Secure Email Gateway

更新时间:
复制 MD 格式

Overview

The Secure Email Gateway is an intelligent email security system powered by the Qwen large model. It uses machine learning, natural language processing, and behavioral analysis algorithms to identify and block spam, phishing emails, malicious attachments, and fraudulent content in real time. The system provides intelligent threat detection, comprehensive email auditing, and one-click recovery.

Note

This service must be purchased and activated separately. A 15-day free trial for up to 3 accounts is available.

Core capabilities

  • AI-Enhanced Scanning: Leverages an industry-leading large model to accurately identify highly disguised threats such as phishing emails, business email compromise (BEC), malicious attachments, and domain spoofing. This feature effectively counters new and evolving attacks.

  • Full Auditing and One-Click Recovery: All intercepted emails, whether blocked by AI or rule-based triggers, are retained for 30 days. You can search, release, or discard these emails to prevent the permanent loss of legitimate messages.

Important

After you purchase and configure the service, Mail Quarantine is upgraded to Secure Email Gateway.

Activate and configure

Administrators can activate the gateway and configure policies from the Alibaba Mail domain admin console.

Trial service

Click Free Trial to configure your trial accounts.

Select 3 of your most vulnerable core accounts for a 15-day trial of our advanced AI protection. We recommend choosing accounts for finance, executives, or publicly listed business emails. You can change the selected accounts during the trial period.

image

Click Confirm to Enable Protection.

image

Click Start Experience.

image

image

You can change the trial accounts at any time during the trial period.

image

View the protection report, which includes details on threats blocked by standard rules, additional threats found by AI, and the AI improvement rate.

image

Purchase service

Note
  • AI gateway licenses are available for on-demand purchase (currently in beta).

  • If you purchased Alibaba Mail from a reseller, contact the reseller to order and activate the gateway.

  • If you purchased your mailbox directly from the official website, follow the steps below to order and activate the gateway.

  • A license key can only activate an Alibaba Mail instance in the region where it was purchased. For example, a license key from the China (Hong Kong) region only works for an Alibaba Mail instance in that region.

  1. Visit the purchase page to place your order: Buy Now imageimage

  2. On the order details page, find your license key, for example, hz47xxxx2acfxxxxa7b53xxxx318xxxx68.

    image

Activate license

  1. Log on to the Alibaba Mail domain admin platform with the administrator account (postmaster).

    Standard edition

    https://qiye.aliyun.com/

    Domestic edition

    https://mail.xc.aliyun.com/

  2. Navigate to Advanced Apps > Mail Quarantine (this is upgraded to "Secure Email Gateway" after activation), and click "Learn More" in the notification message.

    imageTo upgrade to AI Secure Email Gateway, click the "Activate Now" button.image

  3. Enter the license key you obtained and click Next.image

  4. Click Confirm Activation. After activation, the system automatically starts real-time AI scanning and protection for all inbound and outbound emails of protected accounts.

    image

Secure Email Gateway (domain admin)

image

Gateway management console

Enter the gateway console to audit emails, configure policies, and manage quarantined items.

Feature switches

For more information about quarantine, see How to use Mail Quarantine as an administrator.

  • Quarantine Master Switch: Globally enables or disables the quarantine feature.

  • User Quarantine Access: Controls whether regular users can see the Mail Quarantine section in their mailbox.

AI-enhanced scanning

When enabled, the system uses the Qwen large model for intelligent threat identification. This feature is enabled by default.

Secure Email Gateway (console)

To access the console:

Method 1: From the Alibaba Mail domain admin console, navigate to Advanced Apps > Secure Email Gateway. Click Enter Email Gateway Management Console, then click Enter Secure Email Gateway in the upper-right corner of the page.

Method 2: Click the link to the Email Gateway Management Console, log on again with your administrator credentials, and then click Enter Secure Email Gateway in the upper-right corner of the page.

image

Smart protection logs

Note
  • Emails that match an allowlist or blocklist in Mail Quarantine bypass advanced AI scanning and are not sent to quarantine. Therefore, they do not generate Smart Protection Logs.

  • With AI scanning enabled, emails for standard accounts are sent to quarantine only if they trigger an anti-spam rule. However, all emails for Key Accounts, including internal messages, are sent to quarantine for deep AI scanning.

  • Methods to release emails:
    You can release emails by clicking Release, adding the sender to an allowlist, modifying existing rules, or creating a new custom release rule with a higher priority.

image

Search criteria

You can combine the following criteria to search for historical email processing records:

Search dimension

Options

Recipient / Sender

Search by full email address, prefix (the part before @), or domain name.

