<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Bitdefender GravityZone Security for Email Add-On?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Secure email gateway</strong> – Pre-delivery filtering of inbound mail before it reaches mailboxes.<br /> <strong>API mailbox protection</strong> – Post-delivery scanning that retracts threats already sitting in inboxes.<br /> <strong>Email authentication</strong> – Built-in SPF and DMARC checks against spoofed sender domains.<br /> <strong>Live Email Tracker</strong> – Search, preview, release or delete individual messages during investigations.<br /> <strong>End-user quarantine digest</strong> – Scheduled digests let staff release held mail themselves.<br /> <strong>Important</strong> – No mailbox backup or archiving; filtering does not retain mail.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Bitdefender GravityZone Security for Email Add-On?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is the email protection layer for the GravityZone platform, administered from the same cloud console as endpoint protection rather than from a separate mail security portal. Bitdefender retired the original Security for Email platform on 31 January 2026 and now delivers this protection through GravityZone Extended Email Security, which combines gateway filtering with API-based mailbox protection.<br /><br /> <strong>One console</strong> – Email and endpoint alerts sit in one platform.<br /> <strong>Fast rollout</strong> – API connection to Microsoft 365 needs no mail rerouting.<br /> <strong>BEC protection</strong> – Detects impersonation and payment fraud that spam filters miss.<br /> <strong>Fewer helpdesk tickets</strong> – Users release their own held mail from digests.<br /> <strong>Outbound scanning</strong> – Protects sender reputation and reduces blacklisting of your domain.<br /> <strong>Multi-tenant management</strong> – Providers act on threats across several customers at once.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains why the protection built into the operating system leaves gaps that a dedicated security product has to close.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Bitdefender GravityZone Security for Email Add-On suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The add-on scales from a handful of mailboxes to multi-tenant environments, but the reason to buy it changes with company size. Small companies buy it to stop invoice fraud; larger organisations buy it because they have to prove what happened to a specific message.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Increasing</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Removal of already delivered mail</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Useful</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Security for Email Add-On meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so most small firms are affected only indirectly through the customers they supply. Operators in scope must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. The Live Email Tracker supports that deadline in a concrete way: it shows which mailboxes received a specific message, when it arrived and what verdict the filters gave it, which is roughly the set of facts a first report needs. What the add-on does not provide is the rest of the picture. It holds no endpoint telemetry, no evidence that an attacker was removed from the network, and no long-term archive of the affected mail, so an organisation subject to reporting still needs endpoint detection and a retention plan beside it. This text is general product information and not legal advice; assess your own obligations with a qualified adviser.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Security for Email Add-On meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates NIS 2 compliance, because the directive addresses organisational measures rather than tools. NIS 2 asks for risk analysis and security policies, incident handling, business continuity, supply chain security, and the use of cryptography where appropriate. This add-on contributes to two of those categories: it handles incidents on the email vector by filtering, quarantining and retracting messages, and it supports supply chain security by authenticating mail that arrives from suppliers and partners. It contributes nothing to business continuity, nothing to cryptography beyond transport encryption, and nothing to the governance, training and documentation obligations that account for most of the workload. Treat it as one measure inside a wider programme, not as an answer to the directive.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Security for Email Add-On help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for the email section of a questionnaire, and only that section. It answers items on inbound malware and phishing filtering, sender authentication with SPF and DMARC, quarantine handling and who may release a message, outbound scanning, separation of administrator roles, and audit logging of console actions — all of which can be exported as a report rather than written by hand. It does not answer items on endpoint protection, vulnerability and patch management, device encryption, mailbox retention periods, or security awareness training, and a questionnaire will usually ask about all of those. Where several items are open at once, moving up to a higher GravityZone tier that already contains patch management and encryption is normally cheaper and easier to evidence than adding a second vendor, because every report then comes from one console with one set of timestamps.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between GravityZone Security for Email and GravityZone Extended Email Security?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is where the product inspects mail. The retired Security for Email platform filtered only at the gateway, so a message that got past the filter was beyond its reach the moment it landed in a mailbox. Extended Email Security keeps the gateway and adds an API connection to Microsoft 365 that continues scanning after delivery and can pull a message back out of every mailbox that received it. The second difference is simply availability, since the legacy platform was shut down on 31 January 2026.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Security for Email</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Extended Email Security</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Gateway filtering via MX record</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Post-delivery mailbox scanning</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Retraction of a delivered message</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Rollout without changing mail flow</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Microsoft 365</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Platform status</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Retired</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Current</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Post-delivery detection and message retraction depend on the API integration with Microsoft 365, so an organisation running a different mail platform gets gateway filtering only and loses the ability to pull a delivered message back. The gateway path still requires MX record and smart host changes, which means a planned maintenance window and DNS propagation rather than a switch you flip in the morning. The add-on filters mail but does not archive or back it up, so it cannot satisfy a retention requirement and cannot restore a mailbox after a deletion. It is an add-on and requires a GravityZone base product such as Business Security, Business Security Premium, Business Security Enterprise, EDR Cloud or an MDR licence, so on its own it protects nothing on your endpoints.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="office-2024-backup-business-pst-windows"><strong>Planning Office 2024 Backups for Businesses the Right Way</strong><br />Covers how to back up Outlook PST files, templates and the Windows system so that mail data survives a deletion or an outage.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Bitdefender GravityZone Security for Email Add-On</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it run alongside an email gateway that is already in place?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The API-based protection connects directly to Microsoft 365 and can be enabled within minutes even when another secure email gateway is already filtering inbound mail, because it works after delivery rather than in the mail path. This makes it possible to evaluate detection quality in a live environment without touching MX records first.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it replace the filtering built into Microsoft 365?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">It layers on top of it rather than replacing it. The add-on applies its own filter set to every message and adds impersonation detection based on a synchronised user population, which is the class of attack that gets through when a message carries no attachment and no malicious link.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-email,sec-console,compliance-supplier" data-audience="b2b" data-count="3"> </div>