ZTmail S/MIME Automation Gateway

The Cryptographic Gateway for Enterprise Email
S/MIME Encryption for Every Organization, Automated. AI, Your Key.

Automate the cryptographic operations of enterprise email:

Certificate Lifecycle · Sign · Encrypt · Decrypt · Signature Validation · Trusted Identity
Zero Client Change Open S/MIME Built-in Enterprise CA Automated PKI

An S/MIME Automation Gateway with Built-in Cryptographic InfrastructureZTmail S/MIME Automation Gateway (Abbreviated as ZTmail Gateway) sits between your existing email infrastructure and the outside world, automatically handling S/MIME encryption, decryption, digital signing, and certificate management.

Built-in Enterprise CA for issuing S/MIME certificate locally automatically

A dedicated organizational Sub CA (S/MIME Issuing CA) is built into the Gateway, enabling automatic issuance and lifecycle management of ZTmail-trusted email certificates for your organization, without quantity limits.

Organizational Trust

Each organization can have its own ZTmail Trust Domain, providing trusted email digital identities across the organization on scale.

Cryptographic Automation

Sign, encrypt, decrypt, verify, renew, and revoke automatically, without requiring every employee to manage certificates themselves.

Decrypt First. Secure Next. Protect Your Existing Email Security Investment. You do not need to replace your existing email security gateway to adopt S/MIME encryption. Let each system do what it does best.

INBOUND

Encrypted Email Received
ZTmail Gateway
Decrypt · Verify Signature · Verify Trusted Identity
Plaintext Email
Existing Email Gateway
Threat Detection · DLP · Malware · Phishing · Content Inspection
Recipient

OUTBOUND

Sender sent email
Existing Email Gateway
Threat Detection · DLP · Malware · Phishing · Content Inspection
Plaintext Email
ZTmail Gateway
Verify Policy · Sign · Encrypt
Recipient

Make Identity Actionable. A Digital Certificate Is More Than Encryption.

S/MIME certificates do more than enable encryption. A digitally signed email can carry a trusted digital identity, validated through Global Trust or an organizational trust domain according to applicable standards and policies.

ZTmail Gateway can validate that identity and turn it into an actionable security signal.

Who Really Sent This Email?

ZTmail Gateway can recognize the identity assurance represented by the sender's certificate and apply organizational policies accordingly (Go or block directly).

From “Who Is This?” to an Actionable Security Signal S/MIME certificates can represent different levels of identity validation.

MV
Mailbox Validated
IV
Individual Validated
OV
Organization Validated
SV
Sponsor Validated

ZTmail Gateway can use these trust signals as part of configurable email security policies. Trust Can Become a Security Policy.

  • Higher-assurance identity → Allow / Prioritize
  • Unknown or unverified identity → Inspect / Warn
  • Invalid signature → Alert / Quarantine

Every Email Can Carry a Trusted Digital Identity. Many organizations send emails to people outside their own organization. The recipient may not have a certificate for encryption. But the organization can still digitally sign the email.

Government
Official notices, application results and public-service communications.
Banking
Statements, transaction notifications and customer communications.
Utilities & Public Services
Bills, service notifications and account communications.
Enterprise
Legal, financial, executive and other high-trust communications.

A digital signature helps recipients verify: • Who signed the message • Whether the message was altered after signing

Digital signatures don't just protect message integrity, also prove the trusted identity behind it.

YOU BUY GATEWAY. ZTMAIL MANAGES THE CERTIFICATES.

BUY GATEWAY, GET THE CERTIFICATE LIFECYCLE MANAGEMENT.

Certificate Automation from Issuance to Renewal
With its built-in enterprise CA, the ZTmail Gateway automatically issues and manages organizational trusted S/MIME certificates for employees — at organizational scale.

Organization Setup
Establish a dedicated ZTmail Trust Domain for your organization.
Identity & Policy
Define employees and the trusted identity level for their email certificates.
Issuance
The Gateway automatically issues ZTmail-trusted S/MIME certificates for employees.
Deployment
The Gateway automatically manages certificates and private keys for S/MIME email operations.
Renewal
Certificates are automatically renewed before expiration.
Revocation
The organization can revoke certificates whenever necessary.

Built-in CA for Your Organization. Public CA When You Need It.

The ZTmail Gateway's built-in enterprise CA automatically issues and manages ZTmail-trusted S/MIME certificates for employees across your organization. For a small number of mailboxes that need global trust for external communication, Gateway can automatically obtain globally trusted MV certificates from Public CAs.

One Gateway. Two Certificate Sources. Multiple Trust Models. One Optimized Certificate Strategy.
Built-in Enterprise CA
  • Organization-wide S/MIME certificates
  • ZTmail Trust
  • Automated issuance and lifecycle management
  • No per-mailbox certificate dependency, unlimited supply
Global CA
  • Selected external-facing mailboxes
  • Global Trust
  • Automatically issued MV certificates, optional OV/SV certificates
Organizational Trust by Default. Global Trust When Needed. Multiple trust models and automates certificate lifecycle across organizational and global trust environments.

