CybersecurityActive Beta

MailThreatZero

A managed email security gateway for MSPs and multi-domain organizations, with explainable multi-stage scoring, per-tenant policies, quarantine, and domain reputation monitoring — priced per protected domain rather than per mailbox.

MailThreatZero administration console showing mail flow over 30 days, detections by stage, threat breakdown, and service health
MailThreatZero console dashboard (annotated). Source: mailthreatzero.com.

The problem

Most email filtering is a black box. A message gets quarantined or slips through, and the person responsible for the customer can’t see which check fired or why. Meanwhile, per-mailbox pricing grows with every hire.

For an MSP looking after many customer domains, that’s two problems at once: costs that scale the wrong way, and verdicts you can’t defend.

Why existing tools fell short

Mainstream email filtering is typically licensed per mailbox and returns a verdict without showing which checks fired, which makes costs grow with headcount and leaves administrators unable to explain a held or delivered message.

The solution

MailThreatZero is an SMTP gateway that sits in front of each protected domain through its MX record. Every message runs through five scanning stages, and the console shows each stage’s weight, its contribution, and the total that crossed that domain’s quarantine threshold.

New domains can start in Monitor Mode — messages are scored and recorded while delivery is unchanged — so policies can be tuned before anything is enforced.

  • SMTP gateway with five scanning stages: reputation, authentication, malware, content, optional AI
  • Explainable scoring: each stage’s weight and contribution to the verdict
  • Monitor Mode, quarantine review and release, and message tracking
  • Delegated MSP administration with tenant, domain, and read-only roles
  • Domain reputation, DMARC aggregate reporting, and a REST API

Engineering involved

Drawn from the product’s own public documentation and trust pages. Only components the product publicly documents are listed.

Mail pipeline
An operated SMTP gateway built on Postfix, with SpamAssassin (including a Bayesian classifier), Rspamd, ClamAV, Linux Malware Detect, Oletools, Pyzor, Razor2, and a QR-code reader for QR phishing.
Tenant isolation
Access scope is applied in the data layer rather than only in the interface, and statistical spam classification is kept per tenant.
Roles & authentication
Platform administrator, tenant, domain administrator, and read-only roles; MFA where enabled, lockout on repeated failures, signed tokens, hashed passwords, and an audit trail.
AI integration
Optional AI analysis runs on the customer’s own OpenAI or Anthropic account, only when the deterministic stages leave a message inconclusive, with per-tenant credit limits and bypass rules.
Integrations & API
Microsoft Graph and Google Workspace APIs for setup checks and authorized post-delivery actions; optional VirusTotal, Joe Sandbox, or a self-hosted CAPE sandbox; a token-authenticated REST API published as an OpenAPI schema.
Hosting & operations
Run as a hosted service on US infrastructure operated by MSP Reboot; nothing is installed in the customer environment.

What makes it interesting

Explainability is the product. Instead of a single spam score, each verdict is decomposed by stage so an administrator can see exactly why a message was held — and AI is used as a tie-breaker for inconclusive messages rather than as the primary filter, which keeps costs predictable and decisions auditable.

Outcome

Not measured MailThreatZero is in its founding beta program, with capability status published feature by feature. No usage, revenue, or performance figures have been published, so none are claimed here.

Current status

Active Beta Working software in a public beta or early-access program — not yet generally available.

MailThreatZero is in an active beta with a founding beta partner program, and its pricing is published. The product site separates generally available features from those in beta testing (for example post-delivery remediation, SSO, and SIEM webhooks) and lists what is not built. It states that there is no SOC 2 report, ISO certificate, or published uptime figure.

See it working

The product site includes annotated console screenshots, a walkthrough video, and a self-guided demo with synthetic data: mailthreatzero.com.

Want something similar?

Need a system like this, built around your own business? MyAppDone can design, build, deploy, and maintain an application tailored to your workflow.

Related projects