GravityZone add-on

Bitdefender GravityZone Extended Email Security

Stop phishing, business email compromise and ransomware before they turn into breaches. A secure email gateway at the perimeter and API-based protection inside the mailbox, both managed from the GravityZone console your team already uses.

At a glance

Product type
GravityZone add-on
Deployment
Gateway, API, or both
Requires
A GravityZone base licence
Console
GravityZone cloud
  • 250+

    Filters on every message

    inbound and outbound, before and after delivery

  • Minutes

    To first protected mailbox

    over the API, with no MX record change

0%Report more BEC attacksof security leaders, over the past year (Bitdefender Cybersecurity Assessment Report 2025)
0+Filters on every emailapplied to every single message the service processes, inbound and outbound
0,000+Behavioural algorithmsreading over 130 variables in each message before it is let through
0New threats a minutediscovered by Bitdefender Labs across the global protective network

Capabilities

Modern email security, built to stop today's attacks

Gateway filtering alone is no longer enough. Protection extends into the mailbox, so threats that evade the first filter are still found and removed.

Extended Email Security dashboard charting spam and policy detections over time, with counts trending up

Real-time visibility into email risk

One view of what is arriving, what was blocked and what is still sitting in mailboxes, across every user and domain. Post-delivery monitoring keeps that picture current, so investigation and containment start early and dwell time stays short.

Message analysis panel showing an impersonation verdict with SPF, DKIM and DMARC results and a spam score

Email authentication

Built-in support for SPF, DKIM and DMARC enforcement. These are the protocols that stop someone sending mail that claims to come from your domain, and they protect the sending reputation you have built up. Each verdict is recorded against the message so a decision can be explained later.

Message detail view listing sender, source IP, country, size and the delivery response from the receiving server

Message tracing and mail flow control

Every message carries its full record: sender, source IP, country, size, queue and the delivery response from the receiving server. That is what turns "did this email arrive?" into an answer rather than an investigation, and it is the same detail the policy engine filters on.

Outbound status settings with the outbound sources list of public IP addresses the organisation sends email from

Outbound email scanning

Every outgoing message is inspected for malware, spam and the signs of a compromised account before it leaves your network. That is what keeps your domain off blocklists and your sender reputation intact.

Multi-layered protection and scanning

  • Business Email Compromise and impersonation protection catch the social engineering, phishing and impersonation attempts that get past a traditional spam filter.
  • Zero-day and advanced threat protection, sandboxing and AI-powered analysis handle both known and unknown email threats.
  • Signature-based engines run alongside behavioural detection, which defeats new malware packing techniques automatically.

Graymail filtering

  • Newsletters, bulk marketing and other harmless but distracting mail are separated out before they reach the inbox.
  • Staff keep their attention on real business correspondence.
  • The security team stops fielding complaints about inbox clutter.

End-user quarantine digest

  • Users get an on-demand digest of their own quarantined mail and can release a message themselves.
  • Administrators stay in control through policy-based permissions that decide who may release what.
  • Fewer release requests reach the IT queue, which is where most of the day-to-day email workload comes from.

Seamless integration with Microsoft 365

  • Native, API-based access gives full visibility and control across user mailboxes.
  • Automated directory synchronisation through Entra ID keeps provisioning aligned with your organisation as it changes.
  • No mail flow changes are required, and remediation can retract a malicious message across the whole organisation at once.

Flexible deployment

Three ways to put it in front of your mail

Built for modern environments, with a dual-layered architecture: filter at the perimeter with a secure email gateway, protect inside the mailbox over the API, or run both. Deployment and visibility work the same across email systems, so the choice follows the customer's setup rather than ours.

These are the service names the console reports against each message, so what you pick here is what you will see in a message trace later.

Blue hexagon mark for the MX-based Mesh Gateway deployment

Mesh Gateway

MX based

Teal cube mark for the API-based Mesh 365 deployment

Mesh 365

API based

Pink hexagon mark for the Mesh Unified deployment covering both layers

Mesh Unified

MX and API based

Recommended

Deployment

Protect the perimeter, the mailbox, or both

What each route actually involves, start to finish. You can change your mind later without reinstalling anything.

Fastest to deploy

API-based, inside the mailbox

Integrated Cloud Email Security. Connects to Microsoft 365 through the API and monitors mail after delivery.

