Cisco Secure Email Gateway is an email security platform for cloud, on-premises virtual-machine, and hybrid deployments. It protects inbound and outbound messaging against business email compromise, ransomware, advanced malware, phishing, spam, and data loss. Cisco Secure Email and Web Manager provides centralized reporting, message tracking, quarantine administration, and configuration management across multiple gateways.

Product role and deployment architecture

The platform operates at the email gateway layer and applies multiple inspection stages before messages reach internal mail systems or external recipients. The security controls include reputation filtering, antispam, antivirus, malware analysis, URL inspection, attachment handling, outbreak filtering, data loss prevention, and encryption.

Licensing is user-based rather than device-based. A licensed user can receive both inbound and outbound gateway protection without a separate license for each traffic direction.

Three deployment models are available:

Deployment model Operating model Best For
Cloud Cisco-hosted email security service Organizations using Microsoft 365, Google Workspace, or other hosted email platforms that want no local email security infrastructure
On-premises Virtual appliances deployed in an organization-controlled environment Organizations retaining on-premises mail infrastructure, such as Microsoft Exchange, or requiring local control of email processing
Hybrid Combination of Cisco-hosted and virtual-machine deployments Phased cloud migration, split inbound and outbound controls, or environments requiring different control locations for different traffic types

The cloud service uses dedicated customer instances, high availability, disaster recovery, and a stated service-level target of 99.999 percent. Software, computing resources, and support are bundled with the cloud service. The cloud deployment is sized automatically according to the purchased user license.

The virtual appliance model permits deployment on existing infrastructure. Supported platforms identified in the datasheet include VMware ESXi, Microsoft Hyper-V, Red Hat Virtualization, Amazon Web Services, and Microsoft Azure. The virtual appliance license is unlimited when purchased with an applicable Cisco Secure Email software core bundle.

Threat prevention and inspection controls

Talos intelligence and reputation filtering

Cisco Secure Email uses Talos threat intelligence to analyze global traffic activity, identify anomalies, monitor threat trends, and generate rules for customer protection. The datasheet states that threat intelligence updates occur every three to five minutes.

Reputation filtering evaluates IP addresses, domains, and websites. Known-bad sources can be blocked before full message processing, reducing the amount of content that must be analyzed and helping the gateway scale more efficiently.

External threat intelligence can also be integrated through STIX over TAXII. This permits the gateway to consume additional threat feeds alongside Talos intelligence.

Antispam and antivirus

The antispam engine evaluates the complete context of a message. Inspection includes message content, message construction, sender identity, and the destination associated with a call to action. The datasheet identifies a spam catch rate greater than 99 percent and a false-positive rate of less than one in one million.

Virus defense is integrated into the gateway and uses a multilayered, multivendor filtering approach. The Essentials software bundle includes Sophos antivirus. McAfee antivirus is available as a separate add-on.

Intelligent Multi-Scan is an optional multilayer antispam capability. It combines multiple antispam engines, including Cisco Anti-Spam, to increase spam catch rates.

Malware Defense and sandboxing

Malware Defense protects against malicious email attachments. The processing sequence includes:

  1. File reputation checking using SHA256 lookups.
  2. Sandboxing for new or suspicious files.
  3. Behavioral analysis of submitted files.
  4. Retrospection alerts when the disposition of a file changes after new intelligence becomes available.
  5. Mailbox remediation where supported Microsoft 365 and Microsoft on-premises Exchange integrations are used.

Password Protected File Analysis can inspect password-protected files by extracting a password from the email body or testing passwords supplied by an administrator.

The Essentials bundle includes Malware Defense with sandboxing through the Malware Analytics solution, formerly known as Threat Grid. Essentials has a limitation on the number of files that can be sandboxed per day. Advantage removes the file submission limitation.

Organizations requiring a fully local malware analytics deployment can purchase an additional license for Cisco Secure Endpoint Private Cloud and use the Cisco Secure Malware Analytics appliance.

