What are the essential features of Kaspersky Security for Mail Server?
Central management – Managed centrally per application, not one console.
Three applications – Gateway, Exchange and Microsoft 365 under one licence.
Phishing defence – Blocks spear phishing, BEC and QR code lures.
Sender authentication – SPF, DKIM and DMARC with domain alignment checks.
Plus tier – Adds content disarm and encrypted archive scanning.
Important note – No endpoint or workstation protection is included.
Download: Kaspersky Security for Mail Server
Kaspersky Secure Mail Gateway – Ready-to-use appliance with its own mail transfer agent.
Security for Exchange Servers – Protects Microsoft Exchange traffic at gateway and mailbox level.
Security for Microsoft 365 – SaaS cover for Exchange Online, OneDrive, SharePoint and Teams.
Sender authentication – SPF, DKIM, DMARC and domain sender alignment verdicts.
KSMS Plus tier – Adds content disarm, encrypted archive scanning and sandboxing.
Important – No single console covers all three applications together.
Kaspersky Security for Mail Server is a mail-layer security product that bundles three applications under a single licence, covering an on-premises gateway, Microsoft Exchange and Microsoft 365. The on-premises applications report into Kaspersky Security Center while the Microsoft 365 application is managed from Kaspersky Business Hub, and the gateway itself grew out of Kaspersky Security 8 for Linux Mail Server, a name many buyers still search for.
One licence – Run one application or all three together.
Gateway and mailbox – Stops mail before delivery and inside the mailbox.
AI phishing heuristics – Flags LLM-written mail carrying no link or attachment.
Encrypted archive scanning – Users submit archive passwords via a dedicated web portal.
SIEM export – Mail events exported in CEF for SIEM correlation.
KATA sandbox link – Attachments detonate and verdicts appear in KATA alerts.
The deciding factor is not headcount but whether you operate your own mail infrastructure. A company whose mail runs entirely in Microsoft 365 needs only the SaaS application; a company running Exchange on-premises or a gateway in front of it is the intended case for the full licence.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Own Exchange or mail gateway to protect | Sometimes | ✓ | ✓ |
| This product fits | Cloud app only | ✓ | ✓ |
The Swiss reporting obligation applies to operators of critical infrastructure named in the revised Information Security Act, not to every company, so most SMEs are not affected by it at all. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. On the mail layer the product supports that deadline in a practical way: the gateway and Exchange applications record a verdict per message, hold blocked mail in Backup and export events in CEF, so an administrator can reconstruct when a malicious message arrived and which mailboxes received it without reading raw mail logs by hand. What it does not do is detect an incident that started anywhere else, because it has no endpoint, server or network telemetry, so a compromise via stolen credentials or a removable device leaves no trace in its logs. It also produces no report in the form BACS expects, and the notification itself remains a manual task for your own staff. This is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product creates NIS 2 compliance, because the directive addresses organisations and their management bodies rather than the software they buy. NIS 2 requires measure categories including risk analysis and information security policies, incident handling, business continuity and crisis management, supply chain security, and policies on the use of cryptography. Kaspersky Security for Mail Server contributes to incident handling and to the technical protection of one communication channel: filtering, quarantine with a user-level release portal, sender authentication through SPF, DKIM and DMARC, and event export to a SIEM. It contributes nothing to business continuity, backup, access control, vulnerability handling or supplier assessment, and nothing to the governance and staff training duties the directive places on management. Treat it as one documented technical control among many, not as evidence that the measure catalogue has been met.
In March 2022 the German Federal Office for Information Security (BSI) issued a public warning against the use of Kaspersky antivirus software and recommended replacing it with alternative products. The warning remains in force in 2026 and is now regulated under Section 13 of the amended BSI Act, which took effect on 6 December 2025. Separately, the US Department of Commerce prohibited new sales and product updates in the United States from 2024. Kaspersky rejects the German warning as politically rather than technically founded, has publicly asked the BSI to withdraw it and has reserved the right to take legal steps. Independent evaluation of the mail product itself continues: Kaspersky was named a Leader in the SPARK Matrix Enterprise Email Security report 2025 by Quadrant Knowledge Solutions. In Switzerland the position is different again, because BACS does not issue recommendations on individual products, states that no misuse of Kaspersky software has been reported to it, and has imposed no ban; Kaspersky also operates a data centre and a transparency centre in the Zurich area. In practice this matters most if you sell into the public sector, work as a supplier to German authorities or critical infrastructure operators, or answer supply chain questionnaires that ask about vendor country of origin, since a listed vendor can cost you the contract regardless of test results.