Dedicated Hardware Cryptographic Infrastructure for Organizational Trust

ZTmail S/MIME Automation Gateway is delivered as a dedicated hardware cryptographic appliance, providing a secure foundation for your organization's email trust domain. With built-in enterprise CA capabilities and hardware-protected CA keys, the Gateway automatically issues and manages organizational trusted and global trusted S/MIME certificates for your organization.

High Availability Architecture

Enterprise deployments use redundant dual gateway architecture to ensure continuous cryptographic services: Dual Gateway Cluster, High availability, Load balancing, Service continuity

Secure Cryptographic Foundation

The Gateway integrates hardware security modules (HSMs) to protect critical CA keys and support secure certificate issuance and lifecycle management.

One Gateway. Two Trust Domains.

  • ZTmail Trust: ZTmail-trusted OV/SV S/MIME certificates are issued through ZTmail Cloud Cryptographic Service, trusted identity within the ZTmail ecosystem
  • Global Trust: MV S/MIME certificates from public CAs for external communication requirements, optional for OV/SV certificate. Publicly trusted S/MIME certificates for external interoperability

Optional: Software S/MIME Automation Gateway

Client-Cloud based certificate automation for growing organizations that do not require dedicated hardware CA infrastructure, ZTmail Software Cryptographic Gateway provides automated S/MIME certificate management through ZTmail Cloud Cryptographic Service including certificate application, issuance, renewal, revocation etc.

Hardware-Protected Key Management
ZTmail S/MIME Automation Gateway securely manages the cryptographic keys required for trusted email operations.

CA Key Protection

The Organization Sub CA private key is protected by integrated hardware security modules (HSMs), providing a secure foundation for your organization's email trust domain.

User Key Protection

Private keys and CSRs for employee S/MIME certificates are generated locally within Gateway and securely managed throughout the certificate lifecycle. Gateway performs encryption, decryption, digital signing, and certificate operations without requiring certificate deployment to every email client.

High Availability Key Protection

In enterprise deployments, dual Gateway architecture provides secure key synchronization and operational continuity, ensuring continued access to encrypted email and cryptographic services.

Don't Replace. Complete.

Your existing email security gateway already protects your organization with:

Threat Detection · Anti-Phishing · Malware Detection · DLP · Content Inspection · Compliance

Keep It.

ZTmail Gateway adds to the cryptographic capabilities it was not designed to provide:

Certificate Automation · S/MIME Encryption · Decryption · Digital Signature · Signature Validation · Trusted Identity

Protect Your Existing Security Investment.
Let Security Gateways Do What They Do Best. Let ZTmail Do Cryptography.

Don't Let Encryption Become a Security Blind Spot.

Encrypted email protects confidentiality. But encryption can also create a security inspection challenge.
When email content is encrypted, conventional security controls may not be able to inspect the content or apply content-based security policies.

That creates two risks:

Inbound Risk

A malicious or fraudulent email can arrive encrypted, while downstream security controls cannot inspect its content.

Outbound Risk

Sensitive information can be encrypted before conventional content inspection or DLP controls can inspect the plaintext.

Encryption Should Protect Your Email, Not Hide It From Your Security.
Add one Cryptographic Gateway. Your Existing Security Stack Stays Intact.

AI Ensures Email Security

Bring Your Own AI Provider and API Key.

AI security is optional. If your organization already has an email security gateway, keep using its security and AI capabilities. If you do not have one, ZTmail Gateway can optionally integrate AI-powered email analysis using your preferred AI provider and your own API key.

Possible applications include: Phishing Analysis BEC Analysis Suspicious Email Detection Content Analysis
Your AI Provider . Your API Key . Your Choice.

One Gateway. Complete Cryptographic Lifecycle Management.

AUTOMATE
Certificate issuance · deployment · renewal · revocation
PROTECT
S/MIME encryption · decryption · private key security · hardware-protected CA keys
PROVE
Digital signature · signature validation · trusted identity
ADAPT
Built-in Enterprise CA · Organizational Trust · Global Trust · Hybrid Certificate Strategy

Build your own organizational email trust domain with built-in CA capabilities, while using public CA certificates only when global trust is required.

Ready to Build Trusted Email Infrastructure at Scale?

ZTmail helps organizations automate S/MIME encryption, trusted identity, and certificate management with flexible Gateway deployment options.
From dedicated hardware cryptographic infrastructure to cloud-based certificate automation, build the trusted email environment your organization needs.

Start Your Enterprise Trusted Email Journey
Talk to Our Enterprise Team