Mimecast email security, archive and retention licensing covers Mimecast’s original product line: email security in the cloud gateway and API-based forms, the cloud email archive and its retention settings, and related services priced on domains or data volume. All of them are Services under the Mimecast Service Agreement. They are counted in Permitted Users unless the Service Schedule defines another quantity.[3] The Schedule defines other quantities for DMARC Analyzer, Brand Exploit Protect and the Governance, Compliance and Insights (GCI) Services.[2]
Editions
Email Security plans
Since 2025-08-15, new Mimecast customers must buy one of the current email security plans. Products that existing customers already hold remain online, uninterrupted and unchanged.[1] The Plans page lists three plans:[1]
| Plan | Vendor description | Catalog row |
|---|---|---|
| Critical | “Protect the top attack vector with world-class, AI powered Email Security”. Lists BEC protection, social graphing, on-click URL analysis, QR code protection, attachment sandboxing, malware and spam scanning, outbound and internal scanning, browser isolation, email backup and recovery, email continuity and large file send (Cloud Gateway), and protection for collaboration tools. | Email Security Critical plan |
| Advanced | “Enhance AI powered Email Security and add data protection” | Email Security Advanced plan |
| Premium | “Get comprehensive protection that spans across your collaboration tools” | Email Security Premium plan |
The page shows the same protection list under all three plans and gives no per-plan differences beyond the descriptions.[1] The detailed entitlement therefore has to be read from the Services Order. Moving from a legacy bundle to the new plans requires signing a one-page legal agreement that covers AI features. It may also cost more, with standard price increase terms applying.[1] Catalog proof: New email security customers must buy the current plans from 2025-08-15.
Deployment method
Email Security is deployed either MX-based (Cloud Gateway), where mail passes through Mimecast before delivery, or API-based, where Mimecast scans Microsoft 365 mailboxes after delivery through Microsoft Graph.[4] The two methods differ in scope:
- Mimecast describes the threat detection as identical in both.[4]
- API-based deployment currently lacks the business continuity features: backup, restore, Large File Send and Secure Messaging.[4]
- The choice is made at onboarding and cannot be switched. Changing method requires a new Mimecast account.[4]
Catalog proof: The Email Security deployment method cannot be changed after onboarding.
Services with their own metric
- DMARC Analyzer is priced by the number of customer domains subjected to the service. That number is set on the Services Order, whatever other provisions say.[2]
- Brand Exploit Protect protects customer domains from impostor websites. It is hosted in Belgium. The customer names each Domain up to the maximum on the Services Order, and Takedowns are limited to the number on the Services Order.[2]
- Managed Threat Response is a managed, analyst-led service for triaging email that end users report as suspicious. Its tier is set out on the Order Form. It integrates with the customer’s Mimecast Email Security tenant.[11]
Metrics
| Service | Catalog metric | Rule |
|---|---|---|
| Email Security plans, Cloud Archive, MTR | Permitted User | The default usage quantity. The Service Order caps the number of Permitted Users.[2][3] |
| DMARC Analyzer | Customer domain | Priced per customer domain.[2] |
| Brand Exploit Protect | Protected domain and takedown | Maximum Domains on the order. Takedowns are charged per request received, not on completion of a successful Takedown.[2] |
| Backup & Recovery | Pooled storage per licensed seat | Each licensed seat contributes 50 GB to a tenant-wide pool.[9] |
| Simply Migrate | Migration data volume | 20 GB per Permitted User subscribed to the hosted services.[10] |
Catalog proof: DMARC Analyzer is priced per customer domain; Brand Exploit Protect counts Domains and charges Takedowns per request.
Counting / floors
Who counts. The contracts count Permitted Users, meaning end users authorized to access and use the Services.[3] They do not define separate rules for shared mailboxes, aliases, service accounts or departed employees.[3] In Mimecast’s directory, an alias address is resolved to the user’s primary address when mail arrives, and all policy scoping is based on the primary address.[14] In the MSP channel, disabled user accounts still count toward the licensed seat total until a downsell is processed.[15] Catalog proof: Usage quantity defaults to Permitted Users; MSP accounts: disabled users count until a downsell is processed.
Reasonable usage. Service levels do not apply where use exceeds reasonable usage allowances. For Services that include archiving, journaling or SMS messaging, the limit is three times the typical average user, measured against Mimecast’s internal benchmarks.[5] Mimecast may contact customers above the allowance to renegotiate contract terms.[5] The MSP version of the SLA applies the same allowance and lets Mimecast renegotiate with the Partner.[13] Heavy archive users, such as journaling mailboxes, therefore affect the commercial position, not just performance. Catalog proof: SLAs exclude usage above three times the typical average user.
