
What stood out most is how well Trellix ETP handles threat detection at the perimeter, especially the advanced URL analysis — including URL rewrite for S/MIME signed messages — which catches malicious links without breaking signed message integrity, and cleanly quarantines threats before anything reaches our internal mail server. A major plus was that this was a hybrid implementation: we kept our on-premise infrastructure in place for compliance and data residency, while still getting Trellix's cloud-based AI threat analysis, so we didn't have to trade one for the other. It also slotted in well alongside our existing email gateway and DNS-layer filtering, with domain token and source IP verification making outbound mail easy to trust and trace. Review collected by and hosted on G2.com.
The main limitation we ran into was on the reporting and logging side — there's a hard cap of around 10K records, which really restricts how far back you can pull data for reporting or investigation purposes. In an email security context, you often need longer retention windows to spot patterns, trace an incident back to its origin, or satisfy internal audit and compliance requirements. Hitting that ceiling meant we couldn't rely on the platform alone for extended historical reporting and had to think about exporting or archiving logs elsewhere to cover longer retention needs. It would be a much stronger product if the reporting module scaled retention independently of that record limit, or at least gave more flexibility for organizations that need deeper historical visibility. Review collected by and hosted on G2.com.