Ask Secure Message a question. Answers come from this site's docs only. I will cite a page. I will not invent a product claim.
Stand up the gateway on a Debian host you control. Community starts with inbound filtering. Outbound hold-for-portal is Professional.
A dedicated Debian 13 server or VM, 2 vCPU and 4 GB RAM to start, on your own infrastructure. Ports 25, 80 and 443 reachable inbound, and outbound 25 open.
A public FQDN pointing at the host, plus a PTR record matching it. Both are needed before a certificate can be issued or your mail will be trusted.
Ability to edit MX, SPF, DKIM, and DMARC records for the domain(s) you want to protect.
Install Debian 13 on a dedicated server or VM, set a static address and FQDN, and publish the A record plus matching reverse DNS.
Download the release and run sudo ./install.sh. One prompt, then create the first administrator and complete the five-step setup wizard in the browser.
The gateway shows its node ID under System → License. Enter it with the activation code from your email to receive the licence key, then apply it. Or evaluate on the Community tier with no key at all.
Set inbound filtering thresholds. Professional adds outbound encryption rules. Generate DKIM keys and issue the TLS certificate from the console.
Run the built-in preflight, send a real message end to end, then point MX at the gateway and set it as your outbound smart host. No mailbox migration, no client software.
One Debian host. Nothing in the mail path depends on us being reachable.
Autopilot and the classifier stay off until you enable them. Point them at a model on your network, or opt into a hosted provider.
Exact commands, ports, defaults and verification steps are in the documentation. Need a hand? support@secure-message.io.
Request a Community license, or talk to engineering about a scoped trial.