Domains. For DMARC Analyzer, the customer is responsible for adding all owned domains and publishing a DMARC record for each.[2] For Brand Exploit Protect, additional Domains may be subject to additional fees. Only Domains the customer owns or legally controls may be registered.[2]
Archive retention
Archive retention is where Mimecast add-ons most often appear on a Services Order.
Retention by subscription. The retention period set for the account determines how long email and file data stays in the archive. When a message reaches the end of that period, it expires and cannot be retrieved.[6] The period differs by the service subscribed, and security-only accounts keep data for 30 days.[6] Customers can increase or upgrade retention, or ingest historical email, through their account representative.[6] Catalog proof: Archive retention depends on the subscribed service; security-only accounts keep 30 days.
Perpetual Retention. After the Perpetual Retention upgrade is enabled, data archived from then on is kept for the duration of the Mimecast contract. The upgrade does not change the expiry date of messages already in the archive, and it cannot restore messages that have expired.[6] A separate Perpetual Retention Adjustment service removes expiry dates from existing messages. It is priced on the assumption that the whole archive is adjusted.[6] Catalog proof: Perpetual Retention covers only data archived after the upgrade.
Minimum and maximum retention. The account-level Minimum Retention setting should match the period in the customer’s agreement when Compliance Protect is enabled. An administrator must validate it, and it cannot be decreased.[7] The Maximum Retention setting determines how long the account keeps archived data. A change to it must be validated by a Super, Full or Partner Administrator.[12] Catalog proof: Archive Minimum Retention should match the agreement and cannot be decreased.
GCI Suite. The GCI Suite supports a seven-year retention model by default, with extensions available on request.[8] Retention Adjustments cannot extend retention beyond the account-level Maximum Retention. Raising the Maximum Retention is a separate account change.[8] Catalog proof: GCI archiving retains data for seven years by default.
Backup & Recovery
Backup & Recovery backs up Microsoft 365 data. It is sold independently of the GCI Core, Pro and Max tiers.[8] Storage is pooled at tenant level at 50 GB per licensed seat, and additional capacity can be purchased.[8] Any one mailbox may use more or less than its notional 50 GB, provided the tenant stays within the pool.[9] Retention is set per policy, from 1 month to 99 years. For mailbox Backup & Recovery Plan customers it is limited to 1 year.[9] The service is not represented as suitable for bulk recovery of an entire Microsoft 365 tenant.[8] Under the Service Schedule, usage that materially exceeds fair use limits may lead to additional fees or an upgrade.[2] Catalog proof: Backup & Recovery storage is pooled at 50 GB per licensed seat.
Virtualization & partitioning
No virtualization rules apply to the hosted services. The one installable licensed component in this product line is the Simply Migrate software. The licensee may download one copy on one computer or server it controls. It may keep one backup copy, which may be used only while the original is inoperable.[10] Catalog proof: Simply Migrate may be installed once, plus one backup copy.
Cloud / BYOL
The API-based deployment runs on top of the customer’s Microsoft 365 tenant and supports Microsoft 365 only. The MX-based gateway works with any email platform.[4] Microsoft 365 trial tenants are not supported for the GCI Suite.[8]
Programs
Legacy data migration. The Simply Migrate software is provided as part of Professional Services under its own EULA.[3] Its terms work as follows:
- It supports only PST and EML data.[10]
- Migration volume is limited to 20 GB per Permitted User subscribed to the hosted services. For example, 100 users allow 2 TB.[10]
- More capacity must be bought in an amount equal to the initial purchase. A customer with a 2 TB entitlement that needs 3 TB must buy another 2 TB.[10]
- The licence ends when the data limit is reached.[10]
- Under the GTC, historical data for an import must reach Mimecast within 12 months of the start of the engagement. Data received later incurs additional fees.[3]
Catalog proof: Simply Migrate is limited to 20 GB per Permitted User; Historical data for import must be delivered within 12 months.
Audits and compliance
The Simply Migrate EULA is the only published Mimecast document with an audit-style clause. On Mimecast’s written request, the licensee must review its use of the software and certify compliance in a written instrument signed by an officer. If it finds non-compliance, it must remedy it and notify Mimecast.[10] Using the software for more data than the Services Order specifies is outside the licence.[10] Catalog proof: Simply Migrate licensees must self-certify compliance on request.
Out of scope
- The contents of legacy email security bundles sold before 2025-08-15, which Mimecast does not publish.
- The SLA service credit tables for email delivery, DNS resolution and search performance.
- Web Security, Secure Messaging and Large File Send as stand-alone services. They appear in plans and evaluation terms, but no separate metric is published for them.