<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Security for Mail Server Add-On?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Kaspersky Secure Mail Gateway</strong> – Ready-built SEG appliance with mail transfer agent included.<br /> <strong>Kaspersky Security for Exchange</strong> – Scans Microsoft Exchange traffic at gateway and mailbox level.<br /> <strong>Kaspersky Security for M365</strong> – API-based protection for Exchange Online, SharePoint, OneDrive, Teams.<br /> <strong>Sender authentication</strong> – SPF, DKIM, DMARC and domain sender alignment checks.<br /> <strong>Quarantine and reporting</strong> – Role-based access, CEF syslog export to your SIEM.<br /> <strong>Important</strong> – No endpoint, EDR, encryption or patch management is included.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Security for Mail Server Add-On?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Security for Mail Server is an email security product that adds gateway-level and mailbox-level scanning, and the Add-On licence variant is sold for organisations that already run a Kaspersky business product. Each of the three applications is configured in its own web console with Kaspersky Security Center used for central status monitoring, and the Microsoft 365 application was previously sold under the name Kaspersky Security for Microsoft Office 365.<br /> <br /> <strong>Blocking before the mailbox</strong> – Malicious mail is stopped at the gateway, not afterwards.<br /> <strong>Fewer manual spam checks</strong> – ML-based quarantining cuts the daily allowlist and release workload.<br /> <strong>Cross-product visibility</strong> – Sends detections to Kaspersky SIEM and Next XDR Expert.<br /> <strong>One licence, three apps</strong> – Gateway, Exchange and Microsoft 365 without separate purchases.<br /> <strong>Cluster scaling</strong> – Gateway nodes scale horizontally under one web console.<br /> <strong>Active Directory integration</strong> – Policies and role-based access follow existing domain groups.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where built-in protection stops and which attack paths, including email, stay open.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Security for Mail Server Add-On suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive question is not headcount but whether your organisation still receives mail through its own Exchange server, a mail gateway, or Microsoft 365 mailboxes you administer yourself. Companies that have already standardised on Kaspersky for endpoints are the natural buyers, because the Add-On licence attaches to that existing licence.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Usually</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Filtering before the mailbox</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Optional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">With base licence</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Mail Server Add-On meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every company, and it requires a significant cyberattack to be reported to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Meeting a 24-hour deadline depends on noticing the incident in the first place, and here the product contributes two concrete things: message processing events are logged in CEF format and can be pushed to a SIEM via syslog, and detections can be forwarded to Kaspersky Anti Targeted Attack for correlation with endpoint and network events. What it does not do is produce the report itself, cover the attack paths outside email, or evidence the organisational measures the Act expects, such as a documented incident process and named responsibilities. If the initial intrusion arrives through a browser download, a VPN appliance or a stolen credential rather than through a mail attachment, this product will not see it at all. Whether your organisation is subject to the reporting obligation is a legal question, and this text is not legal advice.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Mail Server Add-On meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product makes an organisation compliant with the NIS 2 Directive, because the Directive addresses management responsibility, risk analysis and process, not the purchase of tools. NIS 2 sets out categories of measure that in-scope entities must implement, including incident handling, business continuity, supply chain security, access control, cyber hygiene and awareness, and policies for assessing whether measures actually work. This product maps to a narrow slice of that: it provides detection and filtering for one attack vector, quarantine handling as part of incident response, role-based administrator access, and event export that feeds incident handling evidence. It does not cover business continuity or backup, supply chain risk assessment, vulnerability handling across your estate, staff awareness training, or the periodic effectiveness review the Directive expects. Buyers in scope of NIS 2 should treat email security as one control among many rather than as a compliance answer.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Germany's Federal Office for Information Security (BSI) issued a warning against the use of Kaspersky antivirus software on 15 March 2022 and recommends replacing applications from that portfolio with alternative products. The warning is still published and, since 6 December 2025, sits under Section 13 of the amended BSIG rather than the former Section 7. It is a recommendation, not a prohibition, and Kaspersky products remain legally available in Germany. Separately, the US Department of Commerce prohibited the sale of Kaspersky software in the United States from 20 July 2024 and the supply of updates from 29 September 2024; that measure remains in force. Kaspersky rejects the BSI assessment as unfounded, has publicly pressed for its withdrawal and reserves legal steps, and points to its European data processing in Switzerland, its transparency centres where source code can be inspected, and its continued participation in independent laboratory testing, where its products are regularly evaluated. In Switzerland the position is different again: BACS has issued no product warning against Kaspersky, states that no misuse of the software has been reported to it, and confirms there is no internal directive banning the products, while noting it would warn publicly if verified technical evidence emerged. Practically, this matters most to buyers who sell into the public sector, who operate US entities, or whose large customers impose country-of-origin conditions on security software in their supplier requirements; for a purely domestic Swiss company with no such clauses, it is a judgement call rather than a blocker.