Jump to:navigation, search
Wiki








































FAQ for Securepoint Mail Security

Last adaption: 11.2025

New:
notempty
This article refers to a Beta version
-

Security Features of Mail Security

  • Advantages of Mail Security with UTM

    What advantages does Mail Security offer if I already have a UTM?
  • ATP and APT

    What is ATP and APT?
  • Answer

    The abbreviation stands for Advanced Persistent Threat (APT) and Advanced Threat Protection (ATP). This refers to a sandbox environment used for additional testing of files that Securepoint initially does not classify as viruses. The files are executed, and their behavior is analyzed by the ATP. Depending on this behavior, the files can then be identified as viruses. This provides additional protection against new, unknown viruses or malware.
  • Protection Against Mail Server Overload

    Does Mail Security provide protection against DDoS attacks via email?
  • Answer

    Yes, the infrastructure of Securepoint Mail Security is designed to handle a large number of emails and can thus better withstand a DDoS attack.
  • Post-Incident-Management

    What does 'Post-Incident Management' mean?
  • Answer

    If a delivered email or its attachment is identified as dangerous within 7 days, the sender will receive a notification.
  • Advanced URL-Defence

    What does 'Advanced URL-Defence' mean?
  • Answer

    Links in an email are checked before the email is delivered. If the address is identified as dangerous, access to it . Additionally, links in emails are replaced by a redirect through our Mail Security servers (rewrite). This ensures that even later accesses are checked to see if they are no longer considered safe.
    For example, www.anyideas.de becomes https://cloud.mymailwall.com/m/www.anyideas.de
    This way, the original address remains recognizable.
  • Comprehensive Virus Analysis

    How are '.exe' or '.zip' files examined?
  • Answer

    etection is based on the structure of the file. MIME type or file extension does not matter.
    Zip files are unpacked, and the contained files are checked individually.
    For password-protected files, an attempt is made to guess the password using known password lists or words and word combinations from the email. (Phishing emails often contain a password-protected attachment to evade virus detection. However, the password is then usually provided in plain text in the email so the user can still open the attachment with the virus.)

    General

  • Environmental Changes

    What changes do I need to make in my environment to use Securepoint Mail Security?
  • Answer

    To use Securepoint Mail Security, you need to change the MX record of your email domain to mx.mymailwall.com and provide Securepoint with the server IP (or DNS name) of your email domain to complete the forwarding.
  • Effectiveness of changes

    How long does it take for the changes to take effect?
  • Answer

    Changes usually take effect within five minute
  • Check SPF Record

    What does "Check SPF Record" mean?
  • Answer

    Domains that send via Securepoint Mail Security are checked to see if they have an SPF record and, if so, whether it includes mymailwall.com.
  • Benefits of SPF Record

    What does an SPF record offer?
  • Answer

    An SPF record specifies which servers are allowed to send using the domain names. This prevents domain abuse by not accepting emails from senders not included in the DNS record.
  • Email rejected due to SPF

    An email was rejected due to SPF?
  • Answer

    If an email is rejected due to SPF, it is initially not accepted. In this case, an SPF allowlist entry must be made for the domain. The sender must then resend the email.
  • Greylisting

    What is Greylisting
  • Answer

    When Securepoint Mail Security greylists a message, it responds to the sending mail server with a temporary rejection message, prompting the sender to try again. If another attempt is made to send an email with the same data combination, the email will be accepted. Whether and when another attempt is made depends solely on the sender.
  • Backup-Server

    Can I set up a backup server?
  • Answer

    Yes, you can enter a second target server to be used as a backup.
  • Automatic Delivery Reports

    Why am I not receiving automatic delivery reports (DSN)? notempty
    New
  • Answer

    Outlook requests a DSN directly from the receiving mail server.
    However, when using Securepoint Mail Security, we act as an SMTP relay in front of the destination server. The DSN request from Outlook does not reach the final mail server in its original form.
    Therefore, the destination server does not generate a delivery confirmation.

    Securepoint Mail Security also does not generate such reports because we are not the final recipient.

    This means that emails are fully delivered and processed correctly, but the "delivery confirmation" mechanism via a mail security gateway cannot function.

    This behavior is normal for upstream relays.



    Automatic Email Filters

  • Spam Filter

    What do the spam filters control?
  • Answer

    The spam filters determine the parameters within which an email is identified as possible spam or spam. The default settings are our recommended settings. They should be tested first and only changed when you are certain about the required settings.
  • Spam in Subject

    Why am I receiving emails with the subject ******SPAM*****?
  • Answer

    Our default setting marks emails as spam and/or possible spam. This ensures that new customers can review and adjust their settings without worrying about missing an email.
  • Infected Email Delivered

    A virus was found in one of my emails. Why did I still receive the email?
  • Answer

    The virus filter can be configured to determine what happens to an email containing a virus.

