Microsoft 365
An Exchange Online inbound connector receives filtered mail from the gateway. The setup wizard generates that connector's settings for the specific domain in front of you, with copy buttons.
How it works
MailThreatZero is a managed secure email gateway that scans inbound email before securely relaying it to your existing mail platform. It works with Microsoft 365, Google Workspace, Exchange, hosted email providers, and customer-owned mail servers.
Your mailboxes do not move. Microsoft 365, Google Workspace, Exchange, a hosted provider or your own server — the gateway relays to whatever you already run. Inbound messages pass through the MailThreatZero gateway for security analysis before being relayed to the configured destination mail server.
Every enabled and applicable scanning stage runs for each message, so a message that passes reputation still has its attachments inspected. Each stage contributes to one weighted score rather than voting pass or fail.
Cut off traffic from hosts with a known bad history before a single header is parsed.
Establish whether a sender is entitled to use the domain in the From header, and let that answer inform every later stage.
Catch malicious files and Office macros before they reach a mailbox.
Filter bulk and deceptive mail without punishing legitimate newsletters and billing notices.
Look at the messages rules find ambiguous — the targeted phishing and business email compromise that has no signature.
Every capability in detail, engine by engine.
Engines contribute weighted scores to a total. The total is compared with two thresholds set per domain: one for quarantine and a higher one for rejection.
Below the quarantine threshold. The message is relayed on normally, and the full breakdown is still recorded for tracking.
At or above the quarantine threshold. The message is held on the gateway, and a notification with a review link can be sent to the recipient.
At or above the reject threshold, or a confirmed virus. The sending server is told the message was refused, so a legitimate sender knows.
Every message is scored and recorded per domain, and delivery is unchanged — so policy can be evaluated and tuned against live mail before it is enforced.
Two behaviors exist specifically to stop over-blocking: a verified sender suppresses the heuristics that only make sense for unverified mail, and a non-critical AI verdict cannot cross the quarantine line on its own. We publish the concepts rather than the exact weights and thresholds, which are tuning detail an evader would find more useful than a buyer.
Filtered mail is delivered to your platform over its own supported inbound path — an Exchange Online inbound connector or a Google Workspace inbound gateway — which is SMTP with TLS, configured inside your tenant. Mailboxes, users and licensing stay exactly where they are.
An Exchange Online inbound connector receives filtered mail from the gateway. The setup wizard generates that connector's settings for the specific domain in front of you, with copy buttons.
A Google Workspace inbound gateway does the same job, generated for the domain in the same way.
A destination host and port per domain: hosted Exchange, cPanel, Zimbra or anything that accepts SMTP.
The gateway records what it saw. The authentication result it determined is stamped on the message, so your platform can trust that verdict rather than deriving its own. ARC sealing of that result switches on once the domain's ARC key is published in DNS — the gateway will not sign with a key it cannot resolve. The tenant connection used to verify a domain before cut-over is read-only and directory-scoped — no mailbox read or send permission is requested, and mail is never carried by API. Details are on the security page.
Set its destination mail server and starting policy. Nothing changes for your mail yet.
The wizard generates the exact connector and filtering settings for that domain, with copy buttons rather than placeholders to translate.
Before MX changes, the wizard checks the tenant, public DNS, the destination and that your platform will accept mail from the gateway. Each check returns a specific remedy, and a check that could not run is reported as untested rather than counted as a pass.
Change the domain's MX to
mt0.mailthreatzero.com. Run in Monitor Mode while you tune thresholds and lists against the
per-message breakdowns from real traffic.
Monitor Mode scores and records every message per domain with delivery unchanged.