Email Subject

Keyword matching.

System verdict

Reject, Discard, Quarantine, Spam, Release, Scanning

Delivery status

Auto-Release, Auto-Intercept, Manual Release, Manual Discard

Threat type

Spam, Phishing, Malware & Virus, business email compromise (BEC)

Verdict source

AI-Enhanced Scanning, Standard Security Scanning, Custom Rules

Note

Custom rules currently operate as part of the anti-spam mechanism and are displayed as 'Standard Security Scanning' by default. The system only labels a verdict source as 'Custom Rules' when a message is caught by the 'Quarantine Blocklist'.

Time range

Custom range within the last 30 days.

Action buttons: Reset, Search, Refresh

View email details

Click View on any record to see the following:

  • Sender, recipient, subject, and time

  • Verdict source (for example, "AI-Enhanced Scanning")

  • Detailed reason (for example, "Detected a spoofed bank login link")

  • Email body (including original HTML content)

  • Attachment list (for example, "1.jpg")

image

Manual intervention

  • Release: Delivers a suspicious email to the recipient's inbox after an administrator confirms it is safe.

  • Discard: Permanently deletes a suspicious email after an administrator confirms it is malicious.

Quarantined emails

Quarantine authorization management

Rules

For more information, see How to use Mail Quarantine as an administrator.

Key Accounts

This feature provides enhanced security for key personnel such as executives, finance staff, and procurement officers. It intelligently monitors communications between Key Accounts and external organizations to accurately identify supply chain hijacking attacks and business email compromise (BEC). The AI-generated reputation scores and labels are based on probabilistic calculations from the large model, considering past communication behavior, semantic intent, and threat intelligence. This information provides advanced decision support. Administrators should make final judgments based on their business context.image

Key metrics overview

  • Number of Key Accounts: The total number of accounts currently under protection. The maximum number is 5% of your total licensed accounts, though this percentage may change with product policy updates. The display format is Current number / xx.

  • Total impersonation attacks blocked by AI: The total number of impersonation, phishing, and supply chain attack emails blocked for Key Accounts.

Field Descriptions

Parameter

Description

Account Name

The employee's display name in the address book.

Account Email

The protected corporate email address.

Department

The organizational department to which the account belongs.

Status

Under Secure Protection

Number of Protected Emails

The number of inbound and outbound emails scanned for this account since it was added to the Key Accounts list.

Number of Associated External Domains

The number of unique external domains this account has recently communicated with. A sudden spike may indicate a risk.

Last Communication Time

The timestamp of the last external email communication for this account.

Actions

• Details: View the details panel.
• Remove Protection: Remove this account from the Key Accounts list.

Key account detailsimage

Click Details in the list to display a deep security profile for the account, which includes the following modules:

AI Key Account Briefing
The AI engine is continuously monitoring inbound and outbound emails for this account. No new spoofing or hijacking attempts have been detected recently.

Review full communication log

  • Links to the Mail Log page.

Remove protection

Select Remove Protection from the action options.

This action frees up a Key Accounts slot. The account reverts to standard protection, and its protection records are deleted.

Use cases

  • Protecting key individuals: Add key personnel who are likely targets of attacks (such as CFO, CEO, HR Director) to the Key Accounts list to increase detection sensitivity.

  • Monitoring supply chain risks: Regularly review changes in the "Number of Associated External Domains" to quickly detect potential vendor email compromise.

  • Incident investigation and review: When a security alert is received, use the AI Key Account Briefing to verify the threat and Review full communication log to trace historical interactions. This process helps you determine the final response.

Mail Log

image

This feature allows you to quickly troubleshoot email delivery failures, trace the origin of emails, and verify the security verdict for specific messages.

Key Search Criteria

  • Time range: Supports custom start and end dates (for example, 2026-05-14 to 2026-05-15).

  • Search dimension: Supports matching by recipient, sender, subject, or IP address.

Field Descriptions

Parameter

Description

Verdict Source

Identifies the technology module that triggered the security verdict.
• Standard Security Scanning: Basic detection based on traditional signature libraries.
• AI-Enhanced Scanning: Deep behavioral analysis based on artificial intelligence models.
• Custom Rules: Specific filtering rules set by an administrator.


