The only email gateway that clusters active-active without a master.
Self-hosted. Open-source stack. GDPR by architecture. NetCell MailGuard places itself in front of your existing mail server via MX record — spam, phishing and malware are filtered locally on your servers. No cloud, no US third parties, no data export.
apt install -y curl)Cloud dependencies — everything runs on your own servers
Cluster nodes — no quorum, no master/replica
Detection layers — from DNSBL to attachment sandbox
by architecture — made in Germany, no data export
GDPR by architecture — no compliance acrobatics required.
Cloud providers like Mimecast, Proofpoint and Hornetsecurity route every email through third-party infrastructure. For law firms, tax advisors, hospitals, public authorities and anyone under strict GDPR/BDSG supervision, that means a compliance nightmare. NetCell MailGuard runs on your server, in your data centre — the mail never leaves your infrastructure.
No data-processing agreement
You are the processor — nothing goes to third parties. GDPR Art. 28 DPA is not required at all.
No third-country transfer
All components stay in the EU/EEA — no Schrems II risk, no standard contractual clauses needed.
Complete audit log
Every admin action, every quarantine release, every policy change with timestamp and actor — mandatory evidence for Art. 5 (1) f.
Vendor based in Germany
NetCell IT, Leverkusen — German support, German contracts, no US Cloud Act access.
Eight features that set us apart.
Every vendor offers SPF/DKIM/DMARC. These eight points are our real differentiators.
Active-active without a master
Every cluster node is an equal peer — no failover, no promote, no quorum. Configuration and state are encrypted and synchronised across all nodes. Scales horizontally without limit.
More →GDPR by architecture
Self-hosted, no data export, no cloud provider between sender and recipient. No DPA, no third-country clauses. Law firms, tax advisors, public authorities and hospitals are the target audience.
More →Local attachment sandbox
Suspicious Office, PDF and archive attachments are detonated in an isolated sandbox on your server — not shipped to a cloud sandbox vendor. Operator-managed detection rules.
More →DACH-phishing detection
Patterns for German-speaking phishing waves: account-locked, tax refund, GEZ, Klarna, DHL parcel, Apple ID. English-trained cloud models often miss these.
More →End-user quarantine portal
Recipients receive a daily digest with single-click release. No admin involvement for false positives, no „can you release this mail" tickets. Token-based, secure.
More →White-label branding
Your logo, your product name, your digest subjects as a global cluster identity. Resellers sell MailGuard under their own brand — end customers don't see „NetCell MailGuard".
More →API-first with OpenAPI
Every UI function is also available via REST API. API keys with scope and rate limit, OpenAPI spec as a versioned contract, webhook hooks for quarantine and reputation events.
More →Per-domain policies
Quarantine threshold, detection policy, DKIM keys, DMARC reporting, mail filter lists, header rewrites — all configurable per domain. One operator team manages all domains from one UI.
More →Detonation on your server, not in someone else's cloud.
Suspicious Office documents, PDFs and archives are executed in an isolated YARA sandbox on your server — we observe their behaviour rather than just matching signatures. Cloud vendors upload every attachment to their own infrastructure; here the file never leaves your data centre.
Behaviour detection
Auto-execute macros, PowerShell invocations, embedded executables in PDFs, JavaScript heap-spray — observed inside the sandbox, not just signature-matched.
Nested archives
Password-protected ZIPs (with the password in the mail body!), ZIP bombs, multi-stage nested containers — unpacked and each stage detonated individually.
Operator-managed YARA rules
Write your own .yar rules for fresh threats without waiting for a cloud vendor's update window. CVE patterns, malware families, your own IoC lists.
Verdict feeds back into rspamd
Detonation result (clean/suspicious/virus/phish) flows back into the rspamd pipeline as a ThreatScore boost — quarantined or rejected by the same policy as every other detection layer.
Every node is master.
No failover drama on hardware failure. No promote script. No split-brain prevention. Every node processes incoming mail, every node replicates configuration changes to all others, every node can join or leave at any time.
┌──────────────┐ encrypted ┌──────────────┐
│ MailGuard │ ◀──────────────▶│ MailGuard │
│ Node 1 │ sync │ Node 2 │
│ │ │ │
│ Detection │ │ Detection │
│ stack │ ◀──────────────▶│ stack │
│ + sandbox │ │ + sandbox │
└──────┬───────┘ └──────┬───────┘
│ │
└────── MX round-robin ──────────┘
│
▼
Existing mail server
(Linux MTA / Exchange / Microsoft 365 / Google Workspace)
Free or Pro. You scale with us.
Free covers 1 domain forever — with all detection features. Pro scales with your setup: starting at EUR 29/month (10 domains, 1 server). Domain and cluster count are your choice. Cloud email security vendors (Hornetsecurity, Mimecast, Proofpoint, Microsoft Defender for O365) charge EUR 1,000-2,500/month for the equivalent volume.
Free
Single-domain protection, free forever
- 1 domain · 1 server
- All 14 detection layers + sandbox
- Threat feeds + DACH-phishing keywords
- DKIM/DMARC + audit log + GDPR tools
- No cluster, no portal, no white-label
Pro RECOMMENDED
Domain and cluster size selectable — entry 10 domains, 1 server
- Domain count selectable (10/25/50/100/250)
- Cluster nodes selectable (1-10, +EUR 10/node)
- Everything from Free + reporting + end-user portal
- + White-label branding + REST API (full)
- + Email support < 48 h
Custom
Resellers, enterprise, custom contracts
- 250+ domains or 10+ nodes
- SLA + phone support + account manager
- On-premise perpetual license
- Reseller contracts (multi-cluster)
- SIEM integration + audit-log export
Initial install runs 30 days automatically in trial mode with full Pro feature set — then activate Free or buy Pro. See full pricing matrix →
Frequently asked questions
How does MailGuard differ from Hornetsecurity or Mimecast?
How does active-active without a master work?
Do I need a cloud connection?
Which detection layers are active?
Can I resell MailGuard?
How does the licensing model work?
Ready for your own server instead of cloud?
Install NetCell MailGuard on your own server. 30 days free, then EUR 29 per server — no credit card required for the trial.