Mailbox Auto-Remediation can remove infected messages from supported user mailboxes and prevent users from accessing malicious attachments. The same remediation approach can be used for messages affected by URL retrospection alerts.

URL protection

URL filtering scans links contained in messages and attachments. Policies can be applied according to URL reputation or category. The gateway supports:

  • Short URL analysis.
  • Open redirect URL analysis.
  • URL rewriting.
  • Click-time protection.
  • Retrospection alerts.
  • Mailbox Auto-Remediation for supported Microsoft 365 and Microsoft on-premises Exchange environments.

URL rewriting provides protection when a link appears benign during the initial scan but becomes malicious later. When a rewritten link is clicked, the user can be routed through the Cisco Security proxy. The proxy can display a block page for a malicious site or show a screenshot for a suspicious site. Users may choose to continue to the destination when permitted by policy.

Outbreak filters

Outbreak filters address emerging phishing, scam, and virus campaigns. Talos maintains the outbreak ruleset and distributes protective rules to provide early detection of newly emerging campaigns.

Outbreak filters can rewrite URLs in suspicious messages. The resulting proxy-based inspection occurs when the recipient clicks the link, allowing the destination to be evaluated at click time rather than relying only on the original message scan.

Attachment and macro controls

File handling policies can restrict unwanted attachment types and content. File metadata analysis identifies the actual file type and can detect embedded Microsoft, Adobe, and OLE macro scripts.

Safe Print can convert an attachment into a PDF containing the original content as a screenshot. This provides a way to deliver visual content without passing the original active attachment to the recipient.

Graymail and safe unsubscribe

Graymail detection classifies marketing, social-networking, and bulk messages. Administrators can monitor these categories and apply separate policies.

Safe unsubscribe protects users from malicious links that imitate legitimate unsubscribe mechanisms. It provides a controlled unsubscribe interface and visibility into subscription activity. The capability is included in the Advantage bundle and is also available as a Graymail Safe-unsubscribe add-on.

Web interaction tracking

Web interaction tracking records activity associated with rewritten URLs. Reports can identify:

  • Users who clicked malicious URLs.
  • Malicious URLs clicked by users.
  • The time of the interaction.
  • The reason the URL was rewritten.
  • The action taken by the system.

This information supports incident investigation, user coaching, and policy tuning.

Outbound data protection

Cisco Secure Email provides DLP and email encryption for outbound messages.

The DLP capability includes nearly 200 predefined policy templates covering government, private-sector, and company-specific regulatory requirements. Administrators can use the predefined policies directly or use their components to create custom policies.

Available remediation actions include:

  • Encrypting the message.
  • Adding footers or disclaimers.
  • Adding blind carbon copies.
  • Notifying administrators or users.
  • Quarantining the message.

Envelope encryption permits the sender to retain control over protected content after sending. The sender receives a read receipt after the recipient opens the message, and replies and forwards remain encrypted. The message content is delivered directly from the gateway to the recipient, while the encryption key is stored in the cloud.

DLP is included in Advantage and Premier. Encryption is available through the applicable bundle or as a standalone add-on.

Threat Defense integration

Threat Defense Connector integrates the gateway with Cisco Secure Email Threat Defense. The additional service uses AI and machine-learning scanning engines to detect malicious messages that may bypass gateway inspection.

Secure Email Threat Defense is included in the Premier bundle and is also available as an add-on. The datasheet identifies internal traffic visibility and protection for Microsoft 365 environments as an applicable use case.

Centralized administration and quarantine

Cisco Secure Email and Web Manager centralizes operational data from multiple Cisco Secure Email Gateways. It provides:

  • Centralized reporting.
  • Message tracking.
  • Sender, recipient, subject, and message-attribute searches.
  • Detailed scan results.
  • Policy-action visibility.
  • Central spam quarantine.
  • Central policy quarantine.
  • Unified administration across multiple gateways.

