ZTmail S/MIME Automation Gateway (Abbreviated as ZTmail Gateway) is an enterprise cryptographic gateway designed to automate S/MIME email security on an organizational scale. It handles the cryptographic functions that conventional email security gateways are not designed to provide, while allowing existing security, anti-phishing, malware, DLP, compliance, and content-inspection systems to remain in place.
Core capabilities:
ZTmail handles cryptography. Your existing security infrastructure handles email security.
ZTmail Gateway is offered in two deployment editions. Both use the same core cryptographic gateway architecture, but are optimized for different organization sizes and deployment economics.
One Gateway. One Automated Certificate Strategy. Three Trust Models: ZTmail Trust (ZT), Global Trust (GT) and Hybrid Trust (HT).
For organizations that require a self-contained cryptographic gateway with an integrated enterprise CA, the Hardware Gateway combines the IMAP and SMTP service, built-in CA services, ZTmail trusted organizational Sub CA certificate, dedicated hardware cryptographic protection (PCIe HSM card), security strategy module and autonomous AI access module.
The built-in CA can automatically issue ZTmail-trusted S/MIME certificates for the organization's mailboxes and manage their lifecycle without per-mailbox & per-certificate limit. This changes the economics for large organizations: the investment is the cryptographic gateway infrastructure rather than an annual fee for every mailbox.
The Gateway deployments are designed around high availability, default using a redundant Gateway pair with load balancing and automatic failover. The organizational Sub CA private key is protected by Gateway’s integrated PCIe HSM card.
Key commercial principle: ZTmail-trusted enterprise S/MIME certificates can be provisioned at organizational scale without a per-mailbox certificate charge, without quantity limit.
Models are differentiated by throughput, concurrent connections, cryptographic performance, storage, and supported mailbox scale, the typical deployment is a redundant HA pair. The certificate trust domains (ZT or GT) composition can be customized by customers.
A dedicated organizational Sub CA certificate is built into the Hardware Gateway. The Sub CA operates under the organization's configured ZTmail Trust Root hierarchy and is protected by the Gateway's built-in PCIe HSM card.
The built-in CA can automatically issue and manage ZTmail-trusted S/MIME certificates for employees and mailboxes at organizational scale without certificate type and quantity limit. The organization does not need to purchase a separate certificate for every employee simply to establish trust inside the ZTmail trust domain.
When a mailbox must present a S/MIME certificate trusted by external S/MIME clients outside that trust domain, a Public CA certificate can be supplied automatically through the configured certificate-supply service.
For organizations that require Global Trust, ZTmail can automatically supply certificates from eligible Public CAs according to the selected trust model and certificate requirements.
Public CA certificates can be selectively deployed for mailboxes that communicate with external organizations, public-sector entities, international partners, or other environments where globally trusted S/MIME certificates are required.
Use ZTmail Trust at organizational scale. Use Global Trust where it matters.
The Software Gateway is designed for smaller organizations that need automated S/MIME encryption without the infrastructure and operational complexity of a dedicated hardware appliance. It provides the same core cryptographic gateway functions while automatically supplying ZTmail trust and global trust certificates.
Gateway Models are differentiated by supported mailbox volume. The certificate type mix and trust domain allocation shown below are typical configurations provided as a reference for customers. Certificate types and trust domain allocation can be customized according to the customer's requirements.
For organizations with over 1,000 mailboxes can negotiate bulk custom pricing, but strongly recommend using a hardware gateway, as there are no longer any certificate fees or mailbox number limits.
You Buy Encryption. ZTmail Manages the Certificates.
ZTmail automates the complete certificate lifecycle:
Request → Validate → Issue → Deploy → Renew → Replace
For Hardware Gateway deployments, the built-in enterprise CA can issue ZTmail-trusted organizational certificates at scale. For Public CA certificates, ZTmail Cloud coordinates certificate supply and the applicable CA validation and issuance process.
The Gateway can combine multiple certificate sources without forcing administrators to manually manage individual certificates.
Two Gateway Models. One Secure Email Architecture.
Inbound
Encrypted Email → ZTmail Gateway → Decrypt & Verify → Existing Security Gateway → Inspect & Protect → Recipient
Outbound
Sender → Existing Security Gateway → Inspect & Protect → ZTmail Gateway → Sign & Encrypt / Sign → Recipient
ZTmail handles cryptography. Your existing security gateway handles email security. Each does its own duty.
ZTmail Gateway can recognize the identity assurance represented by an S/MIME certificate and make it available as a configurable security policy signal.
MV: Mailbox Validated IV: Individual Validated OV: Organization Validated SV: Sponsor Validated (Individual + Organization Validated)
Organizations can use these signals in policy decisions such as allow, prioritize, inspect, warn, alert, or quarantine, subject to their own security policies.
The Gateway complies with the CA/Browser Forum defined certificate identity types. Global Trusted and ZTmail Trusted S/MIME certificates are issued according to the applicable CA's policies and the current S/MIME Baseline Requirements.
For Hardware Gateway deployments, the organizational Sub CA private key is protected by the integrated hardware cryptographic module. User private keys are generated and managed within the Gateway environment according to the organization's configured key-management policy.
The ZTmail Cloud Cryptographic Service is used for certificate supply and lifecycle management automation only; end user’s private key is securely stored in local device only.
High-availability Gateway deployments are designed so that the cryptographic service remains available during a node failure. Enterprise key-retention and historical-key requirements can be addressed according to the customer's architecture and key management policy.
Don't Replace. Complete. Each does its own duty.
Keep your existing email security gateway or system for threat detection, anti-phishing, malware detection, DLP, content inspection, and compliance. Add ZTmail Gateway for the cryptographic operations required to safely process S/MIME email.
Protect Your Existing Security Investment. Let Security Gateways Do What They Do Best. Let ZTmail Do Cryptography Best.
Hardware Gateway:
Software Gateway:
Don't let encrypted email create a security blind spot. Deploy ZTmail Gateway to decrypt and verify inbound encrypted email before security inspection, and sign and encrypt outbound email only after it has passed your existing security controls.
REQUEST PRICING
Tell us your organization size and deployment requirements. We will recommend the appropriate Gateway model and certificate configuration strategy.