Delivery Status

Describes the final action taken on the email by the system.
• Auto-Release: The system determined the email was safe and delivered it.
• Auto-Intercept: The system determined a high risk and blocked the email.
• Manual Release/Discard: An administrator manually released or discarded the email.


System Verdict

The final disposition of the email after processing by the security engine.
• Release: Delivered to the user's inbox.
• Quarantine: Sent to the quarantine area, requiring user or administrator action.
• Discard: The email was deleted.


Operation Log

image

Records all key configuration changes and administrative actions that administrators or users perform in the mail backend. This feature provides a complete audit trail for security and accountability.

Key Search Criteria

  • Operator: The account that performed the action.

  • Time range: Supports querying over a custom time period.

Field Descriptions

Parameter

Description

Action

The specific administrative action or API call that was executed.
• Allowlist/blocklist management: Such as "Delete from organization quarantine allowlist".
• Gateway policy adjustment: Such as creating or modifying a "Gateway custom rule".
• Manual intervention: Such as "Release gateway email" or "Discard gateway email".
• System command: Such as QUARANTINERULE_CREATED (create quarantine rule).



Source

The entry point or module where the action occurred.
• Quarantine: Actions such as releasing or deleting from quarantine.

Result

• Success: The action was applied successfully.
• Failure: The action was not executed, often with a corresponding error reason.

Analytics

imageimage

The Analytics panel displays charts and graphs of your email system's health, traffic trends, and the distribution of security threats. You can view data for "Today", "Last 7 Days", "Last 30 Days", or a custom time range.

Key Metrics Explained

  • Mail Flow Overview:

    • Total Received Emails: The total volume of emails received during the specified period.

    • Normally Released Emails: The number of emails that passed security checks and were delivered to inboxes.

    • Intercepted Threats: A breakdown of emails that were "Rejected", "Quarantined", or "Marked".

  • Global Traffic Trends: A chart showing fluctuations in email traffic to help identify sudden traffic spikes.

  • Security Defense Insights:

    • Interception Source: Analyzes whether interceptions were triggered by "Standard Security Scanning", "AI-Enhanced Scanning", or "Custom Rules" to evaluate the effectiveness of each security layer.

    • Threat Type Distribution: Provides a detailed breakdown of intercepted email types, including spam, phishing emails, malware/viruses, and business email compromise (BEC), to help you understand your primary security risks.

Use Cases

  • Periodically assess the security effectiveness of your corporate email system.

  • Adjust anti-spam policies or enhance employee security awareness training based on the threat type distribution (for example, in response to a high volume of phishing emails).

Notifications and renewals

Notifications

Expiration reminders

After the Secure Email Gateway is activated, the service will run until the end of its subscription period. Before expiration, the system will send reminders through various channels.

Reminder Rules:

  • T-30 days (Friendly Reminder): Reminds administrators to begin the renewal process.

  • T-7/T-3/T-1 days (Urgent Alert): Emphasizes that the service is about to expire and highlights the risks.

  • T-0 day (Expiration Notice): Informs that the service has been terminated.

Friendly reminder to administrator:

  • Email Subject: [Renewal Reminder] Your Secure Email Gateway service will expire in 30 days

image

image

Urgent alert email (7, 3, and 1 day):

  • Email Subject: [Urgent] Only x days left! Renew now to maintain email security protection

image

image

Expiration notice:

  • Email Subject: [Expired] Your Secure Email Gateway service has been terminated

image

image

Limit exceeded notifications

When the system detects that the number of active corporate email accounts exceeds the number of licensed gateway accounts, it sends a notification every 7 days.

  • Email Subject: [Limit Exceeded] The number of accounts in your corporate mailbox has exceeded the gateway license limit

image

image

License update notification

When a license is successfully updated, the system sends a success notification.

  • Email Subject: [Success] Your Secure Email Gateway service has been renewed/upgraded

  • Dear Administrator, The Secure Email Gateway license for your organization, [Company Name], has been successfully updated, and your service status has been refreshed. Your updated service benefits are as follows:
    • Valid until: YYYY-MM-DD

    • Number of licensed accounts: XXX

    Thank you for using our service!
    [Alibaba Mail Security Product Team]

Renewal

To extend your service, you can renew it manually or enable auto-renewal.

Log on to the Alibaba Cloud console. From the Billing menu in the upper-left corner, select Billing Management.

image

Manual renewal: To renew manually, go to Billing Management > Subscriptions and complete the renewal.

image

Auto-renewal: To enable auto-renewal, go to Billing Management > Subscriptions and enable Auto-renewal.

image