Sora Yazılım
English
Custom software solutions from Türkiye
Bitdefender · Cybersecurity

GravityZone Email Security

Gateway plus Microsoft 365 API-based email protection against phishing, BEC and malicious attachments.

Quick answer

GravityZone Email Security is Bitdefender's email security add-on; it protects corporate mailboxes against phishing, business email compromise (BEC), impersonation, malicious attachments and spam. More than 250 filters are applied to every email. It can be deployed as an MX-based gateway, as a Microsoft 365 API integration, or as both together, and it is managed from the GravityZone console.

GravityZone Email Security is Bitdefender's add-on product for protecting the email layer; it inspects inbound and outbound email for phishing, business email compromise (BEC), impersonation, malicious attachments, malicious links and spam. The product can be deployed as a secure email gateway (SEG) that operates through your MX record, as mailbox protection that connects to Microsoft 365 over API, or as a combination of the two; it is managed from the Bitdefender GravityZone console.

According to Bitdefender's official product page, the solution applies more than 250 unique filters to every email it processes (Bitdefender, 2026). The vendor's technical documentation states that more than 99% of threats in inbound traffic are blocked and that the antispam layer operates with a detection rate above 99.9% (Bitdefender TechZone, 2026). Both of these figures are the vendor's own claims; measurements of Bitdefender's engines carried out by independent testing organizations are given separately below, with their sources.

At Sora Yazılım we position this product not as a standalone point solution but as the natural complement to endpoint protection: the majority of attacks begin with email and end on the endpoint. Having both mailbox and endpoint telemetry in the same console lets you see on a single screen how many users a phishing campaign reached and on which device the file was executed.

What exactly does GravityZone Email Security protect, and how is it deployed?

Short answer: it protects corporate mailboxes both before and after delivery, and it can be installed using several different deployment models. According to Bitdefender TechZone documentation, the Gateway model works like a classic secure email gateway at the network perimeter once the MX record is redirected, and it supports Microsoft 365, Google Workspace, on-premises Exchange and hybrid environments. The 365 model connects to Microsoft 365 over API and inspects the email after it has landed in the user's mailbox. The Unified model runs both together (Bitdefender TechZone, 2026). The support documentation additionally describes an Outbound Smarthost setup for outbound traffic (Bitdefender B2B Support, 2026).

This flexibility covers both of the scenarios we encounter most often in Turkey. Organizations that have moved their mail infrastructure entirely to the cloud prefer the API model, without touching mail flow at all. Organizations that still run on-premises Exchange or a hybrid setup are protected with the gateway model; this group falls outside the scope of most cloud email security products, yet it is still widespread in Turkey. Outbound email scanning is separately valuable for protecting the organization's IP reputation and for limiting the ability of a compromised account to spread spam through the corporate domain.

Deployment modelHow it worksSupported mail infrastructureTypical use
GatewayThe MX record is redirected to Bitdefender; email is filtered before it reaches the mailboxMicrosoft 365, Google Workspace, on-premises Exchange, hybridOrganizations running a hybrid or on-premises mail server
365 (API)Connects to Microsoft 365 with secure API access; the MX record stays unchangedMicrosoft 365Fully cloud-based organizations wanting fast, disruption-free rollout
UnifiedRuns gateway filtering and API-based mailbox protection togetherMicrosoft 365Organizations wanting full pre- and post-delivery coverage
Outbound SmarthostRoutes outbound email through Bitdefender and scans itAny environment with outbound mail flowProtecting IP reputation and domain trustworthiness

Can email security be deployed without changing the MX record?

Yes. In organizations using Microsoft 365, the API-based model is deployed without touching the MX record at all. Bitdefender's product page describes this integration as secure API-based access and states that directory synchronization is performed automatically through Azure AD (Entra ID) (Bitdefender, 2026). In practice this means the user and group list does not have to be migrated by hand, and a newly hired employee enters the protection scope automatically.

What is the operational advantage of the API model?