    With the default setting, the virus is removed from the email, while other attachments and the email itself are still delivered.

    Note that in this case, the email is no longer checked for spam, as an email with a virus is always classified as spam.

    Solution

    If this should no longer happen, it can be set in the Mail Security Portal under mail.security Incoming in the SettingsVirus Filter option Action for infected email.
  • Executable File is a Virus

    What does "An executable file is a virus" mean?
  • Answer

    This means that all executable files in email attachments are identified as viruses.

    If they are attached directly, not only the file extension is checked, but the file is analyzed so that renamed files are also detected.

    If files are contained in a password-protected archive, they are only recognized by their file extension.
  • Quarantine Mailbox

    What is a quarantine mailbox?
  • Answer

    Any virus detected by Securepoint Mail Security is sent to this mailbox if the program is configured accordingly. The virus file is sent in a password-protected archive, with the password provided in the email. The virus file is also modified so that it cannot be executed unintentionally.

    Troubleshooting

  • Email Not Received

    Why are expected emails not being delivered?
  • Answer

    This can have multiple sources of error. Therefore, it is best to check the log messages.

    Solution

    Using the interface to access the log file, you can search for every email accepted by the Securepoint Mail Security system.

    If an email has been received, you can find the status of the email. The following status values are available:

    • Delivered: Email was sent to the next server
    • Delivery failure: Delivery to the destination server failed
    • In queue: Transmission to the next server is still pending
    • Rejected: The email was rejected due to spam/virus/attachment.

    Emails can be resent directly from the log file.

    Additionally, there are still emails that are rejected by the system. This happens if the sender's domain is not authorized by SPF (Sender Policy Framework).

    S/MIME – General

  • Acquire S/MIME Only

    Is the S/MIME feature also available as a standalone (without Securepoint Mail Security)?
  • Answer

    S/MIME serves as an add-on to Securepoint mail.security and therefore cannot be purchased separately.
  • Prerequisites

    What are the prerequisites for using S/MIME?
  • Answer

    S/MIME certificates can only be requested for domains whose MX record points to mx.mymailwall.com and which are set up in an incoming route.
  • Certify Internal Email

    Can internal emails also be certified with a certificate?
  • Answer

    Only emails sent via Securepoint Mail Security/mymailwall are provided with an S/MIME certificate.
  • Provide Mailbox with Certificate

    How can I provide mailboxes with a certificate?
  • Answer

    Under the menu item mail.security > S/MIME, you will find a list of your mailboxes. Here you can activate one, several, or all mailboxes. Signing and encryption are then carried out automatically according to the rules you have set when sending emails via Securepoint Mail Security/mymailwall.
  • Mailbox Not in Overview

    Why don't I see my mailbox in the S/MIME overview?
  • Answer

    The mailboxes must be set up as known mailboxes in an incoming route. Mailboxes captured in a wildcard route are not displayed.
  • License Cross-Domain

    Is the license cross-domain, or does it need to be acquired per domain?
  • Answer

    The license is acquired cross-domain, similar to Securepoint Mail Security, and can therefore be used for any number of domains.
  • License Count Incorrect

    My license count is displayed incorrectly in the Securepoint portal. How can I change this?
  • Answer

    Please contact Securepoint Support.
  • Download S/MIME Certificate

    Where can I download the S/MIME certificate?
  • Answer

    Downloading S/MIME certificates is not technically provided for security reasons.
  • Use Existing Certificate

    Can I use an existing (third-party) certificate for certain mailboxes?
  • Answer

    Within your existing license, you can upload any number of existing (third-party) certificates, which are then managed and used like Securepoint S/MIME certificates. Please note that these also count as licenses and thus reduce your available quota.
  • In Deactivation

    What does the status "Revoke pending" (EN) / "in Deaktivierung" (DE) mean?
  • Answer

    These are mailboxes that have been deactivated. This status remains for up to 14 days until the status changes to "Inactive" (EN) / "Inaktiv" (DE) and the license becomes available again.
  • S/MIME License Equals Securepoint Mail Security License

    Does the S/MIME license have to match the Securepoint mail.security license?
  • Answer

    No. The S/MIME license can be smaller than or equal to the Securepoint mail.security license.
  • Validity Period

    How long is an S/MIME certificate valid?
  • Answer

    Securepoint S/MIME licenses automatically receive the same validity period as your existing Securepoint Mail Security license. Technically, these are 1-year certificates, but they are automatically renewed without additional costs (within the existing license).
  • Certificate Issuer

    Who issues the S/MIME certificates?
  • Answer

    The S/MIME certificates are issued by the European certification authority Certum. Certum is included in the Adobe Approved Trust List (AATL), an exclusive list of trusted certificate issuers.

