not sure how it works, but there's a ranking system that ports onto every sender and email we receive. This artificial intelligence can conduct a thorough search that's sometimes better than humans. 
The automated detection and response feature handles most of the job. I only need to classify a few emails manually each day. Artificial intelligence does everything else automatically for me. Without this technology, we would have to sort 1,000 emails each day manually. IRONSCALES cuts that down to maybe 50.
The IRONSCALES mobile app is convenient to use outside working hours. It's not my primary tool, but it's nice not to need to open your laptop whenever you would like to classify something. You can use the app to check up on the system. 
What needs improvement?
There's room for improvement in the campaign management. IRONSCALES has many built-in templates that I use, but I can also build templates from scratch. However, the interface for creating custom templates needs to be updated.
I've already contacted IRONSCALES with some features I'd like to see, and they've promised to implement them. For example, let's say I send campaigns using customized tags assigned to each user. If I would like to send a campaign to my colleagues in China, I would send the campaign using a tag that says China. In many cases, new users don't have tags.
I asked IRONSCALES to add the ability to send campaigns to colleagues that don't have any tags. They promised this feature would be available during the next update.
For how long have I used the solution?
I've been using IRONSCALES since I started working here at my current company about a year ago. 
What do I think about the stability of the solution?
IRONSCALES is stable. I can't think of any outages. 
What do I think about the scalability of the solution?
We can grow as much as we want. We are growing right now and adding new sites to our company.
How are customer service and support?
I rate IRONSCALES support 10 out of 10. They provide support in less than 24 hours. I have never had a problem with them, and they always solve my issues.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
The company previously used Microsoft ATP, which required a lot of manual work. I was told that they used to spend a lot of time manually sorting the emails by phishing, spam, etc. The company switched to IRONSCALES because they wanted something to help automatically sort stuff and get faster results.
How was the initial setup?
Though I wasn't here when IRONSCALES was deployed, I saw the system requirements and a basic guide to implementing the system. It was straightforward.
After deployment, it doesn't require much maintenance. It does everything automatically as well. IRONSCALES supports older versions of Exchange and local Exchange servers that require manual updates of the add-ons they use to protect the mailboxes, but we don't use those services.
What other advice do I have?
I rate IRONSCALES nine out of ten. Some improvements to the campaign management might bring it up to ten. It's a great system. I would recommend it if you only need a mail relay. On top of that, there are additional advantages of using the system, like the campaign manager that complements the mail relay.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Digital Risk Intelligence Partner at a comms service provider with 1-10 employees
Easy to set up with great AI and very good threat-sharing capabilities
Pros and Cons
- "The stability is good."
- "The integration with Google Suite needs to be better. it's something they can work on."
What is our primary use case?
We help customers use this to help them to secure against business email compromises, phishing, and impersonation.
What is most valuable?
They're outstanding as a solution. They have a threat-sharing capability so that you get information from all the customers regarding any phishing attack. That's a great feature for us due to the fact that we get information very fast if someone else in the world has seen that email.
The artificial intelligence is excellent. They are able to use it to recognize phishing emails due to the language used.
The initial setup is very easy.
The solution can scale.
The stability is good.
We've been satisfied with technical support.
What needs improvement?
The integration with Google Suite needs to be better. it's something they can work on.
The pricing is a bit high.
In the future, I'd like to see digital exposure of the users, such as credential exposure, or this kind of feature.
For how long have I used the solution?
We've been working with the solution over the past year.
What do I think about the stability of the solution?
The solution has been very stable. It's reliable. We haven't found bugs or glitches and it doesn't crash or freeze.
What do I think about the scalability of the solution?
We don't have any issues with scaling - even when dealing with many different customers.
Our clients range in size. We help companies with anywhere from 50 users to thousands of users.
How are customer service and technical support?
We have been satisfied with the solution's technical support. They have been helpful and responsive.
Which solution did I use previously and why did I switch?
We have used Darktrace in the past. The reason we are looking into Darktrace is to have another option. However, for us, Darktrace is not so good as IRONSCALES. IRONSCALES is easier to use, easier to implement, and more accurate when it comes to false positives.
We've also worked with Proofpoint and some Microsoft-owned options, however, we haven't worked with anything else.
How was the initial setup?
The initial setup is amazing. it's not overly complex or difficult at all.
It was fast, easy, and straightforward to implement and deploy. On average, with the customers, it takes us around 10 minutes to one hour to set everything up, depending on the size of the customer.
What about the implementation team?
