<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Security for Mail Server?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Kaspersky Secure Mail Gateway</strong> – Ready-to-use appliance with its own mail transfer agent.<br /> <strong>Security for Exchange Servers</strong> – Protects Microsoft Exchange traffic at gateway and mailbox level.<br /> <strong>Security for Microsoft 365</strong> – SaaS cover for Exchange Online, OneDrive, SharePoint and Teams.<br /> <strong>Sender authentication</strong> – SPF, DKIM, DMARC and domain sender alignment verdicts.<br /> <strong>KSMS Plus tier</strong> – Adds content disarm, encrypted archive scanning and sandboxing.<br /> <strong>Important</strong> – No single console covers all three applications together.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Security for Mail Server?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Security for Mail Server is a mail-layer security product that bundles three applications under a single licence, covering an on-premises gateway, Microsoft Exchange and Microsoft 365. The on-premises applications report into Kaspersky Security Center while the Microsoft 365 application is managed from Kaspersky Business Hub, and the gateway itself grew out of Kaspersky Security 8 for Linux Mail Server, a name many buyers still search for.<br /><br /> <strong>One licence</strong> – Run one application or all three together.<br /> <strong>Gateway and mailbox</strong> – Stops mail before delivery and inside the mailbox.<br /> <strong>AI phishing heuristics</strong> – Flags LLM-written mail carrying no link or attachment.<br /> <strong>Encrypted archive scanning</strong> – Users submit archive passwords via a dedicated web portal.<br /> <strong>SIEM export</strong> – Mail events exported in CEF for SIEM correlation.<br /> <strong>KATA sandbox link</strong> – Attachments detonate and verdicts appear in KATA alerts.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where built-in protection stops and where a dedicated security layer takes over.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Security for Mail Server suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether you operate your own mail infrastructure. A company whose mail runs entirely in Microsoft 365 needs only the SaaS application; a company running Exchange on-premises or a gateway in front of it is the intended case for the full licence.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasionally</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Own Exchange or mail gateway to protect</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Cloud app only</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Mail Server meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Swiss reporting obligation applies to operators of critical infrastructure named in the revised Information Security Act, not to every company, so most SMEs are not affected by it at all. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. On the mail layer the product supports that deadline in a practical way: the gateway and Exchange applications record a verdict per message, hold blocked mail in Backup and export events in CEF, so an administrator can reconstruct when a malicious message arrived and which mailboxes received it without reading raw mail logs by hand. What it does not do is detect an incident that started anywhere else, because it has no endpoint, server or network telemetry, so a compromise via stolen credentials or a removable device leaves no trace in its logs. It also produces no report in the form BACS expects, and the notification itself remains a manual task for your own staff. This is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Mail Server meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates NIS 2 compliance, because the directive addresses organisations and their management bodies rather than the software they buy. NIS 2 requires measure categories including risk analysis and information security policies, incident handling, business continuity and crisis management, supply chain security, and policies on the use of cryptography. Kaspersky Security for Mail Server contributes to incident handling and to the technical protection of one communication channel: filtering, quarantine with a user-level release portal, sender authentication through SPF, DKIM and DMARC, and event export to a SIEM. It contributes nothing to business continuity, backup, access control, vulnerability handling or supplier assessment, and nothing to the governance and staff training duties the directive places on management. Treat it as one documented technical control among many, not as evidence that the measure catalogue has been met.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In March 2022 the German Federal Office for Information Security (BSI) issued a public warning against the use of Kaspersky antivirus software and recommended replacing it with alternative products. The warning remains in force in 2026 and is now regulated under Section 13 of the amended BSI Act, which took effect on 6 December 2025. Separately, the US Department of Commerce prohibited new sales and product updates in the United States from 2024. Kaspersky rejects the German warning as politically rather than technically founded, has publicly asked the BSI to withdraw it and has reserved the right to take legal steps. Independent evaluation of the mail product itself continues: Kaspersky was named a Leader in the SPARK Matrix Enterprise Email Security report 2025 by Quadrant Knowledge Solutions. In Switzerland the position is different again, because BACS does not issue recommendations on individual products, states that no misuse of Kaspersky software has been reported to it, and has imposed no ban; Kaspersky also operates a data centre and a transparency centre in the Zurich area. In practice this matters most if you sell into the public sector, work as a supplier to German authorities or critical infrastructure operators, or answer supply chain questionnaires that ask about vendor country of origin, since a listed vendor can cost you the contract regardless of test results.