What are the key advantages of ESET PROTECT Mail Plus?
Central management – ESET PROTECT console, cloud or on-premises.
Exchange protection – Scans mail flow on the Exchange server.
Antispam engine – With SPF and DKIM validation and backscatter protection.
Cloud sandbox – Analyses unknown attachments before mailbox delivery.
Quarantine management – Central quarantine, users release their own messages.
Important note – No endpoint protection or Microsoft 365 mailbox coverage.
ESET Mail Security – Server-level scanning of Microsoft Exchange transport and mailbox databases.
ESET LiveGuard Advanced – Cloud sandbox that detonates unknown attachments before delivery.
ESET PROTECT console – Central management as cloud service or on-premises installation.
Antispam and anti-phishing – SPF and DKIM validation, backscatter and SMTP protection.
Rules and quarantine – Custom filtering rules plus central and per-user quarantine.
Important – No endpoint, file server, encryption or Microsoft 365 coverage.
ESET PROTECT Mail Plus is a mail-server security tier of the ESET PROTECT platform and contains exactly three modules: the console, Mail Server Security for Microsoft Exchange, and the ESET LiveGuard Advanced cloud sandbox. ESET previously marketed this bundle as ESET Dynamic Mail Protection, and it is managed from the same console as the vendor's endpoint tiers.
Filtering before delivery – Blocks malicious mail at the server, not the workstation.
Fewer helpdesk tickets – Users release their own quarantined mail without admin help.
Unknown attachment analysis – Suspicious files are detonated in an EU-hosted sandbox.
Evidence-ready reporting – Over 170 built-in reports in the ESET PROTECT console.
SIEM log export – Detection and audit events via syslog in CEF or LEEF.
Cluster support – Multiple Exchange servers share configuration and greylisting data.
The deciding factor is not headcount but whether you still run your own Microsoft Exchange server. Organisations that moved their mailboxes entirely to Microsoft 365 gain nothing from this tier, because it protects the on-premises mail server rather than cloud mailboxes.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Exception only | By sector | By sector |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Own Microsoft Exchange server on site | Rare | Common | Common |
| This product fits | With Exchange | ✓ | One layer |
No software product meets these requirements on its own, and this one covers a single channel. Under the revised Information Security Act, operators of critical infrastructure must report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further period to complete the initial report; this affects organisations such as energy and drinking water supply, transport operators, and cantonal and communal administrations, not every company with an Exchange server. Where an incident starts with an email, this product supports the reporting duty in a concrete way: the console keeps timestamped detection records, the quarantine shows which messages were held and which were released, and detection and audit events can be forwarded by syslog to a SIEM in JSON, LEEF or CEF format, which is what you need to reconstruct the sequence within a day. What it does not cover is at least as important: it produces no telemetry from workstations or servers outside the mail path, it contains no XDR component for root-cause analysis, it does not classify whether an incident is reportable, and it does not submit anything to BACS. This information is a general orientation and does not replace legal advice.
No product creates compliance with the NIS 2 Directive, because the directive addresses organisational risk management rather than the purchase of software. NIS 2 requires measure categories including risk analysis and information system security policies, incident handling, business continuity, supply chain security, cyber hygiene practices and training, cryptography, access control, and the use of multi-factor authentication or secured communications. This product contributes to incident handling and cyber hygiene for the email channel specifically: phishing and malware are filtered at the Exchange server before delivery, unknown attachments are analysed in a sandbox, and the resulting detections are logged centrally and exportable. It contributes nothing to several other categories: there is no multi-factor authentication, no encryption of devices or data at rest, no vulnerability and patch management, no business continuity or backup function, and no awareness training. Treat it as one documented technical measure covering one attack vector, and expect to name separate products for the remaining categories.
