Introducing Valimail + Sublime for modern email security
Editor’s note: This post was published when Valimail and Sublime Security announced their partnership. It was updated in August 2026 to reflect the product integration, which is now available.
Email attacks are becoming more sophisticated as AI makes impersonation easier to scale, and harder for users and security tools to spot. Today’s phishing and Business Email Compromise (BEC) campaigns combine spoofed senders, lookalike domains, and compromised infrastructure to slip past legacy defenses.
That’s why Valimail and Sublime Security are partnering to give security teams a stronger, more comprehensive layer of protection, bringing together Valimail’s outbound authentication expertise with Sublime’s inbound threat detection to stop modern email threats from both sides.
Together, Valimail and Sublime help customers take a multi-layered approach to email security by addressing both outbound email identity and inbound threat detection. Valimail protects the outbound side by helping organizations stop spoofing and impersonation with automated email authentication. Sublime defends the inbound side with organization-specific detection, prevention, and response, stopping sophisticated BEC, phishing, and vendor compromise while autonomous agents handle triage and coverage gaps.
The result is stronger protection, faster response times, and less manual work for security teams. Plus, with the Active Threat Detection integration now available, the two sides connect directly: a malicious sender surfaced through Valimail can be automatically blocked from the inbox in Sublime.
Why Valimail + Sublime = better together
Email security is often managed in silos. Outbound authentication is treated as one initiative, inbound detection another. But attackers don’t operate that way, and disconnected defenses can leave gaps behind.
Legacy Secure Email Gateways (SEGs) were not built for today’s threat landscape, and many organizations are now stitching together point solutions to fill the gaps. Valimail and Sublime provide a modern alternative, making it easier for customers to transition away from legacy SEGs without adding complexity.
By working together, we help organizations deploy both outbound authentication and inbound detection in a coordinated way, reducing deployment friction, eliminating redundant tooling, and offering a more cost-efficient path beyond legacy SEGs.
A more complete approach to protection
Think of Valimail + Sublime as a two-pronged defense. Valimail enforces DMARC and continuously manages authorized senders, stopping impersonation at the source. This is crucial for reducing the risk of attackers spoofing owned domains or executive identities and ensuring continuous protection as email infrastructure changes.
Sublime then provides the detection, prevention, and response layer. It helps organizations identify and stop sophisticated phishing, BEC, hijacked threads, and vendor compromise, while minimizing false positives, autonomously triaging user-reported emails, and closing new coverage gaps in hours, not weeks.
Together, Valimail and Sublime help customers:
- Prevent more impersonation-based attacks
- Improve DMARC enforcement across domains and sending services
- Reduce false positives and manual email review
- Respond to threats faster as attack patterns evolve
- Automate inbound blocking for identified outbound threats
- Reduce manual labor for strained teams
Better together for security teams
Security teams are already managing a high volume of alerts, investigations, and operational overhead. Email security should reduce that burden, not add to it. Valimail and Sublime bring together automated identity protection and organization-specific threat detection and response, helping organizations strengthen protection across both outbound and inbound email without adding unnecessary complexity.
Our partnership is also delivering stronger protection. The Valimail + Sublime integration is now available, and it helps teams move faster on discovered threats. When Active Threat Detection in Valimail surfaces a suspicious or malicious sender targeting your domains, reporting it as a threat passes that intelligence straight into Sublime, where a dedicated blocklist and a matching detection rule apply the action you choose to inbound mail from that sender going forward. No exporting indicators, no writing rules by hand.
The combined approach accelerates time-to-value, helping teams close protection gaps faster, reduce manual effort, and build greater trust in email.
How the integration works
Setup lives in Valimail Enforce under Account Settings, Integrations, and takes a few minutes. Once it is connected:
- Active Threat Detection surfaces suspicious and malicious senders targeting your domains.
- You review a sender and report it as a threat.
- Valimail adds that sender to a dedicated blocklist in your Sublime tenant and maintains a matching detection rule, which applies the action you selected, such as quarantine, to inbound mail from that sender.
The integration creates and maintains only the one blocklist and the one rule it needs, and it applies the action your administrator chose. Nothing else in your Sublime configuration changes.
Valimail Enforce customers with the Active Threat Detection add-on can find full setup steps in the Valimail help center.
Better together for solution and service providers
The channel is at the core of our partnership. By bringing together Valimail’s outbound authentication with Sublime’s inbound threat detection and response, VARs, MSSPs, and strategic partners can offer customers a more complete approach to email protection that is easier to position, deliver, and manage.
Ready to modernize email security? Contact Valimail or Sublime to see how this joint solution can be deployed in your environment.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.