TrellixEmail Security

    Email Security

    A secure email gateway that pulls back the message that turns malicious after delivery.

    Most advanced attacks arrive by email — credential-phishing URLs, wire-fraud requests, and weaponised attachments. Trellix Email Security is a fully cloud-based secure email gateway that identifies, isolates, and stops URL, impersonation, and attachment attacks before they enter your environment, and auto-remediates emails that turn malicious after delivery. Faltrox deploys and operates it in front of Microsoft 365 or Google Workspace.

    Overview

    What Email Security is

    Trellix Email Security is a fully cloud-based secure email gateway that identifies, isolates, and stops URL, impersonation, and attachment attacks before they enter your environment. Most advanced attacks arrive by email — credential-phishing URLs, wire-fraud requests, and weaponised attachments — and email’s highly targeted, customisable nature makes it the primary channel for cybercrime.

    It covers inbound and outbound mail, natively integrating with Microsoft 365 and Google Workspace or any third-party provider. The signature-less MVX engine detonates attachments and URLs, Advanced URL Defense uses deep learning to catch credential-phishing pages, and auto remediate pulls emails from inboxes when they turn malicious after delivery. Faltrox deploys and operates it in front of your mail platform.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Inbound Email

    Blocks URL, impersonation, and attachment attacks before they reach the inbox.

    02

    Outbound Email

    Scans outgoing mail for malware, spam, and phishing to keep your domains off blocklists.

    03

    Weaponised Attachments

    Detonates every attachment type — including password-protected and encrypted files — for zero-day exploits.

    04

    Phishing URLs

    Advanced URL Defense catches credential-phishing and typosquatting links, including those in documents.

    05

    Impersonation & BEC

    Dedicated engines stop CEO fraud and business email compromise with no malicious link or attachment.

    06

    Microsoft 365 & Workspace

    Native integration with M365 and Google Workspace, or any third-party email provider.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Route

      Update your MX records to route mail through Trellix (active protection), or use a transparent BCC rule for monitor-only.

    2. 02

      Analyse

      Messages are first checked for spam, known malware, and impersonation tactics using sender authenticity and domain-age analysis.

    3. 03

      Detonate

      The signature-less MVX engine and Advanced URL Defense analyse every attachment and URL for advanced and zero-day threats.

    4. 04

      Quarantine

      Messages hiding unknown or advanced threats are blocked before they reach the user.

    5. 05

      Auto-Remediate

      If an email turns malicious after delivery, it is automatically extracted from inboxes via the M365 and Google Workspace APIs.

    Capabilities

    Key capabilities

    MVX Detonation Engine

    A signature-less Multi-Vector Virtual Execution engine detonates attachments and URLs against a cross-matrix of operating systems, applications, and browsers to catch zero-day and evasive attacks with near-zero false positives.

    Advanced URL Defense

    PhishVision compares screenshots of targeted brands against pages behind email URLs using deep learning, Kraken adds domain and content analytics, and Skyfeed gathers malware intelligence for false-negative discovery.

    Microsoft 365 Auto Remediate

    When an email becomes malicious after delivery, it is automatically extracted from users’ inboxes via the Microsoft 365 and Google Workspace APIs — closing the post-delivery weaponisation gap.

    Impersonation Defence

    Dedicated engines stop CEO fraud and business email compromise using friendly-name identification and Newly Existing/Observed Domain (NED/NOD) analysis — catching the malware-free attacks that rely on social engineering.

    Outbound Scanning

    Scans outgoing mail for malicious attachments, phishing URLs, malware, and spam to keep your domains off blocklists, with integrated Trellix DLP policy control to stop data exfiltration over email.

    Custom YARA Rules

    Analysts add custom YARA rules to manage and enhance detection, stop the latest threats, and identify ongoing campaigns specific to your organisation.

    In-House Threat Intelligence

    Creates its own email-specific threat intelligence (Smart DNS) rather than relying on third-party feeds, so detection adapts to the email threat landscape in near real time.

    Flexible Deployment

    Active-protection mode via MX record change, or monitor-only via a transparent BCC rule — natively integrating with Microsoft 365 (Exchange Online Protection) and Google Workspace, or any third-party provider.

    Specifications

    Technical detail

    Delivery
    Fully cloud-based secure email gateway; no hardware or software to install
    Native Integration
    Microsoft 365 (Exchange Online Protection), Google Workspace, any third-party provider
    Attachment Coverage
    EXE, DLL, PDF, SWF, Office, images, MP3/MP4, ZIP/RAR/TNEF; password-protected and encrypted
    Deployment Modes
    Active protection (MX record) or monitor-only (transparent BCC)
    Certifications
    FedRAMP, ISO 27001, SOC 2 Type 2

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Email Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01We already have Microsoft 365 email protection — why add this?

    Exchange Online Protection handles known spam and malware; Trellix adds the signature-less MVX detonation chamber, Advanced URL Defense, and dedicated impersonation detection that catch the zero-day and malware-free attacks native filters miss. It integrates natively with M365 rather than replacing it.

    02What happens when a link is safe at delivery but weaponised an hour later?

    That is exactly what auto remediate addresses. Email Security retroactively analyses messages and, via the Microsoft 365 and Google Workspace APIs, automatically extracts an email from users’ inboxes once it becomes malicious after delivery — so the threat is pulled even after it has landed.

    03Can it stop CEO fraud and business email compromise?

    Yes — those are malware-free attacks with no malicious link or attachment, so they need dedicated defence. It uses friendly-name identification, sender authenticity checks, and Newly Existing/Observed Domain analysis to flag impersonation and typosquatting domains created hours before an attack.

    04Does it protect outbound mail too?

    Yes. It scans outgoing traffic for malware, spam, and phishing to keep your domains off blocklists, and its API-based integration with Trellix DLP extends data-loss protection to email, letting admins monitor data events from the Email Security console.

    05How disruptive is deployment?

    Minimal — it is fully cloud-based with nothing to install. For active protection you update your MX records to route mail through Trellix; for evaluation you can run monitor-only via a transparent BCC rule. Faltrox handles the cutover.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us