Industry News
What Two September Acquisitions Tell Us About Where Email Security Is Headed
September 17, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Two acquisitions closed within two weeks of each other this past September, and neither one made much noise outside trade press. Taken together, though, they sketch a clearer picture of where email security is going than any single vendor roadmap could. One deal bought authentication infrastructure. The other bought AI-driven detection. Both buyers were chasing the same destination from opposite ends of the inbox.
What did the two September deals actually involve?
On September 2, 2025, data security vendor Varonis announced it had acquired SlashNext, an AI-native anti-phishing company, for $150 million, with the stated goal of extending its breach-prevention platform into the inbox using SlashNext's predictive AI models for detecting spearphishing and social engineering. Two weeks later, on September 16, digital trust provider DigiCert announced it had acquired Valimail, a zero trust email authentication vendor, to add DMARC-as-a-service capability to its DigiCert ONE platform and enter what it called a market worth more than $4 billion for paid DMARC solutions.
Those two sentences describe deals that look unrelated on paper. One is about catching bad messages before a human clicks. The other is about proving a domain's messages are legitimate before they ever reach a filter. But both buyers are PKI and data-security companies with no prior email product, both are folding a specialist into a broader trust or security platform, and both are betting that email security customers increasingly want one vendor covering the whole problem rather than a stack of point tools.
Why detection and authentication are converging
For most of the last decade, phishing detection and domain authentication lived in separate product categories with separate buyers. Detection tools scanned inbound mail for malicious content. Authentication protocols like SPF, DKIM, and the DMARC standard defined in RFC 7489 verified that outbound mail actually came from the domain it claimed to. SlashNext's technology sits firmly in the first camp, built by a founder who helped architect FireEye's malware sandbox before turning to predictive phishing models. Valimail sits in the second, having built its business entirely around making DMARC enforcement operationally manageable at scale.
The reason these two categories are merging now is largely regulatory pressure applied by the mailbox providers themselves. Since February 2024, Google has required bulk senders to publish a DMARC record and meet a set of authentication thresholds to reach Gmail inboxes reliably, a policy detailed in Google's own sender guidelines. Yahoo introduced parallel requirements the same year. That single policy shift turned DMARC from a nice-to-have into a delivery gate, and it pulled authentication out of the security team's backlog and into every mail admin's daily checklist.
Once authentication became mandatory infrastructure rather than an optional hardening step, it started to look a lot more like the detection layer it used to sit beside: something every domain needs continuously monitored, reported on, and enforced, not configured once and forgotten. Buyers who already sell trust infrastructure, PKI certificates in DigiCert's case, data security posture in Varonis's, saw an adjacent problem they could absorb rather than partner around.
Why platform buyers are absorbing point solutions instead of partnering
The pattern in both deals is acquisition into a platform, not investment in a standalone product line. DigiCert framed the Valimail purchase explicitly as adding a new capability to DigiCert ONE, which already unifies public CA, private PKI, certificate lifecycle management, and DNS visibility, so that email authentication becomes one more pane in a single dashboard covering websites, software, and devices, according to the company's own announcement. Varonis described the SlashNext deal in similar terms, positioning it as a way to give CISOs a consolidated detection and response offering that extends data breach prevention into the inbox and beyond, covering channels like Slack and Teams alongside email.
Neither company had a credible email security product before these deals. Both had adjacent platforms with enough customer trust and distribution to make bolt-on acquisition faster than internal build. This is a familiar M&A pattern in cybersecurity more broadly. SecurityWeek's tracking found 40 cybersecurity M&A deals were announced across all categories in September 2025 alone, part of a year that produced 426 total cybersecurity acquisitions in 2025, continuing a multi-year trend of platform consolidation rather than a spike specific to email.
| Deal | Buyer's core business | Target's specialty | Stated strategic goal |
|---|---|---|---|
| DigiCert–Valimail (Sept 16) | PKI and digital trust | DMARC-as-a-service authentication | Add authentication to DigiCert ONE |
| Varonis–SlashNext (Sept 2) | Data security posture | AI-native phishing detection | Extend breach prevention into the inbox |
For MSPs, the practical read is that the vendors managing email risk on behalf of clients are increasingly the same vendors managing broader data and identity risk. That has real implications for how a technician evaluates a stack, because a tool bought for one narrow job today may be marketed as part of a much bigger platform within eighteen months, with pricing and support models to match.
What this means for MSPs building a client stack
None of this changes the underlying mechanics an MSP has to get right for a client domain. SPF, DKIM, and DMARC records still need to be published correctly, DMARC reports still need to be read rather than ignored, and phishing detection still needs a layer that inspects content and behavior, not just headers. What is changing is who sells that stack and how it is bundled.
Consolidation among vendors tends to produce two outcomes for the businesses buying from them: better default integration between capabilities that used to require stitching together, and higher switching costs once a client is deep inside one platform's ecosystem. An MSP evaluating tools today benefits from starting with a clear picture of a client's current authentication posture before deciding whether a bundled platform or a focused scanning tool makes more sense, which is the kind of baseline audit covered in ActiScan's own getting-started guide for onboarding new domains.
Cost also matters more once acquisitions push previously separate products into a single subscription line. Teams comparing what a consolidated platform charges against a lighter, purpose-built scanning tool should look closely at the pricing page for any vendor under consideration, since platform bundling sometimes means paying for capability a client's domain portfolio does not actually need yet. Business email compromise alone accounted for billions in reported losses in the FBI's most recent Internet Crime Complaint Center data, which is exactly the kind of exposure that both authentication gaps and weak phishing detection leave open, and it is worth confirming a stack closes both doors before assuming a bundled deal does so automatically.
The bigger signal for the next twelve months
Two acquisitions in one month do not prove a trend by themselves, but they line up with regulatory and mailbox-provider pressure that has been building since the Google and Yahoo authentication requirements landed in early 2024. Expect more buyers with adjacent trust or data platforms to look at standalone DMARC and phishing-detection vendors as acquisition targets rather than partnership candidates. For MSPs, the response is not to chase every platform announcement but to keep a current, verifiable read on each client domain's actual authentication and phishing exposure, something that starts with running a scan rather than waiting to see which vendor buys which startup next. Teams that have not yet baselined their client domains can start that process directly through ActiScan's signup page.
The lesson from September is less about SlashNext or Valimail specifically and more about what their acquirers were willing to pay for: not new detection tricks, but proof that authentication and detection are no longer separable problems in any buyer's mind.