What are the essential features of Kaspersky Security for Mail Server Add-On?
Central management – Web console per application, plus Kaspersky Security Center.
Add-on licence – Requires an existing Kaspersky business licence.
Three applications – Gateway, Exchange and Microsoft 365 covered.
Sender authentication – SPF, DKIM and DMARC stop spoofed senders.
Phishing defence – Blocks QR code and spear phishing attempts.
Important note – Protects email only, no endpoint or EDR.
Kaspersky Secure Mail Gateway – Ready-built SEG appliance with mail transfer agent included.
Kaspersky Security for Exchange – Scans Microsoft Exchange traffic at gateway and mailbox level.
Kaspersky Security for M365 – API-based protection for Exchange Online, SharePoint, OneDrive, Teams.
Sender authentication – SPF, DKIM, DMARC and domain sender alignment checks.
Quarantine and reporting – Role-based access, CEF syslog export to your SIEM.
Important – No endpoint, EDR, encryption or patch management is included.
Kaspersky Security for Mail Server is an email security product that adds gateway-level and mailbox-level scanning, and the Add-On licence variant is sold for organisations that already run a Kaspersky business product. Each of the three applications is configured in its own web console with Kaspersky Security Center used for central status monitoring, and the Microsoft 365 application was previously sold under the name Kaspersky Security for Microsoft Office 365.
Blocking before the mailbox – Malicious mail is stopped at the gateway, not afterwards.
Fewer manual spam checks – ML-based quarantining cuts the daily allowlist and release workload.
Cross-product visibility – Sends detections to Kaspersky SIEM and Next XDR Expert.
One licence, three apps – Gateway, Exchange and Microsoft 365 without separate purchases.
Cluster scaling – Gateway nodes scale horizontally under one web console.
Active Directory integration – Policies and role-based access follow existing domain groups.
The decisive question is not headcount but whether your organisation still receives mail through its own Exchange server, a mail gateway, or Microsoft 365 mailboxes you administer yourself. Companies that have already standardised on Kaspersky for endpoints are the natural buyers, because the Add-On licence attaches to that existing licence.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | Often |
| NIS 2 in the European Union | Rare | By sector | Usually |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Filtering before the mailbox | Optional | ✓ | ✓ |
| This product fits | With base licence | ✓ | ✓ |
The obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every company, and it requires a significant cyberattack to be reported to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Meeting a 24-hour deadline depends on noticing the incident in the first place, and here the product contributes two concrete things: message processing events are logged in CEF format and can be pushed to a SIEM via syslog, and detections can be forwarded to Kaspersky Anti Targeted Attack for correlation with endpoint and network events. What it does not do is produce the report itself, cover the attack paths outside email, or evidence the organisational measures the Act expects, such as a documented incident process and named responsibilities. If the initial intrusion arrives through a browser download, a VPN appliance or a stolen credential rather than through a mail attachment, this product will not see it at all. Whether your organisation is subject to the reporting obligation is a legal question, and this text is not legal advice.
No software product makes an organisation compliant with the NIS 2 Directive, because the Directive addresses management responsibility, risk analysis and process, not the purchase of tools. NIS 2 sets out categories of measure that in-scope entities must implement, including incident handling, business continuity, supply chain security, access control, cyber hygiene and awareness, and policies for assessing whether measures actually work. This product maps to a narrow slice of that: it provides detection and filtering for one attack vector, quarantine handling as part of incident response, role-based administrator access, and event export that feeds incident handling evidence. It does not cover business continuity or backup, supply chain risk assessment, vulnerability handling across your estate, staff awareness training, or the periodic effectiveness review the Directive expects. Buyers in scope of NIS 2 should treat email security as one control among many rather than as a compliance answer.
Germany's Federal Office for Information Security (BSI) issued a warning against the use of Kaspersky antivirus software on 15 March 2022 and recommends replacing applications from that portfolio with alternative products. The warning is still published and, since 6 December 2025, sits under Section 13 of the amended BSIG rather than the former Section 7. It is a recommendation, not a prohibition, and Kaspersky products remain legally available in Germany. Separately, the US Department of Commerce prohibited the sale of Kaspersky software in the United States from 20 July 2024 and the supply of updates from 29 September 2024; that measure remains in force. Kaspersky rejects the BSI assessment as unfounded, has publicly pressed for its withdrawal and reserves legal steps, and points to its European data processing in Switzerland, its transparency centres where source code can be inspected, and its continued participation in independent laboratory testing, where its products are regularly evaluated. In Switzerland the position is different again: BACS has issued no product warning against Kaspersky, states that no misuse of the software has been reported to it, and confirms there is no internal directive banning the products, while noting it would warn publicly if verified technical evidence emerged. Practically, this matters most to buyers who sell into the public sector, who operate US entities, or whose large customers impose country-of-origin conditions on security software in their supplier requirements; for a purely domestic Swiss company with no such clauses, it is a judgement call rather than a blocker.
