On-Premise Spam Filter: Stop Cloud-Scanning Your Mail

A comparison of on-premise spam filters and SMTP gateways—Hexamail Guard, SpamAssassin stacks, Exchange Online Protection, and cloud gateways—for teams that want filtering on their network.

Hexamail Editorial

The awkward problem cloud email security does not admit

Microsoft and Google will scan your mail in their cloud. Mimecast and Proofpoint will too, on the MX. That is fine until the requirement is no third party reads the message body, or Exchange is on-prem, or the internet link is not allowed to hairpin every message through a US SaaS.

An on-premise spam filter is an SMTP gateway (or a milter) you run. Hexamail Guard is one. This hub compares the category. Specific questions live next door: self-hosted, SMB, SMTP gateway, cloud vs on-prem.

Filtering on your network versus sending every message to a vendor

What the gateway must do

Sit in front of any SMTP server (Exchange, Hexamail Server, MDaemon, Postfix). Inspect inbound (and ideally outbound). Spam, phishing, malware, spoofing (SPF/DKIM), quarantine, admin/user release. TLS. Not a desktop Outlook plugin.

On-prem and hybrid options

Hexamail Guard

On-prem SMTP proxy: Bayesian and rules, DNSBL/RHSBL/SURBL, SPF and DKIM checks, greylisting, challenge-response, image analysis, Clam-style AV options, quarantine, automatic outbound allowlists, optional POP3/IMAP collection and scan. Works with Exchange and any SMTP server. Mail is not sent to Hexamail’s cloud for analysis.

That privacy line is the product. If you wanted Microsoft to handle spam, you would not be here.

In this cluster