VENICE, CA — May 26, 2023
MailRoute inspects every inbound message on its own infrastructure. A threat that fails inspection never reaches the customer's mail server.
Email is the most heavily attacked channel most organizations operate, and the attacks have not stayed still. Zero-day malware, ransomware payloads, and credential phishing now arrive faster than signature-based tools can be updated. MailRoute has filtered inbound mail for organizations since 2003, and the architecture that does it has one governing idea: inspection happens before delivery, somewhere other than the customer's network.
Off-Site Means the Threat Never Arrives
MailRoute sits in front of the mail server as the MX record. Mail is accepted, inspected, and either delivered or held on MailRoute's infrastructure. An appliance or a mailbox-level scanner examines a message that has already crossed the perimeter. MailRoute examines it before it gets there.
That distinction matters most on the messages nobody has seen before. A quarantined ransomware attachment sitting on MailRoute's systems is a message the customer's network never processed.
"Signature updates will always trail the attack that has not been catalogued yet," said Thomas A. Johnson, founder and CEO of MailRoute. "So we do not rely on them alone, and we do the work somewhere that is not your network. If we get it wrong, we get it wrong on our hardware."
Layers, Not a Single Filter
No single technique catches everything, so MailRoute runs several in sequence against every message:
- Sender authentication — SPF, DKIM, and DMARC evaluation, plus display-name spoofing and lookalike-domain detection
- Content analysis — heuristic and machine-learning classification tuned against live mail flow, not a static ruleset
- URL scanning — links extracted and analyzed, including links embedded in images and QR codes
- Attachment inspection — malware and ransomware payload detection before the attachment moves
- Real-time threat intelligence — reputation and newly registered domain (NRD) blocking applied at connection time
The layers are independent. A message that slips past one still has to clear the rest.
Three Plans, One Filtering Engine
The filtering itself does not change between plans; the surrounding capability does. Basics covers inbound and outbound security. Enterprise adds phone support, LDAP/AD synchronization, single sign-on, and Email Continuity. Enterprise U.S. runs in US-only datacenters with US-citizen-only account access, and meets ITAR, HIPAA, and NIST 800-171 requirements.
MailRoute also integrates directly with Microsoft 365, including GCC High tenants, for organizations that need filtering upstream of a cloud mailbox rather than a server they run themselves. Details are on the MailRoute Email Security Services overview.
About MailRoute
MailRoute has provided hosted email filtering since 2003. Founder Thomas A. Johnson has worked in email security since 1997, when he built Big Fish Communications — later renamed FrontBridge Technologies — which Microsoft acquired in 2005 and still operates today as Exchange Online Protection. MailRoute is self-funded and independent, with infrastructure it owns and runs itself.
Media contact: info@mailroute.net