Ten dollars is not a large sum in enterprise cybersecurity. It is barely lunch in San Francisco. But in 2018, Area 1 Security attached that figure to something security vendors usually prefer to describe in softer terms: a successful catch. Under its Pay-Per-Phish offer, a customer paid $10 for each malicious phish Area 1 detected, with no upfront commitment in the original pitch. If the company caught nothing, the bill for catches was nothing. A pricing plan became a public wager on whether the product worked.
- Area 1 built cloud email security to stop phishing, business email compromise and malware before users acted on them.
- Its 2018 Pay-Per-Phish offer charged $10 per malicious phish detected. Other plans also existed.
- Cloudflare, already a customer, acquired Area 1 in April 2022 for approximately $162 million.
- The technology now lives in Cloudflare Email Security, inside its wider Zero Trust platform.
A message with the right name
The problem Area 1 chose is awkwardly human. A spam filter can spot a tidal wave of junk. A carefully written message to one payroll officer is harder. It may arrive from a plausible domain, borrow a familiar name, and ask for a routine transfer. Business email compromise does not need a dazzling attachment. It needs a recipient whose day is busy enough to make the request seem ordinary.
Area 1 was founded in 2013 by Oren Falkowitz, Blake Darché and Phil Syme, former colleagues at the US National Security Agency. Their early pitch was to identify targeted social engineering before an employee clicked. The product that emerged, Area 1 Horizon, watched email and the surrounding web and network signals. It crawled for suspicious infrastructure, compared domains, examined links and attachments, and read message context. The ambition was preemption: recognize a campaign while it was being prepared, then block its mail before it reached a person.
The useful distinction: the suspicious email is the final act; the campaign leaves traces before it arrives.
The invoice that made the claim visible
That is where the $10 offer matters. Cybersecurity is full of promises about attacks prevented, a number no buyer can independently count with certainty. Area 1 made the count the unit of sale. Its 2018 one-pager called the arrangement “Pay-Per-Phish” and said customers paid for malicious phish detected. The plan had commercial limits and was one option among others, yet the signal was clear: test us against the mail your current defenses miss.
“We stop phish, or you pay nothing.”Area 1’s 2018 Pay-Per-Phish offer
The mechanism was shrewd because it shifted the buying conversation from a long list of features to an uncomfortable question: what slips through today? It also gave Area 1 a reason to improve its own detection. A vendor paid for seats can earn the same amount whether it catches a phish or overlooks one. Area 1’s particular offer tied a piece of revenue to observed catches. That does not prove every catch was valuable, or that every miss was visible. It did make performance harder to treat as a decorative promise.
The buyer had seen the inbox
Cloudflare announced the acquisition in February 2022 and closed it on April 1. Its stated purchase price was approximately $162 million in cash and stock. One fact separates this deal from a generic platform expansion: Cloudflare said it had used Area 1 for two years and had seen phishing attacks virtually disappear from employee mailboxes. That is the buyer speaking about its own experience, not an independent performance study, but it explains why the product made sense inside Cloudflare’s Zero Trust portfolio.
Cloudflare already protected web traffic and application access. Email was a conspicuous entry point for an attacker seeking credentials. Area 1 gave it a way to inspect that entry point, connect email findings to other security signals, and sell a broader set of controls to the same enterprise security team. At closing, Area 1’s CEO Patrick Sweeney described the combination as a way to secure “your email” within the wider platform. The standalone brand became a component of a much larger company.
An election inbox as a test case
The stakes are easy to see in Cloudflare’s account of the 2022 US midterms. It reported protecting the inboxes of more than 100 campaigns, election officials and public organizations, processing over 20 million emails and stopping around 150,000 phishing attempts in the three months before the vote. In one example, a House campaign received a message titled “Staff Payroll Review.” The footer and branding looked convincing. Area 1’s models flagged the sending domain’s resemblance to the real campaign domain and other message clues.

That case captures Area 1’s expertise. It treated a message as an event with relationships and history, rather than just text to scan. It also shows the conditions for a useful deployment. Security teams must give the service access to the mail stream and configure how it acts on suspected messages. A false positive can delay a real conversation; a missed phish can still reach a user. The promise is a better signal and a quicker response, not a mathematically clean inbox.
From a product to a layer
Cloudflare now markets the service as Cloudflare Email Security. It works with Microsoft 365 and Google Workspace and can be deployed by API, mail journaling or inline mail routing. Organizations can keep their existing mail provider. A security team can compare detections against its current controls, then decide whether to block or investigate messages. Cloudflare’s 2023 Retro Scan extended that idea into the past by scanning older Microsoft 365 inbox mail for threats that had already passed through.
The business model has changed with the owner. The memorable $10 rate belongs to Area 1’s historical offer, not a published price for Cloudflare’s current service. Today the buying decision sits among enterprise plans, integrations and security operations workflows. Cloudflare has also widened the detection work: it described QR-code phishing defenses in 2024, and in 2026 explained how language models help its analysts find emerging patterns and train narrower detection models. The original Area 1 dashboard was retired for customer access in October 2025; the email protection continued through Cloudflare’s dashboard.
Alternatives are familiar: built-in Microsoft or Google defenses, traditional secure email gateways, and specialist vendors such as Proofpoint, Mimecast and Abnormal Security. Area 1’s original distinction was the combination of early campaign discovery and its unusually legible performance offer. Its present position is different: email security as one control within a broader Zero Trust network. The best lesson for buyers survives both versions. Before adding another line item, inspect what the current system misses. Then measure whether the new one catches it without making ordinary work harder.