Stand up the gateway on your own infrastructure: one Debian host, filtering inbound mail and protecting outbound within an afternoon. Here’s the full path, start to cutover.
A dedicated Debian 13 server or VM, 2 vCPU and 4 GB RAM to start, on your own infrastructure. Ports 25, 80 and 443 reachable inbound, and outbound 25 open.
A public FQDN pointing at the host, plus a PTR record matching it. Both are needed before a certificate can be issued or your mail will be trusted.
Ability to edit MX, SPF, DKIM, and DMARC records for the domain(s) you want to protect.
Install Debian 13 on a dedicated server or VM, set a static address and FQDN, and publish the A record plus matching reverse DNS.
Download the release and run sudo ./install.sh. One prompt, then create the first administrator and complete the five-step setup wizard in the browser.
The gateway shows its node ID under System → License. Enter it with the activation code from your email to receive the licence key, then apply it. Or evaluate on the Community tier with no key at all.
Set inbound filtering thresholds and outbound encryption rules, generate DKIM keys, and issue the TLS certificate — all from the console.
Run the built-in preflight, send a real message end to end, then point MX at the gateway and set it as your outbound smart host. No mailbox migration, no client software.
One Debian host. Nothing in the mail path depends on us being reachable.
Point the classifier at a hosted model, or at an endpoint inside your own network.
Exact commands, ports, defaults and verification steps are in the documentation. Need a hand? support@secure-message.io.
Start free on the Community tier, or talk to us about a rollout.