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />Compares detection performance and practical differences between the two vendors for buyers weighing a switch.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Mail Server Add-On help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partially, and only for the email section. It answers questions on inbound and outbound mail filtering, malware and phishing scanning at gateway and mailbox level, sender authentication using SPF, DKIM and DMARC, quarantine handling and message release workflow, role-based administrator access, Active Directory-based policy assignment, and whether security events can be exported to a SIEM in a standard format. It does not answer the questions that usually follow: endpoint protection and EDR coverage, patch and vulnerability management, disk encryption on laptops, mobile device management, backup and recovery testing, multi-factor authentication, or documented staff security training. It also does not produce an audit-ready attestation on its own, since the reports it generates cover mail traffic rather than your control framework. To close those gaps, the cheaper route is normally to move up within the same vendor family, for example to a Kaspersky Next tier that adds endpoint, EDR and encryption management under one console, rather than bolting a second vendor's agent onto the same machines and then having to explain two management planes in the questionnaire.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between KSMS and KSMS Plus?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The single most decisive difference is content disarm and reconstruction: KSMS Plus strips active content out of attachments and delivers a neutralised version, while KSMS relies on detection alone. Beyond that, KSMS Plus targets the evasion techniques that have grown fastest, namely password-protected archives, machine-generated phishing text and mail bombing through mass list subscription. Both tiers share the same anti-spam, anti-malware, anti-phishing and sender authentication engines, so KSMS is not a cut-down scanner but a narrower feature set. Organisations with a security team that already triages alerts tend to need the Plus tier; organisations that simply want less spam and fewer malicious attachments usually do not.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">KSMS</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">KSMS Plus</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Anti-spam, anti-malware, anti-phishing</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">SPF, DKIM and DMARC authentication</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">QR code phishing detection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Content disarm and reconstruction</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Password-protected archive scanning</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">AI-generated email detection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Mail bombing detection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Update and KSN availability in the USA</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Restricted</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Restricted</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Add-On licence is not a standalone purchase: it attaches to an organisation that already runs a Kaspersky business product, and buyers starting from nothing need the base licence variant instead. There is a regional restriction that matters if you have a US entity, because Kaspersky's own documentation states that update functionality, including anti-virus signature and code base updates, as well as Kaspersky Security Network functionality, may not be available in the territory of the USA. The three applications are not administered from one single pane: the gateway and the Microsoft 365 application each have their own web console, and Kaspersky Security Center supplies central status monitoring rather than unified policy editing, which is a common source of follow-up questions during rollout. Coverage stops at email, so endpoint protection, EDR, disk encryption, patch management and mobile device security all require separate products, and the features most often assumed to be included, notably content disarm and reconstruction and password-protected archive scanning, sit in the KSMS Plus tier rather than the base tier. The product also does not archive or back up mail, so retention and recovery remain a separate purchase.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="office-2024-backup-business-pst-windows"><strong>Planning Office 2024 Backups for Businesses the Right Way</strong><br />Covers backing up files, Outlook PST archives, templates and the Windows system without data loss.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Security for Mail Server Add-On</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the applications be run without Kaspersky Security Center?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Kaspersky Secure Mail Gateway is configured entirely through its own web interface, including rules, domains, quarantine and reporting. Kaspersky Security Center is optional and is used to monitor product state centrally alongside other Kaspersky applications.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the mail gateway be scaled across several servers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Kaspersky Secure Mail Gateway supports cluster deployment and scales horizontally or vertically, with all servers in the cluster managed centrally from the application web interface. It is delivered either as a virtual machine image with a pre-installed operating system and mail transfer agent, or as an RPM or DEB installation package.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-email,sec-server,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>