ZoTrus Email Encryption Automation Gateway

Automatically and Transparently Encrypt and Decrypt Every Email

Email is transmitted and stored in plain text, which means every message, while in transit and on the server, is vulnerable to interception, tampering, and exploitation. Email fraud, ransomware, and Business Email Compromise (BEC) are rampant, making enterprise email security a critical concern.

ZoTrus Email Encryption Automation Gateway is a plug and play hardware appliance. It automatically provides S/MIME end to end encryption and digital signing for every email, without requiring employees to change their email client or alter any of their habits. Senders compose and send as usual; recipients read as usual, encryption happens automatically within the gateway.

I. The Three Major Challenges of Email Encryption

Email encryption is nothing new, yet it has never achieved widespread adoption. Why?

Challenge 1: Traditional S/MIME Is Too Complex

Applying for certificates, configuring clients, managing keys, renewing certificates regularly... this entire process is enough to discourage 99.99% of enterprises. Employees don't understand what certificates are, and IT departments are overwhelmed by certificate expiration alerts. Email encryption becomes an "impossible mission."

Challenge 2: Proprietary Solutions Are Too Closed

Encrypted mailboxes require switching email providers; encrypted clients require switching software, employees resist, and IT struggles to enforce adoption. With proprietary protocol systems, recipients must use the same system, turning email encryption into "encryption among ourselves", while communications with external clients and partners remain exposed.

Challenge 3: Webmail Cannot Be Encrypted

Webmail does not support S/MIME, yet many employees are accustomed to sending and receiving emails via browsers. This traffic remains a security blind spot, even though messages are protected by TLS in transit, they are still stored in plaintext on the server.

ZoTrus Email Encryption Automation Gateway solves all three challenges at once.

II. The Solution: Gateway Automated Encryption, Transparent to Users

The following diagram illustrates how the ZoTrus Email Encryption Automation Gateway works. Let's walk through the entire encryption process using Alice and Bob, both of whom have deployed the Gateway.

Gateway
  • Alice continues using her usual email client (e.g., Outlook), composing and sending emails as normal. The plaintext email is sent via a TLS encrypted channel to the Email Encryption Automation Gateway, the message does not go directly to Alice's mail server, but passes through the gateway first.
  • The gateway automatically encrypts the email using the recipient Bob's public key. Once the email becomes ciphertext, it is sent via a TLS encrypted channel to Alice's mail server.
  • Alice's email is stored in ciphertext in Alice's mail server. Alice's mail server then connects to Bob's mail server. Regardless of whether Bob's mail server supports TLS encryption, the email is transmitted in ciphertext and stored in ciphertext in Bob's mail server.
  • The gateway deployed at Bob's end retrieves the encrypted email from Bob's mail server in response to Bob's retrieval request, and decrypts it using Bob's private key back to plaintext.
  • Bob receives the decrypted email via a TLS encrypted channel and views the plaintext message using his usual email client.

Throughout this entire process, neither Alice nor Bob performs any additional operations, Alice writes and sends plaintext, and the gateway automatically encrypts it; Bob receives ciphertext and reads plaintext, with the gateway automatically decrypting it. If either of them logs into their mail server via webmail, they will see that the email is indeed stored in ciphertext in both mail servers.

Full Lifecycle Security: The email is protected by ciphertext throughout its entire lifecycle, from creation to transmission, storage, and reading.

Seamless Compatibility, Open Interoperability: If Bob's organization has not deployed the Gateway but Bob has already configured his own S/MIME certificate in Outlook, he can still retrieve the ciphertext email directly from his mail server, and Outlook will decrypt it using his certificate. Because the Email Encryption Automation Gateway adopts the S/MIME international standard, it is fully compatible and interoperable with all S/MIME compliant email clients (Outlook, Thunderbird, Apple Mail, etc.) and other encryption systems. This is not a closed proprietary protocol system, but an open, standards based encryption platform.

When automatically requesting email certificates, the gateway generates the user's certificate private key and CSR locally. All private keys are managed within the Gateway securely locally; the cloud is only used for the certificate request process. To ensure private key security, it is strongly recommended deploying the ZoTrus Enterprise Key Management System (EKMS) alongside the Gateway, a dedicated key management appliance securely deployed within the internal network to centrally manage all employees' keys, including all historical keys.

III. Three Core Advantages

Advantage 1: Transparent Encryption — No Change to User Habits

Not changing user habits is crucial. This not only enables rapid deployment of email encryption without overburdening IT operations, but also ensures that employees' daily work is not disrupted by encryption upgrades. Email encryption has failed to achieve widespread adoption precisely because previous solutions required employees to change their habits and learn new tools.

Scenario: A company with 2,000 employees uses both Outlook and webmail to send and receive emails. After deploying Gateway, IT admin only needs to change the SMTP/IMAP domain resolution to the Gateway IP address, employees take no action, and all emails are automatically encrypted.

The gateway takes over the encryption work that was previously handled by the email client, doing it automatically in the background. Users do not need to install new client software or learn new tools, encryption runs transparently in the background.

The gateway delivers transparent email encryption, removing all barriers to email encryption upgrades and ensuring full lifecycle security for emails, from creation, sending, and reading to storage.

Advantage 2: S/MIME Standard — Global Interoperability

ZoTrus Email Encryption Automation Gateway uses the mature S/MIME international standard for email encryption and digital signing, and employs globally trusted email certificates. Other S/MIME compliant email clients (such as Outlook, Thunderbird, and Apple Mail) will automatically display the digital signature as trusted and automatically decrypt encrypted emails.

