Talk to us
by OpenTextTechBag Intel Page

OpenText Core Email Threat Protection

A spoofed CFO, a link that turns bad after delivery, a statement sent in clear text. One email layer should handle all three — OpenText Core Email Threat Protection, formerly Zix and AppRiver email security, filters inbound, outbound and internal mail, retracts delivered threats on Microsoft 365, and pairs with Zix-heritage encryption that DLP rules switch on.

Filter, retract and encryptZix-heritage DLP encryptionQuoted; no India data centre listed

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
OpenText prints no figure; encryption is per user on monthly, annual or multi-year terms
Quote
Catch rate
OpenText’s own data-sheet figure, set beside “extremely low false positives”; test it on your mail
99.9% (claim)
Reviews
The G2 score shown on OpenText’s product page, from only 6 reviews — a thin signal
3.4 / 5
India
No India data centre on the email pages; Continuity names the US, UK and Switzerland
Not listed

Quick answer

OpenText Core Email Threat Protection, formerly the Zix and AppRiver email filter, screens inbound, outbound and, on Microsoft 365, internal mail: links are checked at click, attachments sandboxed and delivered threats retracted. Zix-heritage Core Email Encryption, licensed per user, encrypts by DLP policy. OpenText publishes no price, and its email pages list no India data centre; Continuity offers the US, UK or Switzerland. Read more ↓ Show less ↑
Part 01 · Orient

The OpenText platform family

This page covers OpenText Core Email Threat Protection — email filtering, with Zix-heritage Core Email Encryption folded in. The rest:

OpenText Content Management
Enterprise content management, formerly Extended ECM.
View page →
OpenText Fortify
Application security testing: SAST, DAST and SCA.
View page →
NetIQ Identity Governance
Access reviews, provisioning and identity lifecycle.
View page →
NetIQ Access Manager
Single sign-on, federation and adaptive MFA.
View page →
NetIQ Privileged Access Manager
Privileged session control and credential vaulting.
View page →
OpenText Voltage SecureData
Format-preserving encryption and tokenisation.
View page →
OpenText Enterprise Security Manager
Real-time SIEM correlation, formerly ArcSight.
View page →
OpenText Service Management
ITSM and asset management, formerly SMAX.
View page →
OpenText AI Operations Management
Event and performance monitoring, formerly Operations Bridge.
View page →
OpenText ZENworks
Endpoint management, patching and disk encryption.
View page →
OpenText Data Protector
Enterprise backup for servers, VMs and applications.
View page →
OpenText Availability
Real-time replication and failover, formerly Carbonite.
View page →
OpenText Cloudally Backup
Microsoft 365, Google, Salesforce, Box and Dropbox backup.
View page →
OpenText Performance Engineering
Load and performance testing, formerly LoadRunner.
View page →
OpenText Functional Testing
Automated functional testing, formerly UFT One.
View page →
OpenText Core Endpoint Protection
Cloud endpoint security for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core DNS Protection
DNS filtering for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core Email Threat Protection
This page.
You’re here

Quick facts

30-second orientation
Product
Hosted email filtering for inbound, outbound and internal mail, with Zix-heritage encryption beside it
Maker
Open Text Corporation, Waterloo, Ontario; NASDAQ and TSX: OTEX; CEO Ayman Antoun since April 2026
Lineage
Zix bought AppRiver in February 2019; OpenText bought Zix for about $860M in December 2021
Price
Not published; quoted by OpenText or an MSP partner, with no INR list
Encryption
Core Email Encryption, formerly Zix Secure Email: per user, monthly, annual or multi-year
Detection
Time-of-click link checks, sandboxed attachments, impersonation filtering, a 24/7/365 analyst team
Microsoft 365
Message retraction and internal user-to-user filtering are documented for Microsoft 365
Console
Secure Cloud portal for licences and billing, with Kaseya, Autotask, ConnectWise and HaloPSA links
India
No India data centre listed; the Continuity FAQ offers the US, UK or Switzerland
In India via
TechBag — mailbox count, encryption policy design, quote in INR with GST, cut-over plan
Part 02 · Learn

Understand email threat protection before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is email threat protection?

A hosted filter checks every message for phishing, malware and impostors before and after it reaches the inbox.

Native filtering and encryption by hand vs OpenText Core Email Threat Protection — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNative filtering, encryption by handOpenText Core Email Threat Protection
Sensitive mail leavingStaff must remember to type “secure”DLP rules encrypt or block it automatically
A bad link found laterAsk everyone to delete the mailRetract it from Microsoft 365 inboxes, logged
A colleague’s hijacked boxInternal mail is trusted by defaultUser-to-user mail is filtered too
Clients sending documentsAttachments over plain emailSecure compose through the portal
Mail server outageBounces until it is back30 days of mail via Continuity, if bought
What it is NOT—Google-documented, India-hosted, or list-priced

The cheapest test is a one-domain pilot: route it through the filter, retract a planted test message, and send encrypted mail to an outside inbox.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
How mail reaches the service

Route

Hosted filter in the mail path

Mail passes through OpenText’s hosted filter before your mailboxes; the former AppRiver did this with an MX change, so plan the cut-over and outbound route.

02
How threats are judged

Filter

Multi-layer engine and live analysts

Machine learning, automated traffic analysis and a 24/7/365 analyst team score each message; links are rewritten and attachments opened in a cloud sandbox.

03
What happens to sensitive outbound mail

Encrypt

Core Email Encryption policy engine

DLP filters read subject, body and attachments, then encrypt, quarantine or block; Best Method of Delivery picks TLS, S/MIME or the secure portal per recipient.

04
Where admins and MSPs work

Manage

Secure Cloud portal

One portal handles provisioning, licences, billing and threat views across customers, with dashboards, mobile access and PSA links for Kaseya, Autotask, ConnectWise and HaloPSA.

A hosted filter in the mail path — Zix-heritage encryption on the way out, all run from the Secure Cloud portal.

Part 03 · Evaluate

Nine capabilities. Filter, respond, encrypt.

OpenText Core Email Threat Protection filters mail before and after delivery, and its sister product encrypts what policy says must not leave in clear text.

Filter
Link protection

Links judged when clicked

Links are rewritten and the destination is checked at the moment of the click; users are sent on, warned or blocked.

Filter
Attachments

Sandboxed or disarmed files

Files are opened in a cloud sandbox, or delivered at once as a disarmed copy with macros stripped or converted to PDF.

Filter
Impersonation

Fake bosses and lookalike domains

AI and display-name filtering catch spoofed executives and trusted domains; OpenText includes it in the base offer.

Respond
Retraction

Pull back what got through

Admins remove a malicious message already sitting in Microsoft 365 inboxes, and each retraction is kept in an audit trail.

Respond
Internal mail

Colleague-to-colleague checks

Internal mail filtering on Microsoft 365 scans user-to-user messages, so a hijacked mailbox cannot phish its own team freely.

Respond
Quarantine

Users clear their own held mail

Administrators can give users quarantine reports and access, so release requests stop landing on the helpdesk queue.

Encrypt
DLP policy

Encryption without a button

Core Email Encryption reads subject, body and attachments against DLP rules and templates, then encrypts, quarantines or blocks.

Encrypt
BMOD

Delivery chosen per recipient

Best Method of Delivery sends by TLS, S/MIME or the secure messaging portal, whichever the recipient’s system can handle.

Encrypt
Secure compose

Clients can write in securely

External parties open an encrypted conversation into your company from the secure portal, with no software to install.

See it, don’t just read it

Watch OpenText Core Email Threat Protection in action

Two 2023 IDC fireside chats with OpenText, on email threat protection and on encryption, from the official Webroot channel, and a 2020 tour of the Secure Cloud portal from the former AppRiver channel. All three predate the OpenText Core product names.

Webroot channel (official)·Discussion, January 2023

A Fireside Chat Between IDC and OpenText Security Solutions on Email Threat Protection

An IDC analyst and OpenText discuss email threat protection, recorded in 2023 before the Core product names.

Webroot channel (official)·Discussion, January 2023

A Fireside Chat between IDC and OpenText Security Solutions on Email Encryption

The encryption half of the same 2023 series: policy-driven encryption of the kind Zix built.

AppRiver channel (official)·Overview, April 2020

Zix | AppRiver's Secure cloud

A 2020 tour of the Secure Cloud portal, from the former AppRiver brand, that still manages the service today.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why OpenText Core Email Threat Protection

Filters catch most phishing, not all of it. OpenText adds retraction after delivery and encryption on the way out.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Encryption that comes from the specialist

Zix made its name in policy-based email encryption, now sold as Core Email Encryption. DLP rules decide when a message is encrypted, Best Method of Delivery picks TLS, S/MIME or a portal per recipient, and outsiders can start a secure reply. Few rival filters go that deep.

02

Response after delivery, not only at the gate

Filters miss things. On Microsoft 365 an admin can retract a malicious message already in inboxes, with an audit trail, and internal filtering checks mail between colleagues, where a hijacked account strikes next. A 24/7/365 team of live threat analysts backs the engine.

03

Built for MSPs running many small clients

Secure Cloud handles provisioning, licences, billing and threat views across customers, and links to Kaseya, Autotask, ConnectWise and HaloPSA for billing. Continuity, Message Privacy and awareness training sit in the same portal as separate products, so an MSP can bundle per client.

