Email Security Gateway
Inbound and outbound email protection with DLP scanning, DKIM signature generation, attachment extraction to secure links, and per-domain policy enforcement. A complete SMTP server implementation — not a proxy.
Inbound Protection
Full SMTP server with Postfix integration, MIME parsing, DLP scanning, and configurable policy actions on every inbound message.
MnemoShare implements a complete SMTP server (25 source files) with Postfix socketmap and content filter integration. Every inbound message is parsed, scanned, and processed inline before delivery.
- Full SMTP server implementation with Postfix socketmap and content filter integration
- MIME parsing with automatic attachment extraction
- DLP scanning on email body content and all attachments
- Policy actions: pass, reject, or rewrite (redact body, extract attachments to secure download links, or hybrid)
- Per-domain configuration for granular control
- Size limits configurable per domain (default 25 MB message, 50 MB attachments)
Outbound Relay
Outbound SMTP relay with DKIM signature generation, rate limiting, sender allowlists, and policy enforcement.
- Outbound SMTP relay with full policy enforcement
- DKIM signature generation and validation
- Rate limiting per sender to prevent abuse
- Sender allowlists for trusted addresses
- MX record resolution for intelligent routing
- Spam filtering integration
Attachment Security
Automatically extract email attachments into secure MnemoShare download links with scanning and a full audit trail.
- Automatic attachment extraction to secure MnemoShare download links
- Multi-format scanning: plain text, Office documents, PDFs
- Anonymous download links for extracted attachments when policy allows
- Full audit trail of every email processing decision
Beyond traditional MFT
Most managed file transfer platforms were designed before modern threats existed. Here is how MnemoShare compares.
| Capability | Traditional MFT | MnemoShare |
|---|---|---|
| Email integration | Files and email are separate systems | Unified SMTP gateway with DLP and policy enforcement |
| Attachment handling | Email attachments bypass file transfer controls | Attachments extracted, scanned, and delivered via secure links |
| Authentication | No email-level authentication | DKIM signature generation and validation, SPF support |
| Policy enforcement | No email policies | Per-domain config: pass, reject, or rewrite with DLP integration |
| Audit trail | No visibility into email-based file sharing | Every email processed, scanned, and logged with policy decisions |
Real-world use cases
Healthcare email compliance
Hospital routes outbound email through MnemoShare gateway. PHI detected in attachments triggers automatic extraction — attachment replaced with secure download link requiring authentication. Audit trail proves compliance.
Financial document routing
Investment firm configures per-domain policies. Emails to external partners have attachments extracted and scanned for PCI data. Clean attachments pass through; flagged content is quarantined for review.
Preventing accidental disclosure
Insurance company uses DLP-integrated email gateway to catch employees accidentally attaching wrong files. Policy blocks emails with SSN patterns in attachments and notifies sender and admin.
Frequently asked questions
- Is this a full email security gateway or just a proxy?
- MnemoShare implements a complete SMTP server (25 source files) with DKIM signature generation and validation, MIME parsing, attachment extraction, rate limiting, sender allowlists, MX resolution, and relay capabilities. It processes email inline, not as a simple proxy.
- How does email DLP integration work?
- The email gateway applies the same DLP detection engine used for file uploads to email body content and attachments. Policy actions include pass, reject, or rewrite (redact body content, extract attachments to secure links, or a hybrid approach).
- Can MnemoShare replace attachments with secure links?
- Yes. When policy triggers on an attachment, MnemoShare extracts it, stores it securely, and replaces the attachment in the email with a secure download link. The recipient authenticates to download, creating an audit trail.
- Does the email gateway support per-domain configuration?
- Yes. Administrators configure policies per sending or receiving domain, with separate rules for internal vs. external communication, different size limits, and domain-specific DLP policies.
Ready to see MnemoShare in action?
Start a free trial, schedule a walkthrough, or dive into the docs.