Skip to content

Secure Mail Gateway

Enterprise email security gateway

HSMG protects an organisation's inbound and outbound email. It attaches to the SMTP flow, scans every message with nine independent engines and reaches one decision: deliver, tag, quarantine or reject.

The Cautious Side Of Doubt

Most gateways let a message through when they are unsure: the scanner did not run, the file would not open, something timed out — the message is marked clean and delivered. It is convenient, and it is exactly how one message opens a whole network.

HSMG takes the other side — fail-closed. If an engine does not answer or a file cannot be opened, the message is temporarily rejected (SMTP 451) or quarantined. In banking and government that sharply cuts the risk of losing data.

The second principle is Fusion. One weak signal never blocks on its own; several weak signals combine into a confident decision. That two-key approach is what keeps false positives down.

Decision levels
DecisionWhen it applies
DeliverClean message — delivered unchanged
TagWeak suspicion — marked in the subject or headers, delivered
GreylistReputation unclear — temporarily deferred
QuarantineStrong suspicion — quarantined (HOLD + .eml)
Reject / DeferConfirmed threat or scanner failure — 5xx reject / 451 defer
Nine engines

What Every Message Passes Through

Three independent antivirus kernels

  • Three kernels run in parallel, come from different sources and cover each other
  • OR-veto: if any one finds a virus the message is rejected regardless of the overall score
  • Maximum scan size 25 MB per kernel; timeouts of 15s and 10s
  • Kernel names are not exposed to the customer — results read as kernel 1/2/3

Phishing And BEC: Attacks With No Attachment

Business email compromise usually arrives with no malicious attachment and no link — only text written in the name of someone trusted. A signature will never catch that.

Detection layers
LayerWhat is checked
AuthenticationSPF, DKIM, DMARC and ARC — domain spoofing and forged senders. Outbound mail is DKIM-signed with a per-domain key
BEC / CEO fraudSeven behavioural vectors in three languages: display-name imitation, lookalike domain, Reply-To mismatch, first-time VIP sender, urgency lexicon, changed payment details, a financial request from a first contact
VIP and impersonationA name-to-real-address table for executives, finance and HR, synchronised from Active Directory groups
URL analysisLinks are analysed without being opened: typosquatting, homoglyphs, shorteners, Base64-hidden links, login pages without TLS, redirect chains followed to the end
QR codesQR codes inside images and PDFs are decoded and the URL inside runs the full URL analysis — the quishing that text filters never see
OCR and password-protected filesText, passwords and URLs are lifted out of images; the password is found in the message body, the document is opened and rescanned

Data Loss Prevention

The DLP module identifies confidential data in the outbound flow and stops it leaving the organisation without permission. Every extractor pairs its pattern with a check digit, which is what keeps false positives low.

Eight extractors
ExtractorData typeCheck
Payment card (PAN)13–19 digit card numberLuhn algorithm
PINFLIndividual identifierFormat + check digit
INN / STIRTaxpayer numberFormat validation
PassportSeries and numberPattern (AA1234567)
IBANInternational account numberMOD-97 check
CVVCard security codeContext + proximity to a PAN
EXPIRYCard expiry dateMM/YY pattern + context
SWIFT / BICBank identifier8/11 character format

Beyond the eight defaults the operator can add patterns of their own — an internal contract number, a customer identifier, a restricted project code. In the quarantined message and the forensic copy confidential data is masked automatically: the operator sees the evidence without the full value.

A Full Air-Gap: Nothing Leaves

HSMG sends no data to any external cloud service. Signature databases, rules and indicators are updated offline, without ever reaching the internet.

Isolation controls
ControlHow it is implemented
Air-gapped networkDetection kernels live on the internal network only; there is no external NAT or gateway and outbound update modules are disabled
Two-layer firewallAt host and forward level; only four ports face outward — SSH, the panel, SMTP :25 and submission :587
Offline updatesSignatures, YARA rules, URL reputation and IOC feeds arrive on media or by scheduled synchronisation
Zero external telemetryNo file, sample or metadata is sent to a vendor cloud
Data residencyEvery message, quarantine item and log stays on local infrastructure — aligned with MB 3669 and local storage requirements
Detonation isolationThe sandbox guest is never routed to the physical network and returns to a clean snapshot after each detonation

Connection And Integration

The gateway sits in front of the corporate mail infrastructure and attaches to the SMTP flow as an MTA milter. There are three installation modes.

Installation modes
ModeHow it works
MTA (inline)Sits in the flow directly and makes the decision — full protection
SPAN / TAPPassive observation — never touches the flow, only detects and reports
BCC (journal copy)Watches a copy of each message — for evaluation without replacing the current gateway

Only SMTP :25, submission :587, the panel and SSH face outward; the milter, ICAP and native AV ports stay on the internal network. The management panel is trilingual (Uzbek, Russian, English) with RBAC and central audit; Active Directory, LDAP and SSO are supported. Verdicts and events are forwarded to the SIEM and correlated with NDR and EDR.

Questions

Frequently Asked Questions

No. HSMG is not a mail server but a filtering gateway in front of one. A message passes through HSMG and is then delivered to your Exchange or other backend.

Yes. SPAN/TAP mode does not enter the flow at all — it only observes and shows what it would have held. BCC mode works from a journal copy. Neither replaces your current gateway.

Yes, that is the core design condition. Signatures, rules and indicators update offline, on media or by scheduled synchronisation. Controlled online updating through a proxy is optionally supported.

Fail-closed applies only to scanner failure — an engine that did not answer or a file that would not open. Ordinary suspicion goes through the Fusion layer instead: one weak signal never blocks, and a confident decision needs several to agree.

No. No file, sample or metadata is sent to a vendor cloud — zero external telemetry is a hard requirement. Sandbox detonation also runs inside the local appliance.

Let's Test Your Mail Flow

We connect in SPAN or BCC mode and show you what is getting through today, without touching your current flow. No message is blocked at this stage.

Let’s start
Request a trial deployment
Request a trial deployment