04

Where it stops

No public price, and G2 shows only 6 reviews. Retraction and internal filtering are documented for Microsoft 365 only; Google Workspace is not named. Encryption, continuity and training are separate purchases. No India data centre is listed, and the newest official videos date from 2023.

The idea
Filter, retract and encrypt from one vendor
The residency
No India data centre listed
The price
Quoted; encryption per user
Proof, not promises

The numbers behind the platform

30 days
of stored inbound mail that Core Email Continuity keeps reachable during an outage
— Vendor
3 routes
Best Method of Delivery chooses from: TLS, S/MIME or the secure messaging portal
— Vendor
100 GB
the largest attachment Core Email Message Privacy will send in a single message
— Vendor
4 PSAs
linked to Secure Cloud for MSP billing: Kaseya, Autotask, ConnectWise and HaloPSA
— Vendor
24/7/365
the hours its live threat analyst team watches traffic and updates the filters
— Vendor
$860M
about what OpenText paid for Zix, cash and debt included, closing December 2021
— Filing

What your OpenText Core Email Threat Protection rollout looks like

Week 1Model

Count mailboxes and senders

List protected mailboxes, the users who send regulated data, and every app or device that relays mail through you.

Week 2Decide

Write the encryption rules

Turn your account numbers, PAN, health or pay data into DLP templates, and decide encrypt, quarantine or block for each.

Week 3Pilot

Pilot one domain

Route a pilot domain through the filter, keep the old path ready, and watch quarantine reports and false positives daily.

Month 2Prove

Test retraction and delivery

Retract a planted test message from Microsoft 365, send encrypted mail to Gmail and a bank, and check each route.

Month 3Commit

Cut over and hand off

Move the remaining domains, give users quarantine access, set disclaimers, and agree who answers encrypted-mail recipients.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

3.8
41+ reviews*
74% would recommend
Phishing and spam catch4.1
Encryption and delivery4.4
Post-delivery response3.9
Console and reporting3.5
Value for money3.6
5★
34%
4★
36%
3★
18%
2★
8%
1★
4%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Loan statements now encrypt themselves when an account number appears; staff stopped forgetting the subject-line keyword.”
Compliance Manager
BFSI
Manufacturing
“A fake vendor-payment mail reached twelve inboxes before a rule caught up. We retracted all twelve in minutes, with the log.”
IT Security Lead
Manufacturing
Healthcare
“Patients reply through the secure portal without installing anything, which mattered more to our clinics than the filtering.”
IT Manager
Healthcare
IT Services
“We run it for 40 small clients from Secure Cloud. Billing syncs to our PSA, but the console still feels like two products joined.”
MSP Service Owner
IT Services
Media
“The PDF conversion of attachments annoyed our design team until we set exceptions for trusted senders.”
Systems Administrator
Media
Logistics
“Ask early where mail is stored. We got US, UK or Switzerland for continuity and had to explain that to our auditors.”
Head of IT
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the email security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Email Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
OpenText Core Email Threat ProtectionThis page

Quoted; encryption licensed per user on its own.

Grid 02 · The architecture

Outbound Control × MSP Operations

The grid nobody publishes — how far each product controls mail leaving the company, encryption and delivery included, vs how well it serves an MSP running many clients.

MSP filters, inbound-firstMSP suites with encryptionSingle-org inbound layersEncryption-led platforms
OpenText Core Email Threat ProtectionThis page

DLP encryption, three delivery routes; PSA-linked portal.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

OpenText Core Email Threat Protection vs the email security field

Against Proofpoint Email Protection, Mimecast Email Security, Barracuda Email Protection, N-able Mail Assure and INKY Email Security — on deployment, platforms, encryption, price, MSP tooling and India.

