What are the primary benefits of Trend Micro ScanMail for MS Exchange Suite Corporate?
Central console – Web console replicates settings to all Exchange servers.
Exchange coverage – Supports Exchange Server 2016, 2019 and Subscription Edition.
Spam filtering – Spam engine, Email Reputation and End User Quarantine included.
BEC detection – Flags messages impersonating executives through writing style analysis.
Link protection – Web Reputation and Time-of-Click rewriting check embedded URLs.
Important note – Protects on-premises Exchange only, not Exchange Online or endpoints.
Security Risk Scan – Detects malware, spyware and document exploits at transport and store level.
Spam and BEC filters – Spam engine, Email Reputation and writing-style checks against executive impersonation.
Content and DLP policies – Active Directory-based rules plus over 100 predefined data templates.
Web Reputation, Time-of-Click – Checks URLs on delivery and again when recipients click.
Search & Destroy – Finds and removes unwanted messages across Exchange mailboxes by keyword.
Important – No endpoint, file server or Exchange Online protection; sandbox licensed separately.
Trend Micro ScanMail for MS Exchange Suite Corporate is the Suite edition of ScanMail for Microsoft Exchange, installed directly on on-premises Exchange servers. Each server has its own web console, while the Server Management console and optional Apex Central integration let administrators monitor and configure several servers from one place.
One configuration, many servers – Replicate tested settings to remote ScanMail servers instead of reconfiguring.
Cleanup after an incident – Search & Destroy removes delivered phishing messages from mailboxes.
Logs for your SIEM – Forwards security risk, policy violation, spam and audit logs.
Internal mail scanned too – Filters apply to inbound, outbound and internal Exchange messages.
High availability supported – Installs on Exchange 2016 and 2019 Database Availability Groups.
Vision One integration – Forwards detection logs and applies Vision One suspicious object lists.
ScanMail Suite suits any organisation that still runs Microsoft Exchange Server on its own infrastructure, from a single-server office to multi-site environments with Database Availability Groups. The mail platform matters more than headcount: companies that have moved all mailboxes to Exchange Online need Trend Micro's separate cloud service instead.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Exceptions only | By sector | By sector |
| Security questionnaire from large customers | Occasional | Common | Common |
| Consistent mail policy across Exchange servers | Single server | ✓ | ✓ |
| This product fits | With own Exchange | ✓ | ✓ |
Since 1 April 2025, the revised Information Security Act requires operators of critical infrastructure, for example energy suppliers, hospitals, transport companies and public authorities, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Most private SMEs outside these sectors are not directly subject to this obligation. On the mail server, ScanMail supports the reporting process with detection logs, quarantine records and one-time or scheduled reports that show when a malicious message arrived, who received it and which action was taken, and SIEM forwarding makes these events available to a central monitoring team. The product does not decide whether an incident is reportable, does not submit the report to BACS, and gives no visibility into endpoints, file servers or Exchange Online. This information does not constitute legal advice; affected organisations should clarify their obligations with a qualified specialist.
No software product makes a company compliant with the NIS 2 Directive, because compliance depends on governance, processes and evidence across the whole organisation. Article 21 of the directive requires risk-management measures including incident handling, business continuity, supply chain security, vulnerability handling, cyber hygiene and training, cryptography, access control and multi-factor authentication where appropriate. ScanMail contributes to incident handling through detection, quarantine, outbreak alerts and SIEM log forwarding, and to cyber hygiene by filtering phishing, malicious links and executive-impersonation emails before they reach users. Its role-based access control and optional FIPS mode help protect the mail security layer itself. It does not cover backup and business continuity, email encryption, multi-factor authentication, patch or vulnerability management, staff training, or protection of endpoints and cloud mailboxes.
Yes for questions about email security on your own Exchange servers, and no for most other areas. ScanMail lets you answer items on malware and spam filtering at the mail server, protection against phishing links and business email compromise, data loss prevention for outgoing mail, quarantine handling, log forwarding to a SIEM, and restricted administrator access through role-based permissions. It gives no answer to questions on endpoint protection and EDR, patch management, backup and recovery, disk or email encryption, multi-factor authentication, security awareness training, or protection of Microsoft 365 mailboxes. Sandbox analysis of suspicious attachments is only available if you also operate a separately licensed Trend Micro Deep Discovery Analyzer. Suite is already the highest ScanMail edition, so remaining gaps need additional products; staying within Trend Micro, for example Apex One for workstations and file servers and Cloud App Security for Microsoft 365 mailboxes, keeps logs and quarantine management in consoles that ScanMail already integrates with.
The decisive difference is spam protection: only the Suite edition includes the spam engine, Email Reputation, Advanced Spam Prevention with business email compromise detection, and End User Quarantine. Suite also adds content filtering, data loss prevention, Web Reputation, URL Time-of-Click Protection and Search & Destroy. Both editions share the same malware scanning including the Advanced Threat Scan Engine, attachment blocking, manual and scheduled scans, and Apex Central support. The Server Management console only lists servers running the same edition, so mixing Standard and Suite splits central administration.
| Feature | ScanMail Standard | ScanMail Suite |
|---|---|---|
| Malware and exploit scanning | ✓ | ✓ |
| Attachment blocking | ✓ | ✓ |
| Antispam and Email Reputation | ✕ | ✓ |
| Business email compromise detection | ✕ | ✓ |
| Content filtering and DLP | ✕ | ✓ |
| Web Reputation and Time-of-Click | ✕ | ✓ |
| Search & Destroy | ✕ | ✓ |
| Apex Central support | ✓ | ✓ |
| Sandbox (Virtual Analyzer) | Separate licence | Separate licence |
ScanMail protects only on-premises Exchange Server 2016, 2019 and Subscription Edition; it does not cover Exchange Online, non-Exchange mail servers, mail gateways, file servers or workstations. Exchange 2016 deployments are tied to Windows Server 2012 to 2016, while Exchange 2019 and Subscription Edition run on Windows Server 2019, 2022 or 2025, and because Microsoft ended support for Exchange 2016 and 2019 in October 2025, ScanMail does not replace a move to Subscription Edition. Sandbox analysis requires a separately licensed Deep Discovery Analyzer or Advisor, and writing-style detection of business email compromise works only for inbound mail. Web Reputation, Time-of-Click Protection and Predictive Machine Learning query Trend Micro cloud services, so the Exchange server needs outbound internet or proxy access, and data protection officers should review Trend Micro's data collection disclosure.
Since March 2026, Trend Micro's enterprise business operates under the name TrendAI. The official documentation continues to use the product name ScanMail for Microsoft Exchange, currently in version 14.0 with ongoing patch releases.
Yes, ScanMail can be installed on Exchange 2016 and 2019 servers with the Edge Transport role. Manual and scheduled mailbox scans are only available on servers with the Mailbox role.
Yes. Trend Micro recommends excluding the ScanMail storage, temp and debug folders from file-based antivirus scans to avoid conflicts.
ScanMail protects only the on-premises Exchange servers in a hybrid deployment. For Exchange Online mailboxes, Trend Micro offers Cloud App Security, to which ScanMail can forward policy violation logs so that quarantined messages from both environments can be managed in one console.
It scans emails on Microsoft Exchange Server 2016, 2019, and SE for malware, spam, and malicious links. Designed for companies that use Exchange on-premises.
Trend Micro ScanMail for MS Exchange Suite Corporate, Trend Micro, TrendAI, ScanMail Suite for Microsoft Exchange, Exchange Server security, mail server antivirus, antispam, data loss prevention, Business Email Compromise
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies