The abbreviation stands for Advanced Persistent Threat (APT) and Advanced Threat Protection (ATP). This refers to a sandbox environment used for additional testing of files that Securepoint initially does not classify as viruses. The files are executed, and their behavior is analyzed by the ATP. Depending on this behavior, the files can then be identified as viruses. This provides additional protection against new, unknown viruses or malware.
Protection Against Mail Server Overload
Does Mail Security provide protection against DDoS attacks via email?
Answer
Yes, the infrastructure of Securepoint Mail Security is designed to handle a large number of emails and can thus better withstand a DDoS attack.
Post-Incident-Management
What does 'Post-Incident Management' mean?
Answer
If a delivered email or its attachment is identified as dangerous within 7 days, the sender will receive a notification.
Advanced URL-Defence
What does 'Advanced URL-Defence' mean?
Answer
Links in an email are checked before the email is delivered. If the address is identified as dangerous, access to it . Additionally, links in emails are replaced by a redirect through our Mail Security servers (rewrite). This ensures that even later accesses are checked to see if they are no longer considered safe.
For example, www.anyideas.de becomes https://cloud.mymailwall.com/m/www.anyideas.de This way, the original address remains recognizable.
Comprehensive Virus Analysis
How are '.exe' or '.zip' files examined?
Answer
etection is based on the structure of the file. MIME type or file extension does not matter. Zip files are unpacked, and the contained files are checked individually. For password-protected files, an attempt is made to guess the password using known password lists or words and word combinations from the email. (Phishing emails often contain a password-protected attachment to evade virus detection. However, the password is then usually provided in plain text in the email so the user can still open the attachment with the virus.)
General
Environmental Changes
What changes do I need to make in my environment to use Securepoint Mail Security?
Answer
To use Securepoint Mail Security, you need to change the MX record of your email domain to mx.mymailwall.com and provide Securepoint with the server IP (or DNS name) of your email domain to complete the forwarding.
Effectiveness of changes
How long does it take for the changes to take effect?
Answer
Changes usually take effect within five minute
Check SPF Record
What does "Check SPF Record" mean?
Answer
Domains that send via Securepoint Mail Security are checked to see if they have an SPF record and, if so, whether it includes mymailwall.com.
Benefits of SPF Record
What does an SPF record offer?
Answer
An SPF record specifies which servers are allowed to send using the domain names. This prevents domain abuse by not accepting emails from senders not included in the DNS record.
Email rejected due to SPF
An email was rejected due to SPF?
Answer
If an email is rejected due to SPF, it is initially not accepted. In this case, an SPF allowlist entry must be made for the domain. The sender must then resend the email.
Greylisting
What is Greylisting
Answer
When Securepoint Mail Security greylists a message, it responds to the sending mail server with a temporary rejection message, prompting the sender to try again. If another attempt is made to send an email with the same data combination, the email will be accepted. Whether and when another attempt is made depends solely on the sender.
Backup-Server
Can I set up a backup server?
Answer
Yes, you can enter a second target server to be used as a backup.
Automatic Delivery Reports
Why am I not receiving automatic delivery reports (DSN)? notempty
New
Answer
Outlook requests a DSN directly from the receiving mail server. However, when using Securepoint Mail Security, we act as an SMTP relay in front of the destination server. The DSN request from Outlook does not reach the final mail server in its original form. Therefore, the destination server does not generate a delivery confirmation.
Securepoint Mail Security also does not generate such reports because we are not the final recipient.
This means that emails are fully delivered and processed correctly, but the "delivery confirmation" mechanism via a mail security gateway cannot function.
This behavior is normal for upstream relays.
Automatic Email Filters
Spam Filter
What do the spam filters control?
Answer
The spam filters determine the parameters within which an email is identified as possible spam or spam.
The default settings are our recommended settings. They should be tested first and only changed when you are certain about the required settings.
Spam in Subject
Why am I receiving emails with the subject ******SPAM*****?
Answer
Our default setting marks emails as spam and/or possible spam. This ensures that new customers can review and adjust their settings without worrying about missing an email.
Infected Email Delivered
A virus was found in one of my emails. Why did I still receive the email?
Answer
The virus filter can be configured to determine what happens to an email containing a virus.
With the default setting, the virus is removed from the email, while other attachments and the email itself are still delivered.
