These already sit on the mailbox, so they can pull a message from every inbox and reply to the person who reported it without another integration.
- Reports arrive via
- Report buttons, abuse mailboxes, Google Workspace alerts
- Finds other copies
- Yes: finds the rest of the campaign across the tenant
- Removes from inboxes
- Yes: removes related messages automatically
- Human sign-off
- Tone, guardrails and policies are configurable
Sorts each report as malicious, spam, safe or a phishing simulation, so reports of your own training emails don't reach an analyst.
Replies to every reporter with an outcome email written for that message, and the reporter can ask follow-up questions. Works with Microsoft 365 and Google Workspace.
Source: Abnormal AI: AI Security Mailbox. Checked 21 September 2026.
- Reports arrive via
- Report Phishing button, in Microsoft 365 or Google Workspace
- Finds other copies
- Yes: clusters it with similar emails
- Removes from inboxes
- Yes: can remove all similar messages automatically
- Human sign-off
- Anything from flag-only to full auto-remediation
Evaluates each report with its adaptive AI and insights from its customer community, and groups it with similar emails already in the tenant.
Automation is set by policy, for example auto-quarantine for confirmed phishing and manual review for low-confidence cases, and it can notify the users affected.
Source: IRONSCALES: SOC automation. Checked 21 September 2026.

Security Copilot Phishing Triage Agent
- Reports arrive via
- The Outlook report button, once reported-message monitoring is on
- Finds other copies
- Not stated
- Removes from inboxes
- No: it classifies; an analyst takes action
- Human sign-off
- Closes false positives; confirmed phishing stays open for an analyst
Analyses the email body, detonates files and links, reviews screenshots and uses Microsoft threat intelligence and advanced hunting, then explains its verdict in plain language.
Needs Defender for Office 365 Plan 2 and provisioned Security Copilot capacity (SCUs). Microsoft's usage dashboard shows a cost per email processed, and analysts can teach the agent through feedback.
Source: Microsoft Learn: Security Copilot Phishing Triage Agent in Microsoft Defender (11 August 2026). Checked 21 September 2026.

CLEAR (PhishAlarm and TRAP)
- Reports arrive via
- PhishAlarm report button, into an abuse mailbox
- Finds other copies
- Yes: other copies, forwards and distribution lists
- Removes from inboxes
- Yes: retracts and quarantines automatically
- Human sign-off
- Clean and bulk reports close themselves; unclear ones go to Proofpoint's analysts
Scores each report with Proofpoint threat intelligence and URL and attachment sandboxing, then TRAP finds other instances across the organisation. Finding every instance needs Proofpoint Targeted Attack Protection.
Sends the reporter feedback on every message, whether it was malicious, bulk or clean. Proofpoint's description of CLEAR dates from 2021, so check current packaging with Proofpoint.
Source: Proofpoint: Closed-Loop Email Analysis and Response solution brief (June 2021). Checked 21 September 2026.