    S/MIME – Encryption

  • License Prerequisite

    When or with which license can email encryption be used? Does this incur additional costs?
  • Answer

    Email encryption is part of Securepoint S/MIME and is included in the price of Securepoint S/MIME licenses. Securepoint S/MIME can be obtained by all Securepoint mail.security users.
  • Applicability of Encryption

    For which mailboxes can encryption be used?
  • Answer

    Encryption can be applied to all mailboxes managed with Securepoint mail.security with an active Securepoint S/MIME certificate. Please note that with enforced encryption for outgoing emails (Outbound), mailboxes without a valid Securepoint S/MIME certificate affected by this rule cannot send emails! Optional decryption is also applied to mailboxes without a Securepoint S/MIME certificate.
  • Error with Enforced Rule

    What happens if an "enforced" rule is active and fails?
  • Answer

  • Prerequisite for Encryption

    What are the prerequisites for encrypting emails?
  • Answer

    A prerequisite for encrypting emails is an active certificate and the recipient's public key. The keys are automatically exchanged and stored via an unencrypted but signed email.
  • Prerequisite for Decryption

    What are the prerequisites for decryption?
  • Answer

    A prerequisite for all rule variants for incoming emails (Inbound) is an existing certificate for the receiving mailbox. Optional decryption is also applied to mailboxes without a Securepoint S/MIME certificate.
  • Use Existing Certificates

    Can existing certificates be used?
  • Answer

    Yes, S/MIME certificates not obtained via Securepoint can also be managed in Securepoint Mail Security. They can be uploaded under the S/MIME menu item in the Securepoint portal. They have the same functionality as Securepoint S/MIME certificates and are counted towards your Securepoint license quota.
  • Permission to Change Rules

    Who can create/change rules?
  • Answer

    All users of the Securepoint portal with write permissions can create or change rules.
  • Activation Duration of Rule

    How long does it take for a rule to become active after creation?
  • Answer

    It can take up to 10 minutes after creating/editing a rule for it to be considered when sending/receiving.
  • Detection of Encryption/Decryption

    Where can I see if an email was encrypted or decrypted?
  • Answer

    Which emails were encrypted, decrypted, or signed can be viewed in the email overview under the Securepoint Mail Security menu item. It is also possible to filter by status.
  • Encryption Type

    What type of encryption is applied?
  • Answer

    S/MIME uses asymmetric encryption. The recipient's public key is used to encrypt content, which can only be decrypted again with the private key.
  • Exchange of Public Keys

    How can the exchange of the public key take place?
  • Answer

    The public keys required for encryption can be exchanged via an unencrypted, signed email. Securepoint Mail Security automatically extracts and stores the key.

    ATP

  • General Meaning and Function

    What is ATP?
  • Answer

    ATP stands for Advanced Threat Protection and refers to an approach in information security that focuses on detecting and defending against advanced threats and attacks designed to bypass traditional security measures such as malware scanners and firewalls.
  • Functionality of ATP

    How does the ATP add-on protect against targeted attacks?
  • Answer

    In addition to the analysis methods of the malware scan engine based on signatures, content, and behavior, Securepoint Mail Security with ATP uses signatureless methods and sandboxes from various leading sandboxing providers.

    All types of attachments are specifically examined for hidden attacks and are test-executed in connection with various combinations of operating systems and applications, including different web browsers and plugins such as Adobe Reader or Flash.

    This allows even attacks designed to bypass traditional security solutions to be detected.
  • Delay Due to ATP

    What delays in email delivery can be expected due to the extensive ATP analyses?
  • Answer

    Only data for which the malware scan engine cannot reach a reliable conclusion is forwarded and analyzed again in parallel—these are in the per mille range of the total data volume. As a result, analyses usually run as quickly as usual and are barely noticeable in terms of time. However, depending on the scope of the ATP analysis, individual elements may take up to ten minutes to process
  • ATP Analysis Results

    Where can I see the results of the ATP analysis?
  • Answer

    The data identified as threats during the ATP analysis are displayed. They appear in the email search with the label "Infected (ATP)."
  • Data Protection and ATP

    What data is transmitted to the sandboxes, and which data protection laws apply?
  • Answer

    The sandboxes of our technology partners are installed in the German-speaking region. This ensures that all data—only metadata, attachments, or scripts are sent—remains within the EU.

    European and German data protection laws (GDPR) apply.

    While the sandboxes continuously receive updates from their manufacturers, they are isolated in such a way that they cannot establish any external connections themselves.