We can assist our clients with the initial setup.
What's my experience with pricing, setup cost, and licensing?
We have a yearly licensing contract. The pricing is a bit expensive, and we'd, of course, like it to be lower, however, we really like the product.
What other advice do I have?
We are a customer as well as an integrator. In some cases we sell the solution, in some cases, we provide the customer with the service. We are a security service provider.
We are working with the latest version. IRONSCALES is a universal service cloud for service. So you always have the latest one.
I would recommend the solution to other users and companies. I couldn't believe that it could filter out 35% of the email. We've very satisfied.
I'd rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. System provider, Partner
Systems Engineer at a tech services company with 10,001+ employees
Has an easy to setup phase and can be managed conveniently by the users
Pros and Cons
- "The most valuable features of the solution are that it is easy to set it up, install, and manage the product."
- "The tool supports 15 to 16 languages, but the content it uses in the training in Spanish has certain limitations."
What is our primary use case?
I use the solution in my company to stop phishing and spam efficiently and automatically.
What is most valuable?
The most valuable features of the solution are that it is easy to set it up, install, and manage the product.
What needs improvement?
I think maybe on the side of the awareness training, the tool can improve a little more information and have some other languages since even though English is good, Spanish is not so good. The tool can improve the content in Spanish and other languages. The tool supports 15 to 16 languages, but the content it uses in the training in Spanish has certain limitations.
For how long have I used the solution?
I have been using IRONSCALES for a year. My company is an end user of the tool.
What do I think about the stability of the solution?
It is a very stable solution as it is software that runs in the cloud. I didn't have any outages with the tool.
What do I think about the scalability of the solution?
It is a very scalable solution. I know the tool scales up very well. Some of our customers have thousands of use of mailboxes. In my case, only one hundred users use the tool. It requires very little installation, but I know thousands of customers.
How are customer service and support?
The technical support offered is very good. The tool's support team attends very quickly to the support tickets raised. The technical support is very good at resolving issues.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used a security gateway from Forcepoint, which was a lot more complicated to maintain and set up. Forcepoint decided to discontinue its solution for email gateway, and then it decided to introduce another solution in the market that includes AI.
How was the initial setup?
The product is easy to set up as it is an API-based solution. With IRONSCALES, you don't have to do anything on the platform. You just need to do the integration and the connection with Office 365 tenants, and that is it.
I rate the product's setup phase as a ten out of ten.
The solution can be deployed by one person from IRONSCALES, who will create the tenant for me. Then, I do the rest of the setup process, which includes three or more steps, but it can be done in minutes.
The solution can be deployed in 15 to 30 minutes. 
What's my experience with pricing, setup cost, and licensing?
The product is available as a middle-priced tool. I think it is not the cheapest solution. There are other solutions apart from IRONSCALES that are more expensive, while some are a little bit more cheap, but they are not available with the same capabilities.
What other advice do I have?
The automated response capabilities are very accurate for detecting suspicious activities and suspicious languages used by the attackers.
The only people needed when using the tool are to take care of the console and an analyst. In some cases, some incidents require an analyst to complete the analysis of the email. I don't create incidents that can be automatically resolved by AI. I create incidents that need a review from an analyst. The only people who need to be aware of the incidents and where such details should not be classified is when it comes to analysts. I don't need to do any maintenance process for the tool every day. Everything is available as a service, so I don't need to do anything to maintain the platform apart from dealing with the non-classified incidents.
The tool uses a lot of AI technologies to detect the accuracy of the email, especially to filter out phishing emails. It not only detects phishing emails but also provides a preview of who the attackers are before we receive the real phishing email. It is not just to detect phishing emails but also to detect the intent of the attacker in creating a phishing email.
I rate the tool a nine and a half out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free IRONSCALES Report and get advice and tips from experienced pros
        sharing their opinions. 
Updated: October 2025
Popular Comparisons
Microsoft Defender for Office 365
Darktrace
Cloudflare One
Proofpoint Email Protection
Microsoft Exchange Online Protection (EOP)
Cisco Secure Email
Abnormal Security
Check Point Harmony Email & Collaboration
Mimecast Email Security
Fortinet FortiMail
Avanan
Barracuda Email Security Gateway
Trend Micro Email Security
Perception Point Advanced Email Security
Sophos Email
Buyer's Guide
Download our free IRONSCALES Report and get advice and tips from experienced pros
        sharing their opinions. 
Quick Links


