Because the MX record does not change, DNS propagation, TTL waiting time and the risk of an interruption in mail flow all disappear. The rollout can be started with a pilot user group, results monitored and the scope then widened. Rolling back is just as straightforward: when the integration is removed, mail flow is not affected at all. For Microsoft 365 licensing, tenant configuration and identity-side preparation, you can review the scope described on our Microsoft 365 solutions page; designing both sides together eliminates the most frequent source of permission errors.

At which layers are BEC, impersonation and phishing attacks stopped?

These attacks are not stopped by a single filter but by multiple overlapping layers, because BEC emails usually contain neither a malicious attachment nor a malicious link and therefore do not get caught by classic signature-based scanning. According to Bitdefender TechZone documentation, the antispam layer consists of IP, domain and URL reputation analysis, email address and phone number filtering, cryptocurrency wallet blocklists, patented fingerprinting algorithms that use cryptographic hashes, AI-assisted image analysis for image-embedded spam, and machine learning models built specifically for spear phishing and BEC. On the detection side, the Malware Protection, Antispam and Sandbox Analyzer engines work together (Bitdefender TechZone, 2026).

The product page additionally names email authentication with SPF and DMARC, graymail (marketing/newsletter) filtering, outbound email scanning and end-user quarantine digests as capabilities (Bitdefender, 2026). SPF and DMARC should not be neglected: this is the only mechanism that prevents spoofed email from being sent in your domain's name, and when it is not configured correctly even the most expensive filter is effectively bypassed. In our deployments we recommend starting the DMARC policy in monitoring mode first and tightening it only after the reports have been read.

Sandbox analysis is a critical layer for suspicious attachments. Bitdefender's Sandbox Analyzer component ships on the endpoint side with the GravityZone Business Security Premium package; using the same analysis infrastructure across the email and endpoint layers prevents the same malicious file from producing two different verdicts in two different products.

What happens if a threat is detected after the email has reached the user?

Post-delivery remediation exists for exactly this scenario. A campaign can look clean in its first minutes and be classified as malicious hours later; in that case the email has to be pulled back out of the mailbox. According to Bitdefender documentation, automatic remediation keeps monitoring emails for 48 hours after delivery, and the administrator can trigger the Remediate action directly from the console. Quarantined emails are retained for 28 days, and Live Email Tracker keeps detailed records for 90 days (Bitdefender TechZone, 2026).

What changes on the user side?

End users receive an automatic quarantine digest or view their own emails through the quarantine portal. The Outlook report button lets an employee forward a suspicious email, or a message that was quarantined by mistake, to the help desk with a single click (Bitdefender TechZone, 2026). This feedback loop should not be underestimated: correcting false positives quickly increases users' trust in the filter and, with it, the likelihood that they will report a genuine attack.

If the incident has moved beyond email — for example, if the user entered credentials on a fake page — correlation is required. GravityZone XDR collects telemetry from Office 365, Google Workspace, Identity (Active Directory / Entra ID / Intune), Network, Cloud and Mobile sensors in addition to the endpoint sensor (Bitdefender TechZone, 2026). That way the phishing email, the anomalous sign-in that follows it and the process activity on the endpoint are merged into a single incident chain.

For organizations without a team to monitor that chain 24/7, Bitdefender MDR comes into play. The service runs on a follow-the-sun model with three SOCs in the United States (Texas), Romania (EU) and Singapore, and the team consists of more than 285 security analysts, researchers and threat hunters (Bitdefender, 2026).

How does GravityZone Email Security differ from Trend Micro Email Security and FortiMail?

All three are mature email security products; the differentiation comes less from detection quality than from architecture and ecosystem preference. Bitdefender's advantage is that the email layer is managed in the same console as endpoint and XDR. Trend Micro Email Security is the natural choice for organizations tied to the Trend Vision One ecosystem. Fortinet FortiMail, in turn, is a gateway-focused approach that can be positioned as hardware, virtual machine or cloud and integrates with the Fortinet Security Fabric — it makes particular sense if a FortiGate-based network infrastructure is already in place. Organizations that want to consolidate backup under the same contract can evaluate Acronis Advanced Email Security.