Partly, and the split is easy to predict. It answers questionnaire items on email filtering (server-level antispam and anti-phishing with SPF and DKIM validation, backscatter and SMTP protection), on sandbox analysis of unknown attachments, on centralised security management with role-based access, on log retention and SIEM forwarding by syslog, and on reporting, where the console provides over 170 built-in reports and custom reports drawn from more than 1000 data points. It also answers the data location question that European and Swiss auditors ask most often: the private cloud infrastructure for ESET LiveGuard Advanced is located exclusively in the EU, sample analysis takes place at ESET headquarters in Bratislava, Slovakia, the service is covered by ESET's ISO 27001 certification, and the administrator decides whether clean samples are deleted immediately after analysis, after 30 days, or retained. It answers none of the following: endpoint protection and EDR coverage, vulnerability and patch management, disk encryption, multi-factor authentication, mobile device management, mailbox backup or archiving, protection of Microsoft 365 mailboxes, and security awareness training. If more than one or two of those are open items in your questionnaire, moving up to a higher tier of the same family is usually cheaper and simpler than adding a second vendor, because you keep one console, one agent framework and one set of reports for the evidence trail.
The decisive difference is that Mail Plus contains no endpoint protection at all, while Complete is a full endpoint suite that happens to include the same mail server module. Mail Server Security is not available in the Entry or Advanced tiers; Complete is the lowest full tier that includes it. So the real choice is whether you already have endpoint protection you are happy with and only need to close the mail server gap, or whether you are buying protection for the whole estate at once. Neither tier includes the ESET Inspect XDR component, which starts at the Elite tier.
| Component | Mail Plus | Complete |
|---|---|---|
| ESET PROTECT console | ✓ | ✓ |
| Exchange mail server security | ✓ | ✓ |
| Cloud sandbox (Advanced Threat Defense) | ✓ | ✓ |
| Endpoint and file server protection | ✕ | ✓ |
| Full disk encryption | ✕ | ✓ |
| Microsoft 365 and Google Workspace protection | ✕ | ✓ |
| Vulnerability and patch management | ✕ | ✓ |
| XDR with ESET Inspect | ✕ | ✕ |
Platform coverage is narrower than older marketing material suggests. According to ESET's own system requirements, Microsoft Exchange is the only supported mail server: Exchange Server Subscription Edition, Exchange Server 2019, 2016 and 2013, installed on Windows Server 2012 R2 through Windows Server 2025; a standalone Client Access Server role is not supported. Some ESET product pages still show the wording Exchange and Domino, but ESET Mail Security for IBM Domino stopped being sold on 31 July 2024 and reached End of Life on 31 July 2026 with no successor product, so Domino environments cannot be covered by a new purchase. The most frequent follow-up purchase is Microsoft 365 protection: mailboxes hosted in Exchange Online are not covered here and require the separate Cloud App Protection module, which is why organisations mid-migration often end up buying twice. Finally, this is a filtering product, not a retention product: it holds quarantined messages, but it performs no mailbox backup, journaling or long-term archiving, and it leaves workstations entirely unprotected.
It is software installed directly on the Microsoft Exchange server, not an upstream cloud gateway. Your MX records and mail routing stay as they are, and scanning happens on the transport layer and against the mailbox databases on the machine itself.
ESET states that ESET Mail Security supports businesses running Microsoft Exchange in a hybrid setup. Note that it protects the on-premises Exchange side of that hybrid; mailboxes that have already been moved to Exchange Online are outside its scope.
Suspicious samples are analysed at ESET headquarters in Bratislava, Slovakia, on private cloud infrastructure located exclusively within the EU. The administrator sets the retention policy for clean samples: deletion immediately after analysis, deletion after 30 days, or retention.
Filters spam, phishing and malware on Microsoft Exchange, managed from the ESET PROTECT console. Endpoint protection not included.
ESET PROTECT Mail Plus, ESET, ESET PROTECT, ESET Dynamic Mail Protection, mail server security, Exchange antispam, anti-phishing, cloud sandbox
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies