A spoofed CFO, a link that turns bad after delivery, a statement sent in clear text. One email layer should handle all three — OpenText Core Email Threat Protection, formerly Zix and AppRiver email security, filters inbound, outbound and internal mail, retracts delivered threats on Microsoft 365, and pairs with Zix-heritage encryption that DLP rules switch on.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers OpenText Core Email Threat Protection — email filtering, with Zix-heritage Core Email Encryption folded in. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A hosted filter checks every message for phishing, malware and impostors before and after it reaches the inbox.
What consolidation actually replaces, dimension by dimension.
| Dimension | Native filtering, encryption by hand | OpenText Core Email Threat Protection |
|---|---|---|
| Sensitive mail leaving | Staff must remember to type “secure” | DLP rules encrypt or block it automatically |
| A bad link found later | Ask everyone to delete the mail | Retract it from Microsoft 365 inboxes, logged |
| A colleague’s hijacked box | Internal mail is trusted by default | User-to-user mail is filtered too |
| Clients sending documents | Attachments over plain email | Secure compose through the portal |
| Mail server outage | Bounces until it is back | 30 days of mail via Continuity, if bought |
| What it is NOT | — | Google-documented, India-hosted, or list-priced |
The cheapest test is a one-domain pilot: route it through the filter, retract a planted test message, and send encrypted mail to an outside inbox.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Mail passes through OpenText’s hosted filter before your mailboxes; the former AppRiver did this with an MX change, so plan the cut-over and outbound route.
Machine learning, automated traffic analysis and a 24/7/365 analyst team score each message; links are rewritten and attachments opened in a cloud sandbox.
DLP filters read subject, body and attachments, then encrypt, quarantine or block; Best Method of Delivery picks TLS, S/MIME or the secure portal per recipient.
One portal handles provisioning, licences, billing and threat views across customers, with dashboards, mobile access and PSA links for Kaseya, Autotask, ConnectWise and HaloPSA.
A hosted filter in the mail path — Zix-heritage encryption on the way out, all run from the Secure Cloud portal.
OpenText Core Email Threat Protection filters mail before and after delivery, and its sister product encrypts what policy says must not leave in clear text.
Links are rewritten and the destination is checked at the moment of the click; users are sent on, warned or blocked.
Files are opened in a cloud sandbox, or delivered at once as a disarmed copy with macros stripped or converted to PDF.
AI and display-name filtering catch spoofed executives and trusted domains; OpenText includes it in the base offer.
Admins remove a malicious message already sitting in Microsoft 365 inboxes, and each retraction is kept in an audit trail.
Internal mail filtering on Microsoft 365 scans user-to-user messages, so a hijacked mailbox cannot phish its own team freely.
Administrators can give users quarantine reports and access, so release requests stop landing on the helpdesk queue.
Core Email Encryption reads subject, body and attachments against DLP rules and templates, then encrypts, quarantines or blocks.
Best Method of Delivery sends by TLS, S/MIME or the secure messaging portal, whichever the recipient’s system can handle.
External parties open an encrypted conversation into your company from the secure portal, with no software to install.
Two 2023 IDC fireside chats with OpenText, on email threat protection and on encryption, from the official Webroot channel, and a 2020 tour of the Secure Cloud portal from the former AppRiver channel. All three predate the OpenText Core product names.
An IDC analyst and OpenText discuss email threat protection, recorded in 2023 before the Core product names.
The encryption half of the same 2023 series: policy-driven encryption of the kind Zix built.
A 2020 tour of the Secure Cloud portal, from the former AppRiver brand, that still manages the service today.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Zix made its name in policy-based email encryption, now sold as Core Email Encryption. DLP rules decide when a message is encrypted, Best Method of Delivery picks TLS, S/MIME or a portal per recipient, and outsiders can start a secure reply. Few rival filters go that deep.
Filters miss things. On Microsoft 365 an admin can retract a malicious message already in inboxes, with an audit trail, and internal filtering checks mail between colleagues, where a hijacked account strikes next. A 24/7/365 team of live threat analysts backs the engine.
Secure Cloud handles provisioning, licences, billing and threat views across customers, and links to Kaseya, Autotask, ConnectWise and HaloPSA for billing. Continuity, Message Privacy and awareness training sit in the same portal as separate products, so an MSP can bundle per client.
No public price, and G2 shows only 6 reviews. Retraction and internal filtering are documented for Microsoft 365 only; Google Workspace is not named. Encryption, continuity and training are separate purchases. No India data centre is listed, and the newest official videos date from 2023.
List protected mailboxes, the users who send regulated data, and every app or device that relays mail through you.
Turn your account numbers, PAN, health or pay data into DLP templates, and decide encrypt, quarantine or block for each.
Route a pilot domain through the filter, keep the old path ready, and watch quarantine reports and false positives daily.
Retract a planted test message from Microsoft 365, send encrypted mail to Gmail and a bank, and check each route.
Move the remaining domains, give users quarantine access, set disclaimers, and agree who answers encrypted-mail recipients.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Loan statements now encrypt themselves when an account number appears; staff stopped forgetting the subject-line keyword.”
