Secure Message is a self-hosted secure message gateway. It protects and encrypts outbound mail, delivers it through a one-time-code recipient portal, and filters inbound spam, phishing, and BEC — all on infrastructure you own.
From a single protected domain to a multi-tenant fleet — Secure Message covers outbound protection and inbound defense in one appliance, without bolting on extra products.
Rule-based policies scan every outbound message and automatically encrypt, redirect, or block sensitive mail — before it ever leaves your domain.
Recipients open protected messages in a branded web portal using a one-time code sent to their inbox. No account, no password, no app to install.
Layered checks — SPF, DKIM, DNSBL reputation, and content heuristics — quarantine junk and spoofed mail before it reaches a mailbox.
Optional LLM classification catches business-email-compromise, spear-phishing, and social engineering that slip past signature-based filters.
Every stored message and attachment is encrypted with AES / Fernet keys you hold, so data on the appliance is unreadable if a disk is ever exposed.
Review held mail, release false positives in a click, and manage per-domain allow and block lists from a single admin console.
Reject mail to non-existent users at the edge via SMTP callout, LDAP, or Microsoft Entra directory lookups — cutting backscatter and wasted load.
Automated, encrypted backups of configuration, quarantine, and message stores keep you recoverable without ever exposing plaintext.
Every admin action and message decision is logged and exportable to CSV for audits, e-discovery, and retention requirements.
Secure Message pairs classic mail authentication with an on-premise AI layer that understands message intent — catching modern phishing and BEC while keeping every byte of your mail inside your perimeter.
Stops spear-phishing, business-email-compromise, spoofing, and lookalike-domain attacks with layered SPF/DKIM/DNSBL checks plus intent analysis — before a malicious message ever reaches a mailbox.
A large-language-model classifier reads what a message is actually trying to do — urgency, payment redirection, credential harvesting, tone — and flags social engineering that signature and rule-based filters miss.
The model runs inside your own deployment: your mail is never sent to a third-party AI service, prompts and content stay encrypted at rest under your keys, and every AI decision is logged and auditable.
No mailbox migration, no client software, no accounts for your recipients. Secure Message sits in front of the mail you already run.
Route inbound mail through Secure Message and relay outbound through it as a smart host. Deploy on your own server, cloud or on-prem, in an afternoon — no mailbox migration, no client software.
Inbound mail is authenticated and scored (SPF/DKIM/DNSBL + heuristics, with optional AI). Outbound mail is checked against your policies and encrypted automatically when it matches.
Protected messages arrive as a notification with a secure link. The recipient enters a one-time code and reads or replies in the portal, while everything stays encrypted at rest.
Most secure-email services decrypt and scan your mail on their servers. Secure Message keeps encryption at rest under a key that only ever exists on your host, and runs entirely inside your own perimeter.
Messages, attachments, and quarantine are encrypted with AES / Fernet keys that never leave your deployment — plaintext is never written to disk.
SPF, DKIM, and DNSBL reputation checks reject spoofed and forged senders before any content is evaluated, cutting phishing at the door.
A large-language-model classifier reads message intent to catch phishing, business-email-compromise, and social engineering that signature-based filters miss — running inside your perimeter, never sending your mail to a third party.
TOTP multi-factor for administrators, granular roles, and full audit logging of every configuration change and message decision.
Self-host the gateway and no message — inbound or outbound — is ever processed on someone else’s servers. Your mail stays inside your perimeter.
Every message is encrypted at rest under a key that only ever exists on your host, and the entire mail path runs inside your own perimeter. The one decision left is where AI inference happens — and that can be your own hardware too.
Total control for regulated, sovereign, and air-gapped environments.
Point the classifier at a hosted model, or at inference running on your own network.
Healthcare, finance, and legal teams keep HIPAA, GLBA, and privileged mail encrypted at rest and deliver it to recipients without exposing PHI or client data to a third party.
Run one multi-domain gateway across every client, with per-domain policies, branding, and quarantine — turning secure email into a billable managed service.
Add outbound encryption and modern inbound filtering in front of Microsoft 365 or your own mail server — no mailbox migration, no new client for users to learn.
Audit logs, retention controls, allow/block governance, and encrypted backups give compliance and security teams the paper trail and control they’re accountable for.
Fill, sign and flatten a PDF on the workstation, then send it through the gateway. No extra cloud account. Distributed from the Rubix Hub, free forever.
Licensed annually per protected domain, self-hosted on your own infrastructure. Every plan includes the core secure gateway, encryption at rest, and the one-time-code recipient portal.
The core gateway, free for a single domain and one administrator.
Full inbound protection and the encryption portal for growing teams.
Compliance, automation and priority support for regulated orgs.
Prices in USD. Multi-domain, MSP and self-hosted licensing available — compare all plans on the Rubix Hub.
Stand up a secure gateway in an afternoon — encryption at rest, inbound filtering, and a recipient portal with no accounts to manage.