DimensionOpenText Core Email Threat ProtectionProofpoint Email ProtectionMimecast Email SecurityBarracuda Email ProtectionN-able Mail AssureINKY Email Security
What it isHosted filter + ZixGateway, intel-ledGateway or API flagshipTiered email suiteMSP filter + archiveInline banner security
DeploymentHosted, in the mail pathMX gateway or APIMX or Microsoft 365 APIMX, API, or bothMX gatewayConnectors, MX stays
Mail platformsM365 named; Google notAny host via MXAny host; API for M365Any host; API for M365Any host by MXM365 and Google
Detection approachML + live analystsThreat intel + AIAI/ML, all directionsGateway + API learningPooled intelligenceVision + profiling
Awareness trainingSeparate Core SKUSeparate SKUMimecast Aware SKUIn higher tiersNone listedBanners teach in-line
Pricing modelPer user, by productPer user, by packagePer user, S1–S3Per user, by tierQuote, per clientPer licence, quoted
Published entry priceNot published$2–5.86/user/month~$5–15/user/mo reported$3–12/user/monthNot publishedNot published
Included vs add-onEncryption is separateExtras add upBundles plus add-onsTier-gated modulesArchive + continuity inPro adds the extras
Outbound and encryptionDLP, BMOD, portalFrom Essentials AdvancedSecure Messaging add-onPolicy encryptionTLS, no portalPro only
Admin and multi-tenancySecure Cloud + PSAsChannel or in-houseOwn admin consoleMSP-friendlyOne console, all clientsMulti-tenant dashboard
India data regionNone listedMumbai data centreSingapore for APACNo India DC recordedNot on recordNone published
SupportIncluded, US deskPartner, then vendorTerms in contractPartner-ledN-able and partnersKaseya, 24/7
Lock-in and exitMX and portal to undoMX cut-backArchive is stickyMX and API to undoArchive to migrateDelete the rules
Best fitEncrypt-heavy SMBsRegulated enterprisesGateway + archive buyersValue suite + trainingN-able MSPsKaseya MSPs
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose OpenText Core Email Threat Protection if…

  • ✓You send regulated data by email and want DLP-driven encryption, per-recipient delivery and a secure reply portal from the filter’s own vendor
  • ✓You run Microsoft 365 and want to retract delivered threats and filter mail between colleagues, with an audit trail
  • ✓You are an MSP that wants filtering, encryption, continuity and training provisioned and billed from one portal with PSA links

Compare alternatives if…

  • ✓Mail must be stored in India — Proofpoint has announced a Mumbai data centre; OpenText lists none
  • ✓You want a published per-user price before a sales call — Proofpoint Essentials and Barracuda print theirs
  • ✓You run Google Workspace or want no MX change — INKY documents both Google and connector-based routing

Do not expect…

  • ✓A public price list, in USD or INR
  • ✓Documented Google Workspace support for retraction or internal filtering
  • ✓Encryption, continuity or awareness training inside the filtering licence

OpenText Core Email Threat Protection is one of 30 email security products TechBag carries. The Email Security guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does handling email threats by hand cost you?

Drag the sliders (mailboxes protected; admin-hour cost). Estimates model IT time spent clearing phishing that got through, releasing quarantined mail and encrypting sensitive messages by hand, at an assumed 1.5 hours per mailbox a year, with 70% of it removed by retraction, user self-service quarantine and policy-driven encryption. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual email-handling cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. OpenText prints no figure for Core Email Threat Protection. Core Email Encryption, the Zix-heritage companion, is licensed per user on monthly, annual or multi-year subscriptions, with support and maintenance in the fee; Continuity, Message Privacy and awareness training are separate products. TechBag counts mailboxes and encryption users first, then quotes in INR with GST.

Core Email Threat Protection

Best for Microsoft 365 firms and the MSPs that run them

  • Quoted; no public figure
  • Impersonation protection in the base offer
  • Core Advanced edition also named

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Core Email Encryption

Best for teams emailing regulated data

  • Per user: monthly, annual or multi-year
  • Support and maintenance included
  • DLP rules, TLS, S/MIME or portal delivery

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Mail platform

Is every domain on Microsoft 365? Retraction and internal filtering are documented for it, not for Google Workspace.

2
Mail routing

How will mail reach the filter, and what is the rollback if the cut-over misroutes inbound or outbound mail?

3
Encryption scope

Which data types must trigger encryption, and do you need Core Email Encryption as well as the filter?

4
Recipients

Will clients and regulators accept TLS, S/MIME or a portal login, and who supports them when they cannot open a message?

5
Data location

Where are filtered mail, quarantine and continuity copies stored? Get the region in writing for DPDP review.

6
Edition

Which features sit in Core versus Core Advanced Email Threat Protection? OpenText does not publish the split.

7
Add-ons

Do you need Continuity, Message Privacy or awareness training? Each is a separate product with its own licence.

8
Contract

Does the quote state the licence unit, term, support hours and roadmap commitments? Ask for INR with GST.

FAQ

Questions buyers ask

It is OpenText’s hosted email filter, formerly sold as Zix and AppRiver email security. It screens inbound, outbound and, on Microsoft 365, internal mail for phishing, ransomware, impersonation and spam, rewrites links for click-time checks, sandboxes attachments and can retract delivered threats.

Ready to evaluate OpenText Core Email Threat Protection?

Count mailboxes and the users who email regulated data first, or let a TechBag advisor map your DLP rules, plan the routing cut-over and get the quote in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.