The management architecture can centralize configuration for clustering of up to 20 gateways. Reporting, message tracking, and quarantine can aggregate information from up to 40 gateways.

Spam quarantine provides a shared self-service location for users and administrators. Policy quarantine provides a controlled repository for suspicious or policy-violating messages, allowing administrators to inspect and action messages from the dashboard.

For on-premises gateway bundles, the Security Management Appliance add-on provides centralized reporting and message searches across multiple gateways. For cloud gateway bundles, Cisco Secure Cloud Email Manager is included.

Software bundles and add-ons

Licenses are subscription-based and available in one-year, three-year, or five-year terms. Pricing is tiered by the number of mailboxes.

Bundle or add-on Included capability Best For
Essentials Antispam, Sophos antivirus, Malware Defense, Graymail detection, and outbreak filters; sandboxing has a daily file-submission limitation Organizations requiring core inbound email threat protection
Advantage All Essentials features plus DLP, Envelope Encryption, Safe Unsubscribe, and unlimited Malware Analytics file submission Organizations requiring outbound compliance controls and unrestricted malware analysis
Premier Advantage, Cisco Secure Email Threat Defense, and Cisco Secure Awareness Training Organizations requiring gateway protection, advanced internal email detection, and user awareness training
Security Management Appliance Centralized reporting and message search across multiple on-premises gateways Distributed on-premises deployments
Image Analyzer Detects illicit content in incoming and outgoing email Organizations requiring content monitoring and user education
Graymail Safe-unsubscribe Policy-controlled safe unsubscribe processing and monitoring Organizations needing controlled handling of bulk and marketing mail
Intelligent Multi-Scan Multiple antispam engines, including Cisco Anti-Spam Environments requiring additional antispam inspection
McAfee Antivirus McAfee antivirus scanning Organizations requiring an additional antivirus engine
Data Loss Prevention Detection of sensitive outbound data and severity-based actions Compliance, privacy, and confidential-data controls
Encryption Activation of Cisco Secure Email Encryption service End-to-end protection for sensitive messages
Secure Email Threat Defense AI and machine-learning detection with internal traffic visibility and protection Microsoft 365 and advanced-threat use cases

Virtual appliance sizing

The following values are the published virtual deployment requirements. They are not throughput figures. Capacity planning should account for message volume, attachment size, scanning features, retention, quarantine requirements, redundancy, and the number of protected users.

VMware ESXi, Microsoft Hyper-V, and KVM

The starred models are identified as available only for VMware ESXi.

Product Model Disk Memory Cores Best For
Cisco Secure Email Virtual Gateway C100v* 200 GB 8 GB 2 Smaller virtual gateway deployments
Cisco Secure Email Virtual Gateway C300v* 500 GB 16 GB 4 Medium gateway deployments requiring additional storage and processing
Cisco Secure Email Virtual Gateway C600v 500 GB 16 GB 8 Higher-processing virtual gateway deployments
Cisco Secure Email and Web Manager Virtual M100v* 250 GB 6 to 8 GB 2 Smaller centralized management deployments
Cisco Secure Email and Web Manager Virtual M300v* 1 TB 8 to 16 GB 4 Medium management and reporting environments
Cisco Secure Email and Web Manager Virtual M600v 2 TB 16 GB 8 Larger multi-gateway management and quarantine environments

Amazon Web Services

Product Model Disk vRAM vCPU EC2 instance type Best For
Cisco Secure Email Virtual Gateway C600v 500 GB 30 GB 16 c4.4xlarge AWS-hosted gateway deployment
Cisco Secure Email and Web Manager Virtual M600v 2 TB 15 GB 8 c4.2xlarge AWS-hosted centralized management

Microsoft Azure

Product Model Disk Memory vCPU Azure VM size Best For
Cisco Secure Email Virtual Gateway C600v 500 GB 32 GB 8 Standard D8s v3 Azure-hosted gateway deployment
Cisco Secure Email and Web Manager Virtual M600v 1 TB 32 GB 8 Standard D8s v3 Azure-hosted centralized management

The AWS and Azure tables publish only the C600v and M600v models. The on-premises hypervisor table lists additional C100v, C300v, M100v, and M300v choices.