Note that in this case, the email is no longer checked for spam, as an email with a virus is always classified as spam.
Solution
If this should no longer happen, it can be set in the Mail Security Portal under mail.security Incoming in the Settings → Virus Filter option Action for infected email.
Executable File is a Virus
What does "An executable file is a virus" mean?
Answer
This means that all executable files in email attachments are identified as viruses.
If they are attached directly, not only the file extension is checked, but the file is analyzed so that renamed files are also detected.
If files are contained in a password-protected archive, they are only recognized by their file extension.
Quarantine Mailbox
What is a quarantine mailbox?
Answer
Any virus detected by Securepoint Mail Security is sent to this mailbox if the program is configured accordingly.
The virus file is sent in a password-protected archive, with the password provided in the email. The virus file is also modified so that it cannot be executed unintentionally.
Troubleshooting
Email Not Received
Why are expected emails not being delivered?
Answer
This can have multiple sources of error. Therefore, it is best to check the log messages.
Solution
Using the interface to access the log file, you can search for every email accepted by the Securepoint Mail Security system.
If an email has been received, you can find the status of the email. The following status values are available:
Delivered: Email was sent to the next server
Delivery failure: Delivery to the destination server failed
In queue: Transmission to the next server is still pending
Rejected: The email was rejected due to spam/virus/attachment.
Emails can be resent directly from the log file.
Additionally, there are still emails that are rejected by the system. This happens if the sender's domain is not authorized by SPF (Sender Policy Framework).
S/MIME – General
Acquire S/MIME Only
Is the S/MIME feature also available as a standalone (without Securepoint Mail Security)?
Answer
S/MIME serves as an add-on to Securepoint mail.security and therefore cannot be purchased separately.
Prerequisites
What are the prerequisites for using S/MIME?
Answer
S/MIME certificates can only be requested for domains whose MX record points to mx.mymailwall.com and which are set up in an incoming route.
Certify Internal Email
Can internal emails also be certified with a certificate?
Answer
Only emails sent via Securepoint Mail Security/mymailwall are provided with an S/MIME certificate.
Provide Mailbox with Certificate
How can I provide mailboxes with a certificate?
Answer
Under the menu item mail.security > S/MIME, you will find a list of your mailboxes. Here you can activate one, several, or all mailboxes. Signing and encryption are then carried out automatically according to the rules you have set when sending emails via Securepoint Mail Security/mymailwall.
Mailbox Not in Overview
Why don't I see my mailbox in the S/MIME overview?
Answer
The mailboxes must be set up as known mailboxes in an incoming route. Mailboxes captured in a wildcard route are not displayed.
License Cross-Domain
Is the license cross-domain, or does it need to be acquired per domain?
Answer
The license is acquired cross-domain, similar to Securepoint Mail Security, and can therefore be used for any number of domains.
License Count Incorrect
My license count is displayed incorrectly in the Securepoint portal. How can I change this?
Answer
Please contact Securepoint Support.
Download S/MIME Certificate
Where can I download the S/MIME certificate?
Answer
Downloading S/MIME certificates is not technically provided for security reasons.
Use Existing Certificate
Can I use an existing (third-party) certificate for certain mailboxes?
Answer
Within your existing license, you can upload any number of existing (third-party) certificates, which are then managed and used like Securepoint S/MIME certificates. Please note that these also count as licenses and thus reduce your available quota.
In Deactivation
What does the status "Revoke pending" (EN) / "in Deaktivierung" (DE) mean?
Answer
These are mailboxes that have been deactivated. This status remains for up to 14 days until the status changes to "Inactive" (EN) / "Inaktiv" (DE) and the license becomes available again.
S/MIME License Equals Securepoint Mail Security License
Does the S/MIME license have to match the Securepoint mail.security license?
Answer
No. The S/MIME license can be smaller than or equal to the Securepoint mail.security license.
Validity Period
How long is an S/MIME certificate valid?
Answer
Securepoint S/MIME licenses automatically receive the same validity period as your existing Securepoint Mail Security license. Technically, these are 1-year certificates, but they are automatically renewed without additional costs (within the existing license).
Certificate Issuer
Who issues the S/MIME certificates?
Answer
The S/MIME certificates are issued by the European certification authority Certum. Certum is included in the Adobe Approved Trust List (AATL), an exclusive list of trusted certificate issuers.