Decision criterionBitdefender GravityZone Email SecurityTrend Micro Email SecurityFortinet FortiMail
Core positioningEmail add-on connected to the GravityZone consoleEmail layer of the Trend Vision One ecosystemStandalone email security gateway
When it stands outWhen endpoint protection is already Bitdefender; when a single console and single contract are wantedWhen the organization has invested in Trend Micro XDR/Vision OneWhen the network layer is Fortinet; when you want to run the gateway under your own control
Deployment without changing MXAPI-based model available for Microsoft 365Varies by product family; an architecture review is neededThe gateway architecture sits in the mail flow
On-premises / hybrid mailSupported with the gateway modelAssessed according to the architectureThe scenario where it is strongest
Correlation with endpointIn the same console, together with XDR sensorsThrough Vision OneThrough the Security Fabric

The table should be read as a decision tree, not as a ranking. Sora Yazılım is an authorized channel partner for all three brands; we make the choice together with you based on your existing infrastructure, your maturity on the identity management side and the capacity of your internal team, and on request we set up a limited comparative pilot.

Aren't the built-in protections in Microsoft 365 enough?

Whether they are enough depends on your risk profile; however, a second and independent engine layer in email security reduces the risk of being exposed to a single vendor's detection gap. This does not mean Microsoft's protection is weak — it means intelligence sources of different origins are layered on top of one another. In addition, a separate email security layer brings mailbox protection and endpoint protection onto the same policy and reporting plane.

Independent measurements of Bitdefender's detection engines cover the endpoint products rather than the email product; even so, they provide a verifiable indicator of engine quality. In AV-TEST's November–December 2025 corporate Windows 11 test, Bitdefender Business Security Enterprise 7.9 received the "TOP PRODUCT" certification with 17.5 points out of 18 (AV-TEST, 2025). In AV-Comparatives' March–June 2026 business test, GravityZone Business Security Premium 8.26 recorded a 99.8% protection rate with 4 false alarms in the real-world protection test (AV-Comparatives, 2026).

Alert quality matters especially in email-borne incidents, because a single campaign touches hundreds of mailboxes and, if every touch turns into a separate alert, the team drowns. In its own announcement regarding the 2024 MITRE Engenuity ATT&CK enterprise evaluation, Bitdefender reported that it generated an average of 3 alerts to report an incident to the SOC, while the median for the other participants was 209 alerts (Bitdefender, 2024). This data point comes from the vendor's own announcement. On the positioning side, Bitdefender was placed in the "Visionary" quadrant for the fourth consecutive time among 13 vendors in the Gartner Magic Quadrant for Endpoint Protection evaluation dated 26 May 2026 (Bitdefender, 2026) — that is the "Visionary" quadrant, not "Leader".

Which GravityZone package licenses Email Security?

It is not included by default in any GravityZone package. Bitdefender's official comparison page lists Email Security / Extended Email Security — together with Patch Management, Full Disk Encryption, Security for Exchange, Security for Mobile, Container Security and the XDR sensors — as an add-on licensed separately at every tier (Bitdefender, 2026). This is the source of a frequent budgeting mistake: when the endpoint package is purchased, email protection is assumed to come with it, whereas it is a separate line item.

GravityZone tierEmail-related capabilities included in the packageEmail Security add-on
Small Business SecurityAntimalware, antiphishing, Web Threat Protection, ransomware mitigationLicensed separately
Business SecurityThe above + Application Control, Network Attack Defense, device and web access control, Endpoint Risk AnalyticsLicensed separately
Business Security PremiumThe above + HyperDetect, Cloud Sandbox Analyzer, advanced fileless attack defense, Microsoft Exchange mailbox protection, attack forensicsLicensed separately
Business Security EnterpriseThe above + cross-endpoint correlation and visualization, threat hunting, Anomaly Defense, one-click remediationLicensed separately
GravityZone Defense XDRThe above + Office 365, Identity, Network and Cloud XDR sensors, automatic correlationLicensed separately

Source: Bitdefender official comparison page (Bitdefender, 2026). Pricing varies with the number of mailboxes, the commitment term and the deployment model selected; we do not publish prices on our site. Request a quote based on your organization's mailbox inventory.