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection?</strong><br />Compares detection quality and product scope of the two vendors side by side.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Mail Server help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only for the email section. It answers questions on inbound and outbound mail filtering, anti-phishing and anti-spam controls, malicious attachment and link handling, quarantine and release workflow, sender authentication policy through SPF, DKIM and DMARC, audit logging, and forwarding of security events to a SIEM. It answers nothing on endpoint protection, EDR, patch status, disk encryption, multi-factor authentication, backup and restore testing, mobile device management or security awareness training, and it produces no asset inventory. Those are usually the items that decide whether a questionnaire is accepted, so the mail product alone will not clear one. Where the gap is on the mail side, moving from KSMS to KSMS Plus is the cheaper route; where the gap is endpoint or EDR, staying inside the same vendor family with a Kaspersky Next tier keeps one console and one support contract instead of splitting the estate across two vendors.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>Test: Best antivirus programs for Windows</strong><br />Covers the endpoint protection layer that a mail security product does not include.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between KSMS and KSMS Plus?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The single decisive difference is attachment handling. Base KSMS blocks or delivers an attachment, while KSMS Plus can strip the dangerous elements out of it through content disarm and reconstruction and deliver a safe version instead, and it can open password-protected archives whose password is not in the same message by having the recipient enter it on a dedicated portal. KSMS Plus also adds the heuristics for AI-generated mail and for list-linking, also known as mail bombing. Everything a standard mail filter is expected to do is already in the base tier, so the upgrade is a question of whether targeted attachment-based attacks are part of your threat picture.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">KSMS</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">KSMS Plus</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Anti-spam, anti-phishing, anti-malware</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Sender authentication (SPF, DKIM, DMARC)</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">QR code phishing detection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Content disarm and reconstruction</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Password-protected archive scanning</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">AI-generated email heuristics</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">List-linking (mail bombing) detection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Availability is regionally restricted: since the 2024 US Department of Commerce rule, Kaspersky products cannot be newly sold or updated in the United States, which matters if your group has US entities or your mail infrastructure is administered from there. The product covers the email layer only, so workstations, file servers, mobile devices and the endpoints that actually open the delivered mail all still need their own protection. Management is not unified either: the gateway runs from its own web interface and can report into Kaspersky Security Center, while the Microsoft 365 application is administered separately from Kaspersky Business Hub. The Exchange application additionally depends on a Microsoft SQL Server instance being available, which is the most common unbudgeted item when a first deployment is planned. Finally, the base tier stops at blocking attachments rather than sanitising them, and that is the usual reason for a later move to KSMS Plus.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Security for Mail Server</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it run without sending data to the vendor cloud?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, on the gateway side. Kaspersky Secure Mail Gateway can integrate with Kaspersky Private Security Network and use the reputation databases locally, so no data leaves the organisation, and it can also be deployed in a certified mode in which the appliance is not permitted to reach servers outside your own infrastructure.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Are older mail platforms such as Lotus Notes and Domino still covered?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The current official application list names three applications: the secure mail gateway, the Microsoft Exchange application and the Microsoft 365 application. Older retail listings for this product also mentioned Lotus Notes and Domino, Sendmail, Qmail, Postfix and Exim, so check the current application list against your own platform before ordering rather than relying on an archived description.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-email,compliance-supplier,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>