MailGuard: inbound protection for email security

MailGuard protects incoming email at the gateway: anti-spam, anti-phishing, BEC defence, attachment filter with CDR, DLP and URL rewriting in one console.

MailGuard is the inbound gateway of Conbool. It checks every incoming message before it reaches the mailbox and stops spam, phishing and malware at the handover point. It is connected through the MX record, without rebuilding the mail server behind it.

MailGuard overview with protection status, policies and quarantine

Central MailGuard overview with the protection modules.

What inbound protection covers

MailGuard combines six protection areas in one console. Each area has its own page with the configuration details.

Analysis with scoring

Every message receives a score from the active check layers. From the mark score an email is flagged as suspicious, from the block score it is blocked. Policies and routing determine which check applies to which senders and recipients. Stricter rules can thus be set for accounting or management than for general info mailboxes.

SIEM export and log forwarding

All detections and delivery events can be handed to a SIEM such as Splunk, Microsoft Sentinel, IBM QRadar or Elastic as a normalised event stream. Details on the pull API, formats and data protection are described under SIEM export, and the SIEM export solution page puts it in context.

Operations and compliance

Processing takes place in data centres in Germany, GDPR compliant and to ISO 27001. Every check result lands in the audit log under GDPR Art. 30 and can be followed in tracing. Further reading: the MailGuard product page, the spam filter for businesses, the DMARC reports for sender authentication and the guide to connecting a domain.