What does email security require in Turkey in terms of KVKK and sector compliance?

Law No. 6698 on the Protection of Personal Data — KVKK, Turkey's data protection law — obliges the data controller to provide an appropriate level of security to prevent unlawful access to personal data; and when a data breach occurs, notification must be made to the Board and to the data subjects concerned (KVKK, Data Breach Notification). Email is the channel through which personal data most easily leaks outside the organization: a file sent to the wrong recipient, a bulk download performed from a compromised mailbox or a fraudulent invoice redirection are typical breach scenarios.

For this reason email security must be designed not merely as "spam blocking" but as a compliance control. In practice we ask for these three things together in our deployments: outbound email scanning, retention of quarantine and incident records in an auditable form, and regular review of authentication records (SPF/DMARC). On the product side, the 90-day retention of Live Email Tracker records and the 28-day retention of quarantine provide a starting point for answering the question "what reached which user" during a breach investigation; in sectors that require longer retention, we plan for these records to be forwarded to a central log infrastructure.

One additional point for organizations working in finance, healthcare and the public procurement chain: audits ask not only whether the email security control exists, but whether it can be proven to be working. What is requested is not a screenshot of a policy but periodic reports and incident records. Designing the regular reports produced from the GravityZone console so that they can be attached to the audit file is far less costly than a hurried preparation after the fact.

What does Sora Yazılım do during the rollout?

As an authorized Bitdefender channel partner, we deliver licensing, architecture selection, installation, policy design, migration and ongoing operational support together. The process starts by mapping the existing mail infrastructure and flow: how many mailboxes there are, which part sits in the cloud, which applications use SMTP relay and what the SPF/DMARC status of the domain is. The deployment model is then selected and a pilot group is started. Once the false positive rate and user feedback have been monitored, the scope is widened gradually; when migrating from a previous solution, we plan an overlap period in which two filters run side by side for a while.

Email security alone is not enough. On the endpoint side, Bitdefender Endpoint Security Tools supports a broad range of operating systems, from Windows 11 and Windows Server 2025 through Red Hat Enterprise Linux, Debian and Ubuntu distributions to macOS machines with Intel and Apple M series processors (Bitdefender B2B Support, 2026); the endpoints behind the email layer should be protected from the same console. For configuration work on the identity, directory and cloud workload side, we provide support within the scope of our DevOps and infrastructure services.

Next step. Share your mailbox count, your current email security solution and the cloud/hybrid distribution of your mail infrastructure; let us size the appropriate deployment model, the add-on scope and, if needed, an integrated configuration together with an endpoint package. If you want a comparative evaluation, we prepare a single quotation file that also covers the Trend Micro and Fortinet alternatives. Request a quote through the contact form; let us draw up the technical support and rollout plan together.

Key features

What it offers

  • MX-based gateway (SEG) or Microsoft 365 API-based mailbox protection — or both together
  • More than 250 unique filters applied to every email
  • Business email compromise (BEC) and impersonation protection
  • Machine learning-based detection models for spear phishing and BEC
  • IP, domain and URL reputation analysis
  • Patented fingerprinting algorithms using cryptographic hashes
  • AI-assisted image analysis for image-embedded spam
  • Email authentication with SPF and DMARC
  • Graymail (marketing/newsletter) filtering and outbound email scanning
  • Malware Protection, Antispam and Sandbox Analyzer engines working together
  • Post-delivery automatic remediation and the Remediate action from the console
  • End-user quarantine digest, self-service quarantine portal and Outlook report button
Tech Summary