Partially, and only for the email section. It answers questions on inbound and outbound mail filtering, malware and phishing scanning at gateway and mailbox level, sender authentication using SPF, DKIM and DMARC, quarantine handling and message release workflow, role-based administrator access, Active Directory-based policy assignment, and whether security events can be exported to a SIEM in a standard format. It does not answer the questions that usually follow: endpoint protection and EDR coverage, patch and vulnerability management, disk encryption on laptops, mobile device management, backup and recovery testing, multi-factor authentication, or documented staff security training. It also does not produce an audit-ready attestation on its own, since the reports it generates cover mail traffic rather than your control framework. To close those gaps, the cheaper route is normally to move up within the same vendor family, for example to a Kaspersky Next tier that adds endpoint, EDR and encryption management under one console, rather than bolting a second vendor's agent onto the same machines and then having to explain two management planes in the questionnaire.
The single most decisive difference is content disarm and reconstruction: KSMS Plus strips active content out of attachments and delivers a neutralised version, while KSMS relies on detection alone. Beyond that, KSMS Plus targets the evasion techniques that have grown fastest, namely password-protected archives, machine-generated phishing text and mail bombing through mass list subscription. Both tiers share the same anti-spam, anti-malware, anti-phishing and sender authentication engines, so KSMS is not a cut-down scanner but a narrower feature set. Organisations with a security team that already triages alerts tend to need the Plus tier; organisations that simply want less spam and fewer malicious attachments usually do not.
| Capability | KSMS | KSMS Plus |
|---|---|---|
| Anti-spam, anti-malware, anti-phishing | ✓ | ✓ |
| SPF, DKIM and DMARC authentication | ✓ | ✓ |
| QR code phishing detection | ✓ | ✓ |
| Content disarm and reconstruction | ✕ | ✓ |
| Password-protected archive scanning | ✕ | ✓ |
| AI-generated email detection | ✕ | ✓ |
| Mail bombing detection | ✕ | ✓ |
| Update and KSN availability in the USA | Restricted | Restricted |
The Add-On licence is not a standalone purchase: it attaches to an organisation that already runs a Kaspersky business product, and buyers starting from nothing need the base licence variant instead. There is a regional restriction that matters if you have a US entity, because Kaspersky's own documentation states that update functionality, including anti-virus signature and code base updates, as well as Kaspersky Security Network functionality, may not be available in the territory of the USA. The three applications are not administered from one single pane: the gateway and the Microsoft 365 application each have their own web console, and Kaspersky Security Center supplies central status monitoring rather than unified policy editing, which is a common source of follow-up questions during rollout. Coverage stops at email, so endpoint protection, EDR, disk encryption, patch management and mobile device security all require separate products, and the features most often assumed to be included, notably content disarm and reconstruction and password-protected archive scanning, sit in the KSMS Plus tier rather than the base tier. The product also does not archive or back up mail, so retention and recovery remain a separate purchase.
Yes. Kaspersky Secure Mail Gateway is configured entirely through its own web interface, including rules, domains, quarantine and reporting. Kaspersky Security Center is optional and is used to monitor product state centrally alongside other Kaspersky applications.
Yes. Kaspersky Secure Mail Gateway supports cluster deployment and scales horizontally or vertically, with all servers in the cluster managed centrally from the application web interface. It is delivered either as a virtual machine image with a pre-installed operating system and mail transfer agent, or as an RPM or DEB installation package.
| Operating Systems | Windows Server 2019: Standard / Datacenter Desktop Experience / Core Windows Server 2016: Standard / Datacenter Windows Server 2012 R2: Standard / Datacenter |
| Mail Server | Microsoft Exchange Server 2019: Mailbox / Edge Transport / Microsoft Exchange Server 2016: Mailbox / Edge Transport / Microsoft Exchange Server 2013 SP1: Mailbox / Hub Transport / Client Access Server |
| Processor | According to hardware requirements for the protected Microsoft Exchange server |
| Memory RAM | At least 2 GB free RAM |
| Storage | 6 GB available disk space |
| Framework | Microsoft .NET Framework 4.5 |
| Database | Microsoft SQL Server 2019: Express / Standard / Enterprise / Microsoft SQL Server 2017: Express / Standard / Enterprise / Microsoft SQL Server 2016: Express / Standard / Enterprise / Microsoft SQL Server 2014: Express / Standard / Enterprise / Microsoft SQL Server 2012: Express / Standard / Enterprise |
| Management Console Operating Systems | Windows Server 2019: Standard / Datacenter Desktop Experience / Core / Windows Server 2016: Standard / Datacenter / Windows Server 2012 R2: Standard / Datacenter / Windows 10 / Windows 8.1 / Windows 8 / Windows 7 SP1: Professional / Enterprise / Ultimate |
| Management Console Processor | Intel Pentium 400 MHz or faster / 1000 MHz recommended |
| Management Console Memory RAM | 256 MB free RAM |
| Management Console Storage | 500 MB available disk space |
| Management Console Software | Microsoft Management Console 3.0 / Microsoft .NET Framework 4.5 |
| Windows Update | Microsoft Windows update KB2999226 is required |
| Visual C++ Libraries | Microsoft Visual C++ Redistributable for Visual Studio must be installed with x64 and x86 libraries |
| Security Center Versions | Kaspersky Security Center 13 / 12.2 / 12.1 / 12 / 11 / 10 Service Pack 3 / 10 Service Pack 2 Patch a / 10 Service Pack 2 Maintenance Release 1 |