  1. 1Authorise the connection to your Microsoft 365 tenant.
  2. 2Let directory synchronisation through Entra ID pull in users and domains.
  3. 3Set policy, then let post-delivery monitoring detect and retract threats that got through.
No MX record change. Runs alongside an existing gateway, including one from another vendor.

Secure email gateway, at the perimeter

MX-based filtering that stops threats before they are ever delivered. Works with any email provider, cloud or on-premise.

  1. 1Change your MX record so inbound mail routes through the Cloud Email Security servers.
  2. 2Configure a smart host so outbound mail routes back out the same way.
  3. 3Set the policy engine on mail flow, then review what the filters are catching.
The classic gateway deployment, and the one to choose when the mail platform is not Microsoft 365.
Recommended

Both layers together

Pre-delivery filtering and post-delivery detection covering the full attack lifecycle.

  1. 1Deploy the gateway so the bulk of the volume never reaches a mailbox.
  2. 2Add API protection so anything that evades the filter is still found in the inbox.
  3. 3Apply stronger controls where exposure is highest, by domain, department or individual.
Closes the post-delivery gap that gateway-only filtering leaves open.

In detail

Everything the service does

The full capability list, including the controls that decide whether it is workable day to day.

19 capabilities

Everything the service does
CapabilityWhat it does
1Threat detection6 capabilitiesWhat it finds, and how.
Catches fraud that carries no malware at all.
Stops what has never been seen before.
Signature and behaviour together.
Over 10,000 algorithms per message.
Re-checks the link when the user clicks it.
Catches the compromised account.
2Mail flow and policy5 capabilitiesControl over what moves, and where.
Filter on the attributes you choose.
Stronger rules where the risk is.
Several providers, one domain.
Inspects what you send.
Remove a message from every inbox.
3Data protection and compliance4 capabilitiesEvidence, encryption and the audit trail.
Keeps confidential content in.
Encrypted server to server.
Mail flow, rules and actions.
Archived automatically after 90 days.
4Administration4 capabilitiesWhat running it actually costs you in time.
Users release their own mail.
Provisioning stays current.
Several organisations, one console.
Email telemetry feeds the platform.

Why choose GravityZone Extended Email Security

Protection at both layers

Perimeter filtering and mailbox-level defence in one product, covering cloud, hybrid and on-premise mail. Pre-delivery and post-delivery, against phishing, ransomware, BEC and insider threats.

Cloud-ready and API-based

The API-driven architecture means provisioning and testing take minutes rather than a change window, which suits hybrid and cloud-first environments and scales as the business grows.

An interface people learn quickly

A modern design with quick configuration and short workflows for both administrators and end users, so adoption does not depend on a training programme.

One platform, not another silo

Because it sits inside GravityZone, email protection, endpoint defence, compliance and risk management share one console. Fewer tools, faster investigations and a lower total cost of ownership.

For managed service providers

Built for running email security across many customers

Designed with input from more than 200 MSPs. Pick a capability to see what it changes in day-to-day operations.

True multi-tenancy and global rules

Manage every client from one place

A fast interface built from the ground up for MSP workflows, so onboarding a new customer is a short task rather than a project.

Global rules and policies
Apply one policy across every tenant instead of repeating the same configuration per customer.
Cross-tenant email search
Search for a message across all client tenants at once when an incident spans several of them.

Requirements

What it needs, and what it works with

Extended Email Security is an add-on. It attaches to a GravityZone licence you already hold, or to a new one bought alongside it.

Base licence, one of

GravityZone Business Security

Business Security Premium

Business Security Enterprise

GravityZone EDR Cloud

Bitdefender MDR

GravityZone Cloud MSP Security

Email environments

Microsoft 365

On-premise

Hybrid

Any third-party provider

Deployment

MX record change for the gateway

API for mailbox protection

Smart host for outbound

Both layers together

Minutes

API deployment needs no MX record change and no mail flow rework.

No appliances

Cloud native, so there is no hardware to size and nothing to patch.

Entra ID sync

Mailbox inventory stays aligned with your directory automatically.

Related products

The rest of the GravityZone range

Extended Email Security is an add-on and attaches to any of these base licences.

Questions people actually ask

Put it in front of your own mail

We will set up a trial against a real mailbox, or quote the add-on against the licence you already hold.