Important technical data

Product type
GravityZone add-on — not included by default in any package, licensed separately
Deployment models
Gateway (MX-based), 365 (API-based), Unified, Outbound Smarthost
Native API integration
Microsoft 365 — secure API-based access; automatic directory synchronization with Azure AD (Entra ID)
Infrastructures supported in the gateway model
Microsoft 365, Google Workspace, on-premises Exchange, hybrid environments
Filter coverage
More than 250 unique filters on every email processed
Detection engines
Malware Protection, Antispam, Sandbox Analyzer
Email authentication
SPF and DMARC support
Quarantine retention period
28 days
Post-delivery monitoring
Automatic remediation continues to monitor for 48 hours after delivery
Live Email Tracker record retention
90 days
Use Cases

When would you choose this product?

Manufacturing and industry

Gateway protection for hybrid mail infrastructure

In manufacturing companies that run on-premises Exchange alongside Microsoft 365, the MX-based gateway model puts both sides behind a single filter. Fraudulent invoice and payment instruction attempts in supplier correspondence are stopped before delivery; outbound scanning limits the ability of application servers on the production floor to spread spam through SMTP relay.

Finance and insurance

Layered defense against BEC and payment instruction fraud

Emails that impersonate an executive to request a wire transfer contain no malicious attachment, so classic antivirus does not catch them. Impersonation protection, domain lookalike checks and SPF/DMARC validation target exactly this scenario. Merging endpoint and email incidents in the same console also provides audit reporting from a single source.

Healthcare

Reducing breach risk in correspondence containing patient data

In hospitals and private healthcare providers, personal health data circulates as email attachments. Outbound email scanning, retention of quarantine records and post-delivery recall capability make it possible to document which data reached whom during breach investigations under KVKK (Turkey's data protection law).

Public sector and municipalities

Phishing filtering in high-volume external correspondence

In institutions with heavy citizen and supplier correspondence, inbound mail volume is high and the attack surface is wide. Unknown attachments are inspected through reputation analysis, URL checks and sandbox analysis; the end-user quarantine digest reduces the release-request load on the IT team.

Logistics and foreign trade

Detecting spoofed domains in supply chain correspondence

In export and shipping processes, bills of lading, customs and payment correspondence are easy to imitate. Domain and sender reputation checks flag messages coming from lookalike domains with a single character changed; outbound scanning, in turn, helps prevent the organization's own domain from being blacklisted.

Managed service provider (MSP)

Email security from a single console in a multi-tenant environment

For providers managing the mailboxes of several customers, consolidating the email layer into the same console as endpoint management lowers the operational load. Policy, quarantine and reporting can be separated per customer; as scale grows, the need to move between separate product consoles disappears.

Who is it for?

Small, medium and mid-to-large organizations running Microsoft 365, Google Workspace or hybrid/on-premises Exchange mail infrastructure and carrying phishing, BEC and invoice fraud risk, as well as multi-tenant managed service providers. Especially IT teams whose endpoint protection is already Bitdefender GravityZone and that want to manage the email layer from the same console.

