Every security team knows the abuse mailbox tax. Users flag newsletters and vendor promotions as suspicious, and analysts burn hours triaging mail that was never a threat, while the same bulk mail buries the messages employees actually need. Graymail isn't malicious, but treating it as mere clutter misses the point: the same high-volume stream is where reconnaissance and brand impersonation like to hide. Sorting it blind is its own risk.
Building on existing graymail detection, today, advanced graymail protection is available in public beta for Sublime Enterprise customers. It's built into the platform you already run, across Microsoft 365 and Google Workspace, and included in your Enterprise plan.
“Sublime’s advanced graymail protection reduced the sales and marketing noise across our email environment, especially in our priority inboxes. It gave us a cleaner way to separate graymail from phishing, reducing distractions and avoidable escalations so the team could stay focused on real threats.”
- Olindo Verillo, Director, Detection & Response, Cerebras
Every graymail classification you can open and inspect
Most tools sort bulk mail in a black box: messages move, and when someone asks why, there's no answer. Graymail protection works the other way. It's classified during the same analysis that detects threats, using transparent signals your team can inspect, so there's no second engine to stand up or tune. Every graymail decision traces to the same readable detection logic behind a threat verdict, so your team sees exactly what fired and why, and adjusts it if they disagree. That's what makes this a security control, not a productivity filter bolted on the side.
Routed by policy, tuned to every user, in both directions
An Automation routes graymail to the folder your org already uses for it, either Promotions (recommended when available) or Junk in Microsoft 365 and Spam in Google Workspace, so it lands where users already look rather than in a daily digest to dig through or a quarantine portal to log into. When a user pulls a sender out of that folder, Sublime keeps their future mail in the inbox; when a user moves a sender in, Sublime routes future mail there. That learning works in both directions, in either folder, with no personal filters to build. Turn it on for a handful of mailboxes, watch how it behaves for a few days, and expand at your own pace.
Visibility for the whole team, on the platform you already run
Graymail gets its own view, with revamped navigation that keeps it out of your Threat Log queue and security workflows, and it surfaces in Attack Insights with volume, top senders, and the reason behind each classification.
Try it, and give us your feedback
Advanced graymail protection is in public beta now for Sublime Enterprise customers. If your team is losing hours separating suspicious mail from bulk noise, this is the moment to pilot it. Reach out to your Success contact or file a Support request to have it enabled on a pilot set of mailboxes, pick your destination folder, and expand from there. Full setup steps are in the graymail docs.
See how graymail protection works on the feature page. New to Sublime? Get a demo.
Get the latest
Sublime releases, detections, blogs, events, and more directly to your inbox.
.png)
.png)


.avif)