Partly, and only for the email section. It answers questions on inbound and outbound mail filtering, anti-phishing and anti-spam controls, malicious attachment and link handling, quarantine and release workflow, sender authentication policy through SPF, DKIM and DMARC, audit logging, and forwarding of security events to a SIEM. It answers nothing on endpoint protection, EDR, patch status, disk encryption, multi-factor authentication, backup and restore testing, mobile device management or security awareness training, and it produces no asset inventory. Those are usually the items that decide whether a questionnaire is accepted, so the mail product alone will not clear one. Where the gap is on the mail side, moving from KSMS to KSMS Plus is the cheaper route; where the gap is endpoint or EDR, staying inside the same vendor family with a Kaspersky Next tier keeps one console and one support contract instead of splitting the estate across two vendors.
The single decisive difference is attachment handling. Base KSMS blocks or delivers an attachment, while KSMS Plus can strip the dangerous elements out of it through content disarm and reconstruction and deliver a safe version instead, and it can open password-protected archives whose password is not in the same message by having the recipient enter it on a dedicated portal. KSMS Plus also adds the heuristics for AI-generated mail and for list-linking, also known as mail bombing. Everything a standard mail filter is expected to do is already in the base tier, so the upgrade is a question of whether targeted attachment-based attacks are part of your threat picture.
| Capability | KSMS | KSMS Plus |
|---|---|---|
| Anti-spam, anti-phishing, anti-malware | ✓ | ✓ |
| Sender authentication (SPF, DKIM, DMARC) | ✓ | ✓ |
| QR code phishing detection | ✓ | ✓ |
| Content disarm and reconstruction | ✕ | ✓ |
| Password-protected archive scanning | ✕ | ✓ |
| AI-generated email heuristics | ✕ | ✓ |
| List-linking (mail bombing) detection | ✕ | ✓ |
Availability is regionally restricted: since the 2024 US Department of Commerce rule, Kaspersky products cannot be newly sold or updated in the United States, which matters if your group has US entities or your mail infrastructure is administered from there. The product covers the email layer only, so workstations, file servers, mobile devices and the endpoints that actually open the delivered mail all still need their own protection. Management is not unified either: the gateway runs from its own web interface and can report into Kaspersky Security Center, while the Microsoft 365 application is administered separately from Kaspersky Business Hub. The Exchange application additionally depends on a Microsoft SQL Server instance being available, which is the most common unbudgeted item when a first deployment is planned. Finally, the base tier stops at blocking attachments rather than sanitising them, and that is the usual reason for a later move to KSMS Plus.
Yes, on the gateway side. Kaspersky Secure Mail Gateway can integrate with Kaspersky Private Security Network and use the reputation databases locally, so no data leaves the organisation, and it can also be deployed in a certified mode in which the appliance is not permitted to reach servers outside your own infrastructure.
The current official application list names three applications: the secure mail gateway, the Microsoft Exchange application and the Microsoft 365 application. Older retail listings for this product also mentioned Lotus Notes and Domino, Sendmail, Qmail, Postfix and Exim, so check the current application list against your own platform before ordering rather than relying on an archived description.
| Operating Systems | Windows Server 2019: Standard / Datacenter Desktop Experience / Core Windows Server 2016: Standard / Datacenter Windows Server 2012 R2: Standard / Datacenter |
| Mail Server | Microsoft Exchange Server 2019 Mailbox / Edge Transport / Microsoft Exchange Server 2016 Mailbox / Edge Transport / Microsoft Exchange Server 2013 SP1 Mailbox / Hub Transport / Client Access Server |
| Security Server Processor | According to hardware requirements for the protected Microsoft Exchange server |
| Security Server Memory RAM | At least 2 GB free RAM |
| Security Server Storage | 6 GB available disk space |
| Framework | Microsoft .NET Framework 4.5 |
| Database | Microsoft SQL Server 2019 Express / Standard / Enterprise / Microsoft SQL Server 2017 Express / Standard / Enterprise / Microsoft SQL Server 2016 Express / Standard / Enterprise / Microsoft SQL Server 2014 Express / Standard / Enterprise / Microsoft SQL Server 2012 Express / Standard / Enterprise |
| Management Console Operating Systems | Windows Server 2019 Standard / Datacenter Desktop Experience / Core / Windows Server 2016 Standard / Datacenter / Windows Server 2012 R2 Standard / Datacenter / Windows 10 / Windows 8.1 / Windows 8 / Windows 7 SP1 Professional / Enterprise / Ultimate |
| Management Console Processor | Intel Pentium 400 MHz or faster / 1000 MHz recommended |
| Management Console Memory RAM | 256 MB free RAM |
| Management Console Storage | 500 MB available disk space |
| Management Console Software | Microsoft Management Console 3.0 / Microsoft .NET Framework 4.5 |
| Security Center Versions | Kaspersky Security Center 13 / 12.2 / 12.1 / 12 / 11 / 10 Service Pack 3 / 10 Service Pack 2 Patch a / 10 Service Pack 2 Maintenance Release 1 |