Presales sizing and design rules

Use the following rules when developing a design:

  1. Size the cloud service by the number of licensed mailboxes. The cloud platform handles infrastructure allocation automatically.
  2. For virtual deployments, select the appliance class according to user count, message volume, attachment processing, malware sandboxing, quarantine retention, and reporting requirements.
  3. Do not use disk capacity as a direct throughput estimate. The datasheet specifies virtual resources but does not publish message-per-second, messages-per-hour, or megabytes-per-second performance figures.
  4. Include additional capacity for Malware Defense, URL retrospection, message tracking, quarantine retention, and centralized reporting.
  5. Use separate gateway instances or clusters where failure-domain separation is required.
  6. Use Cisco Secure Email and Web Manager when multiple gateways require consistent policy administration, consolidated reporting, or centralized quarantine.
  7. Select Advantage when DLP, encryption, safe unsubscribe, or unrestricted Malware Analytics submissions are required.
  8. Select Premier when internal email visibility, Threat Defense, and awareness training are part of the security requirement.
  9. Use hybrid deployment when inbound and outbound traffic require different processing locations or when cloud migration is being performed in phases.
  10. Validate the final virtual design with the Cisco sizing tool or a content security specialist before production deployment.

Environmental and physical considerations

The datasheet provides virtual infrastructure requirements but does not publish hardware-appliance environmental or physical specifications. The following items are therefore not specified:

  • Mean time between failures, or MTBF.
  • Operating temperature range.
  • Non-operating temperature range.
  • Relative humidity.
  • Operating altitude.
  • Acoustic noise.
  • Physical dimensions.
  • Physical weight.
  • Hardware power consumption.
  • Hardware power-supply configuration.

Because the documented deployment models are cloud services and virtual appliances, physical characteristics must be evaluated at the hosting-layer level. For on-premises deployments, the customer should assess the selected hypervisor host, storage subsystem, power design, cooling, rack environment, and virtualization cluster resilience. These values should not be inferred from the virtual appliance resource tables.

Warranty and service coverage

The datasheet describes software subscription support rather than a hardware warranty. All email security licenses include software subscription support for the purchased subscription term. The stated support entitlements include:

  • Software updates.
  • Major software upgrades.
  • Cisco Technical Assistance Center support.
  • Online tools for developing internal expertise.
  • Collaborative learning and training opportunities.

The datasheet does not specify hardware warranty duration, replacement-response targets, spare-parts coverage, or physical appliance service levels. Those items are not applicable to the documented cloud and virtual-machine deployment model unless separately provided under an infrastructure or service agreement.

Additional Cisco services include advisory services, implementation services, and technical services. Advisory services address risk, compliance, security, and threat-management alignment. Implementation services provide deployment expertise and recommended practices. Technical services cover proactive support for software, hardware, multivendor solutions, and network environments.

Evaluation and operational adoption

The virtual appliance can be evaluated through Cisco’s evaluation process. The cloud service can be evaluated through the Cisco account team or an authorized partner.

A practical presales evaluation should test:

  • Inbound spam and phishing detection.
  • Malware attachment handling and sandbox disposition.
  • URL rewriting and click-time inspection.
  • Retrospection and mailbox remediation.
  • DLP policy accuracy for outbound content.
  • Encryption workflows for external recipients.
  • Quarantine administration and user self-service.
  • Message tracking across multiple gateways.
  • Reporting detail and policy-action visibility.
  • Integration with Microsoft 365 or on-premises Exchange where applicable.
  • Administrative effort for cloud, on-premises, and hybrid operating models.

The final design should match the selected software bundle, mailbox count, deployment location, virtual resource requirements, mail-flow topology, quarantine strategy, and operational support model.