The Gateway does not require recipients to use the same system, as long as the recipient has an email certificate and uses an S/MIME compliant email client (whether Outlook or ZTmail), they can automatically decrypt received encrypted emails. This is an open encryption system, not a closed proprietary protocol silo.

Advantage 3: DLP + AI Dual Engine Protection

ZoTrus Email Encryption Automation Gateway includes a built in Data Loss Prevention (DLP) function that performs real time content inspection on every outbound email:

Inspection Dimension
Description
Multi dimensional Content Inspection
Supports multiple detection conditions including keywords, regular expressions, file fingerprints, data identifiers, and file attributes, performing deep content awareness on email body, subject line, and attachments (including PDFs, Office documents, etc.)
Flexible Disposition Policies
Administrators can configure multiple disposition actions: direct blocking and interception, pop up alerts notifying the sender, forwarding to an approval queue for administrator review, or forwarding the email to designated administrators or monitoring personnel
Audit and Traceability
The backend provides complete auditing of outbound and intercepted emails; administrators can manually whitelist and release intercepted emails
Monitoring Notifications
Supports real time forwarding of policy triggering emails to monitoring personnel, either as original messages or as attachments

ZoTrus Email Encryption Automation Gateway also integrates an AI Intelligent Detection Engine. Like ZTmail, users can bring their own API keys and freely choose AI models for intelligent security analysis of email content for both inbound and outbound traffic, using the same disposition rules as the DLP function to manage suspicious incoming and outgoing emails. The AI engine detects the following types of threats and anomalies:

AI Detection Capability
Description
Smart Spam Identification
AI automatically analyzes email content features to accurately distinguish between legitimate emails and spam, significantly reducing false positive rates
Deep Phishing Detection
AI automatically detects phishing indicators such as malicious links, forged senders, and social engineering tactics, providing proactive alerts
BEC (Business Email Compromise) Detection
AI analyzes email context, sender behavior patterns, and language style to identify BEC attacks such as executive impersonation, fake invoices, and urgent wire transfer requests
Anomalous Behavior Alerting
AI automatically detects anomalies in email headers, content, and sending time patterns, triggering alerts when deviations from normal behavior are identified
Outbound Content & Behavioral Analysis
AI analyzes outbound email content for sensitive data leakage (e.g., intellectual property, financial data, personally identifiable information), and detects anomalous sending behaviors such as unusual attachment types, abnormal sending frequencies, large volume data transfers, and non standard communication patterns — automatically blocking or alerting based on pre configured policies to prevent data exfiltration

"Identity Verification + AI Detection" Dual Protection

ZoTrus Email Encryption Automation Gateway features an industry first "Identity Verification + AI Detection" dual protection mechanism, managing both inbound and outbound traffic: proactively blocking phishing and fraud threats on inbound emails, while detecting and preventing data leakage on outbound emails in real time. Together, they provide comprehensive, zero gap security for email — leaving phishing and fraudulent emails with nowhere to hide, and making data exfiltration impossible.

  • Identity Verification (Proactive): Every inbound email undergoes sender identity verification. For digitally signed emails: after verifying the signature's trustworthiness and validity, the gateway can either pass them through based on preset rules, or only pass emails with T2/T3/T4 authentication levels. For emails without digital signatures: the gateway proactively adds "No digital signature, identity not verified — proceed with caution" to the subject line to alert the recipient.
  • AI Detection (Reactive): Proactively detects fraud risks and anomalous behaviors on inbound emails; simultaneously analyzes outbound email content and sending behavior to identify data leakage risks. Leaves no threat hidden, automatically acting based on pre configured rules or at the administrator's discretion.

IV. Use Cases

Use Case
Description
Government Agencies
Meet Classified Protection and Cryptographic Compliance Requirements, protect official email communications
Financial Institutions
Protect sensitive customer information and transaction data, defend against BEC fraud
Manufacturing
Protect trade secrets including design blueprints and supply chain communications
Healthcare
Protect patient privacy and medical data
Education
Protect research outputs and personal information of faculty and students
Any Mid to Large Enterprise with Email Security Needs
Fully automated, transparent email encryption protection

V. Deployment Options & Technical Specifications

Deployment Options

Option
Description
On Premises Hardware
2U rack mount appliance deployed at the enterprise network perimeter; dual unit high availability deployment recommended
Cloud Deployment
Deployed in public cloud or private cloud environments
Key Management
Optional ZoTrus Enterprise Key Management System (EKMS), a dedicated appliance deployed within the internal network to centrally manage employee keys

Technical Specifications

Item
Specification
Form Factor
2U rack mount hardware
Deployment Location
Enterprise network perimeter or cloud data center
Supported Algorithms
RSA / SM2 dual algorithm
Compatible Clients
Outlook, Thunderbird, Apple Mail and others
Key Management
Local private key generation; optional EKMS
Encryption Standards
S/MIME standard

Model Selection

The Gateway is available in different performance tiers based on CPU processing power. Customers can choose the appropriate model according to the number of email users and email volume. For specific model recommendations, please contact our sales team.

VI. Why Choose the ZoTrus Email Encryption Automation Gateway?

ZoTrus Email Encryption Automation Gateway fundamentally changes the traditional notion that "email encryption requires a dedicated email client." With a gateway based approach, the email client users choose is irrelevant, what users need is for their emails to be encrypted in transit and at rest using appropriate cryptographic algorithms. What users do not need is to abandon their familiar email client just for encryption.

This is an innovative email security practice.

Make Every Email Automatically Encrypted, Make Every Email Communication Truly Secure.

ZoTrus Email Encryption Automation Gateway has been successfully deployed across government, finance, manufacturing, and other industries.

Contact us today for a customized deployment plan.