S/MIME – Encryption
License Prerequisite
When or with which license can email encryption be used? Does this incur additional costs?
Answer
Email encryption is part of Securepoint S/MIME and is included in the price of Securepoint S/MIME licenses. Securepoint S/MIME can be obtained by all Securepoint mail.security users.
Applicability of Encryption
For which mailboxes can encryption be used?
Answer
Encryption can be applied to all mailboxes managed with Securepoint mail.security with an active Securepoint S/MIME certificate. Please note that with enforced encryption for outgoing emails (Outbound), mailboxes without a valid Securepoint S/MIME certificate affected by this rule cannot send emails!
Optional decryption is also applied to mailboxes without a Securepoint S/MIME certificate.
Error with Enforced Rule
What happens if an "enforced" rule is active and fails?
Answer
Prerequisite for Encryption
What are the prerequisites for encrypting emails?
Answer
A prerequisite for encrypting emails is an active certificate and the recipient's public key. The keys are automatically exchanged and stored via an unencrypted but signed email.
Prerequisite for Decryption
What are the prerequisites for decryption?
Answer
A prerequisite for all rule variants for incoming emails (Inbound) is an existing certificate for the receiving mailbox. Optional decryption is also applied to mailboxes without a Securepoint S/MIME certificate.
Use Existing Certificates
Can existing certificates be used?
Answer
Yes, S/MIME certificates not obtained via Securepoint can also be managed in Securepoint Mail Security. They can be uploaded under the S/MIME menu item in the Securepoint portal. They have the same functionality as Securepoint S/MIME certificates and are counted towards your Securepoint license quota.
Permission to Change Rules
Who can create/change rules?
Answer
All users of the Securepoint portal with write permissions can create or change rules.
Activation Duration of Rule
How long does it take for a rule to become active after creation?
Answer
It can take up to 10 minutes after creating/editing a rule for it to be considered when sending/receiving.
Detection of Encryption/Decryption
Where can I see if an email was encrypted or decrypted?
Answer
Which emails were encrypted, decrypted, or signed can be viewed in the email overview under the Securepoint Mail Security menu item. It is also possible to filter by status.
Encryption Type
What type of encryption is applied?
Answer
S/MIME uses asymmetric encryption. The recipient's public key is used to encrypt content, which can only be decrypted again with the private key.
Exchange of Public Keys
How can the exchange of the public key take place?
Answer
The public keys required for encryption can be exchanged via an unencrypted, signed email. Securepoint Mail Security automatically extracts and stores the key.
ATP
General Meaning and Function
What is ATP?
Answer
ATP stands for Advanced Threat Protection and refers to an approach in information security that focuses on detecting and defending against advanced threats and attacks designed to bypass traditional security measures such as malware scanners and firewalls.
Functionality of ATP
How does the ATP add-on protect against targeted attacks?
Answer
In addition to the analysis methods of the malware scan engine based on signatures, content, and behavior, Securepoint Mail Security with ATP uses signatureless methods and sandboxes from various leading sandboxing providers.
All types of attachments are specifically examined for hidden attacks and are test-executed in connection with various combinations of operating systems and applications, including different web browsers and plugins such as Adobe Reader or Flash.
This allows even attacks designed to bypass traditional security solutions to be detected.
Delay Due to ATP
What delays in email delivery can be expected due to the extensive ATP analyses?
Answer
Only data for which the malware scan engine cannot reach a reliable conclusion is forwarded and analyzed again in parallel—these are in the per mille range of the total data volume.
As a result, analyses usually run as quickly as usual and are barely noticeable in terms of time. However, depending on the scope of the ATP analysis, individual elements may take up to ten minutes to process
ATP Analysis Results
Where can I see the results of the ATP analysis?
Answer
The data identified as threats during the ATP analysis are displayed. They appear in the email search with the label "Infected (ATP)."
Data Protection and ATP
What data is transmitted to the sandboxes, and which data protection laws apply?
Answer
The sandboxes of our technology partners are installed in the German-speaking region. This ensures that all data—only metadata, attachments, or scripts are sent—remains within the EU.
European and German data protection laws (GDPR) apply.
While the sandboxes continuously receive updates from their manufacturers, they are isolated in such a way that they cannot establish any external connections themselves.