“A fake vendor-payment mail reached twelve inboxes before a rule caught up. We retracted all twelve in minutes, with the log.”
“Patients reply through the secure portal without installing anything, which mattered more to our clinics than the filtering.”
“We run it for 40 small clients from Secure Cloud. Billing syncs to our PSA, but the console still feels like two products joined.”
“The PDF conversion of attachments annoyed our design team until we set exceptions for trusted senders.”
“Ask early where mail is stored. We got US, UK or Switzerland for continuity and had to explain that to our auditors.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the email security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted; encryption licensed per user on its own.
The grid nobody publishes — how far each product controls mail leaving the company, encryption and delivery included, vs how well it serves an MSP running many clients.
DLP encryption, three delivery routes; PSA-linked portal.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Proofpoint Email Protection, Mimecast Email Security, Barracuda Email Protection, N-able Mail Assure and INKY Email Security — on deployment, platforms, encryption, price, MSP tooling and India.
| Dimension | OpenText Core Email Threat Protection | Proofpoint Email Protection | Mimecast Email Security | Barracuda Email Protection | N-able Mail Assure | INKY Email Security |
|---|---|---|---|---|---|---|
| What it is | Hosted filter + Zix | Gateway, intel-led | Gateway or API flagship | Tiered email suite | MSP filter + archive | Inline banner security |
| Deployment | Hosted, in the mail path | MX gateway or API | MX or Microsoft 365 API | MX, API, or both | MX gateway | Connectors, MX stays |
| Mail platforms | M365 named; Google not | Any host via MX | Any host; API for M365 | Any host; API for M365 | Any host by MX | M365 and Google |
| Detection approach | ML + live analysts | Threat intel + AI | AI/ML, all directions | Gateway + API learning | Pooled intelligence | Vision + profiling |
| Awareness training | Separate Core SKU | Separate SKU | Mimecast Aware SKU | In higher tiers | None listed | Banners teach in-line |
| Pricing model | Per user, by product | Per user, by package | Per user, S1–S3 | Per user, by tier | Quote, per client | Per licence, quoted |
| Published entry price | Not published | $2–5.86/user/month | ~$5–15/user/mo reported | $3–12/user/month | Not published | Not published |
| Included vs add-on | Encryption is separate | Extras add up | Bundles plus add-ons | Tier-gated modules | Archive + continuity in | Pro adds the extras |
| Outbound and encryption | DLP, BMOD, portal | From Essentials Advanced | Secure Messaging add-on | Policy encryption | TLS, no portal | Pro only |
| Admin and multi-tenancy | Secure Cloud + PSAs | Channel or in-house | Own admin console | MSP-friendly | One console, all clients | Multi-tenant dashboard |
| India data region | None listed | Mumbai data centre | Singapore for APAC | No India DC recorded | Not on record | None published |
| Support | Included, US desk | Partner, then vendor | Terms in contract | Partner-led | N-able and partners | Kaseya, 24/7 |
| Lock-in and exit | MX and portal to undo | MX cut-back | Archive is sticky | MX and API to undo | Archive to migrate | Delete the rules |
| Best fit | Encrypt-heavy SMBs | Regulated enterprises | Gateway + archive buyers | Value suite + training | N-able MSPs | Kaseya MSPs |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
OpenText Core Email Threat Protection is one of 30 email security products TechBag carries. The Email Security guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (mailboxes protected; admin-hour cost). Estimates model IT time spent clearing phishing that got through, releasing quarantined mail and encrypting sensitive messages by hand, at an assumed 1.5 hours per mailbox a year, with 70% of it removed by retraction, user self-service quarantine and policy-driven encryption. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. OpenText prints no figure for Core Email Threat Protection. Core Email Encryption, the Zix-heritage companion, is licensed per user on monthly, annual or multi-year subscriptions, with support and maintenance in the fee; Continuity, Message Privacy and awareness training are separate products. TechBag counts mailboxes and encryption users first, then quotes in INR with GST.
Best for Microsoft 365 firms and the MSPs that run them
Best for a broader rollout
Best for teams emailing regulated data
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is every domain on Microsoft 365? Retraction and internal filtering are documented for it, not for Google Workspace.
How will mail reach the filter, and what is the rollback if the cut-over misroutes inbound or outbound mail?
Which data types must trigger encryption, and do you need Core Email Encryption as well as the filter?
Will clients and regulators accept TLS, S/MIME or a portal login, and who supports them when they cannot open a message?
Where are filtered mail, quarantine and continuity copies stored? Get the region in writing for DPDP review.
Which features sit in Core versus Core Advanced Email Threat Protection? OpenText does not publish the split.
Do you need Continuity, Message Privacy or awareness training? Each is a separate product with its own licence.
Does the quote state the licence unit, term, support hours and roadmap commitments? Ask for INR with GST.
Count mailboxes and the users who email regulated data first, or let a TechBag advisor map your DLP rules, plan the routing cut-over and get the quote in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.