On-Premise Spam Filter: Stop Cloud-Scanning Your Mail
A comparison of on-premise spam filters and SMTP gateways—Hexamail Guard, SpamAssassin stacks, Exchange Online Protection, and cloud gateways—for teams that want filtering on their network.
The awkward problem cloud email security does not admit
Microsoft and Google will scan your mail in their cloud. Mimecast and Proofpoint will too, on the MX. That is fine until the requirement is no third party reads the message body, or Exchange is on-prem, or the internet link is not allowed to hairpin every message through a US SaaS.
An on-premise spam filter is an SMTP gateway (or a milter) you run. Hexamail Guard is one. This hub compares the category. Specific questions live next door: self-hosted, SMB, SMTP gateway, cloud vs on-prem.
What the gateway must do
Sit in front of any SMTP server (Exchange, Hexamail Server, MDaemon, Postfix). Inspect inbound (and ideally outbound). Spam, phishing, malware, spoofing (SPF/DKIM), quarantine, admin/user release. TLS. Not a desktop Outlook plugin.
On-prem and hybrid options
Hexamail Guard
On-prem SMTP proxy: Bayesian and rules, DNSBL/RHSBL/SURBL, SPF and DKIM checks, greylisting, challenge-response, image analysis, Clam-style AV options, quarantine, automatic outbound allowlists, optional POP3/IMAP collection and scan. Works with Exchange and any SMTP server. Mail is not sent to Hexamail’s cloud for analysis.
That privacy line is the product. If you wanted Microsoft to handle spam, you would not be here.
In this cluster
- Replacing a Linux filter? Self-hosted spam filter.
- Ten to two hundred seats? Spam filter for small business.
- MX architecture? SMTP spam gateway.
- Arguing with a SaaS quote? Cloud vs on-premise email security.
app cta