Frequently Asked Questions

Frequently asked questions

Does deploying GravityZone Email Security require me to change my MX record?
If you use Microsoft 365, no. The API-based model connects to your tenant with secure API access and does not touch mail flow; there is no DNS propagation wait and no risk of interruption. If you choose the Gateway model, the MX record is redirected to Bitdefender and email is filtered before it reaches the mailbox. The two models can also be run together.
Are Google Workspace and on-premises Exchange supported?
In the gateway model, yes. Bitdefender TechZone documentation states that the Gateway deployment supports Microsoft 365, Google Workspace, on-premises Exchange and hybrid environments. API-based mailbox protection, on the other hand, is named on the product page for Microsoft 365 only. If you use Google Workspace, the gateway model is the way forward.
How many filters are applied to each email?
According to Bitdefender's official product page, more than 250 unique filters are applied to every email processed. These filters cover reputation analysis, fingerprinting algorithms, image analysis, authentication checks and machine learning models. The figure is the vendor's official claim and is published on the product page.
How long are quarantined emails retained?
According to Bitdefender TechZone documentation, emails stay in quarantine for 28 days. Users receive an automatic quarantine digest or can view their own messages through the quarantine portal. Detailed email tracking records (Live Email Tracker) are retained for 90 days; this is the record set consulted in post-incident investigations.
What happens if a delivered email later turns out to be malicious?
Post-delivery remediation comes into play. The automatic remediation mechanism keeps monitoring emails for 48 hours after delivery and takes action when the classification changes. The administrator can also trigger the Remediate action directly from the GravityZone console to pull the message back out of the affected mailboxes.
How do users report a suspicious email?
With the Outlook report button. An employee can forward a message they find suspicious, or an email they believe was quarantined by mistake, to the help desk with a single click. This feedback loop makes false positives easy to correct quickly, increases users' trust in the filter and thereby raises the reporting rate for genuine attacks.
Are outbound emails scanned as well?
Yes. Outbound email scanning is a named capability on the product page, and the support documentation describes a separate Outbound Smarthost setup for outbound traffic. Outbound scanning serves two purposes: it limits a compromised account's ability to spread spam from the corporate domain and helps prevent the organization's IP reputation from being blacklisted.
Are SPF and DMARC supported?
Yes, email authentication (SPF and DMARC) is among the capabilities named on the product page. In practice we recommend starting the DMARC policy in monitoring mode, reading the reports and tightening the policy only after you have completed the list of legitimate sending sources; otherwise legitimate marketing or ERP emails may be rejected.
Which GravityZone package includes Email Security?
None of them by default. Bitdefender's official comparison page lists Email Security / Extended Email Security as an add-on licensed separately at every tier — like Patch Management, Full Disk Encryption and Container Security. It needs to be planned as a separate line item in budgeting.
Is it the same as the Exchange protection in Business Security Premium?
No. The Business Security Premium package includes Microsoft Exchange mailbox protection as part of endpoint protection; Email Security, by contrast, is a separate add-on and an independent email security solution operating at the gateway and Microsoft 365 API layers. The two are not mutually exclusive, they are positioned at different points.
Should I choose this instead of Trend Micro Email Security?
What decides it is your existing ecosystem. If your endpoint protection is already Bitdefender, consolidating the email layer into the same console is operationally advantageous. If the organization has invested in Trend Vision One, Trend Micro Email Security is the more natural choice. Sora Yazılım is a channel partner for both brands; we can set up a comparative pilot.
Do I still need Email Security if I already have FortiMail?
It is not mandatory. FortiMail is a mature email security gateway and works in an integrated way with a Fortinet-based network infrastructure. We generally recommend Bitdefender Email Security to organizations whose endpoint protection is Bitdefender and that want single-console management. Layering the two on top of each other makes sense in some scenarios, but false positive management becomes more complex.
Isn't the protection in my Microsoft 365 subscription enough?
It depends on your risk profile. A second and independent engine layer reduces the risk of exposure to a single vendor's detection gap and layers different intelligence sources on top of each other. In addition, correlating email and endpoint incidents in the same console shortens the time lost during incident response. To decide, we review your existing incident history together.
How does pricing work and how long does the rollout take?
The license is determined by the number of mailboxes, the commitment term and the deployment model selected; we do not publish prices on our site. The duration depends on the complexity of your mail infrastructure and your SPF/DMARC readiness. Our standard approach is to begin with a pilot group and widen the scope gradually after monitoring the false positive rate. Share your inventory and we will prepare a quote and a plan.
Vendor's official product page

Opens the vendor's original technical documentation and product page in a new tab.

BitdefenderGravityZone Email Security
Related Services

Services we deliver alongside this product

GravityZone Email Security licensing + deployment + support

Sora Yazılım handles licensing, deployment, training and ongoing management — all from a single team.

WhatsApp Support