We're a Google Workspace organization with more than 600 users, currently relying on Gmail's built-in email protection. The quarantine and message-management experience has been frustrating, so we're comparing Check Point Avanan and IRONSCALES.
IRONSCALES is slightly less expensive, but the difference is small enough that effectiveness and ease of management matter more. We're considering running proof-of-concept tests with both products at the same time, although we can only use detect-only mode during the parallel test.
For anyone who has used either product recently with Google Workspace—or both products—which would you choose today and why? I'd also appreciate hearing about unexpected issues during deployment, false positives, quarantine workflows, remediation after delivery, and how each product handles malicious calendar invitations.
7 Answers
We use IRONSCALES and are happy with the results, including for several Google Workspace customers. I haven’t performed a recent head-to-head evaluation against Avanan, so I wouldn’t claim it is better overall, but it has been stable and effective enough that we’ve continued using it.
Avanan has generally been a top-tier option in my experience, although most of that experience is with Microsoft 365 rather than Google Workspace. Its API-based integration is a major part of the product, so I’d specifically validate that the Google implementation provides the same level of visibility and remediation.
Our experience with Check Point was mixed. It was effective, but it created more support work than expected: inline inspection interfered with calendar delegation, internal-only mailing groups had issues, and poor sender DNS records sometimes resulted in administrative quarantine events where the choices were to whitelist, bypass protections, or release messages repeatedly. The inline inspection can also affect calendar-event handling, so I’d test those workflows carefully rather than assuming API remediation covers everything.
It was still much better than Barracuda for us, but compared with a well-tuned native mail-security platform, the administrative burden was significant.
Don’t judge the products only by their feature lists during the POC. Track false positives, detection rates, time to identify threats after delivery, how reliably messages are pulled back, and how easy quarantine management is for both administrators and end users.
Because you’re using Google Workspace, definitely test malicious calendar invitations. Removing the email does not necessarily remove an event that has already reached a user’s calendar, so verify exactly what each product cleans up. Detect-only testing is useful for comparing catch rates, but a short remediation phase with each product will reveal much more about the operational experience.
We switched from Mimecast to Check Point and found Check Point’s detection noticeably more accurate. I haven’t evaluated IRONSCALES recently, so I can’t make a direct comparison, but Avanan has been the stronger product in the environments I’ve seen.
We’ve used Check Point Email Security for several years and it has worked well for us. It may require some transport rules to route mail through the inline protections, but once configured, the protection has been reliable. I’d also consider testing Abnormal as a third option if your evaluation process allows it.
We moved from Barracuda to Check Point and the difference was dramatic. It caught a lot of messages that had been getting through before, and the controls are much more granular. Overall, we’ve been very happy with it.

That’s a good point about calendar events. We’ll make sure the POC includes invitations that are delivered before the related message is detected, not just ordinary phishing emails.