---
title: How to Block Executable Files in SecurityGateway™ for Email
description: How to block executable file attachments in SecurityGateway for Email, including files hidden inside ZIP and ISO archives, with reject or quarantine rules.
image: https://blog.mdaemon.com/hubfs/How%20to%20Block%20or%20Quarantine%20executable%20Attachments-TN.png
---

[![MDaemon Technologies](https://blog.mdaemon.com/hs-fs/hubfs/MDaemon-Technologies_logo_large.png?width=564&height=110&name=MDaemon-Technologies_logo_large.png "MDaemon Technologies")](https://mdaemon.com/)

- [Blog Home](https://blog.mdaemon.com)

# MDaemon Technologies Blog

## [How to Block Executable Files in SecurityGateway™ for Email](https://blog.mdaemon.com/how-to-block-executable-files-in-securitygateway-for-email)

 By [Brad Wyro](https://blog.mdaemon.com/author/brad-wyro)

- [Tweet](https://twitter.com/share)

Malware only needs one click to do considerable damage to your business. That click is still most often triggered the same way it always has been: a hyperlink to a spoofed login page, a Word or Excel file carrying a malicious macro, unpatched software, or a plain old file attachment paired with a convincing social engineering pitch (“invoice attached,” “please review,” “your delivery couldn't be completed”).

What has changed is how attackers get executables past the mail filter. Because most secure email gateways, SecurityGateway included, now block obviously dangerous file types by default, attackers have adapted their delivery methods rather than abandoning executables altogether:

- **Archive smuggling:** the payload is zipped or packed into a password-protected ZIP, RAR, or ISO/IMG disk-image file so a gateway can't “see” what's inside without unpacking it.
- **HTML smuggling:** an innocuous-looking HTML attachment reconstructs the malicious archive locally, inside the victim's browser, only after it's already past the gateway.
- **Double extensions and disguised filenames:** files like invoice\_march.pdf.exe or a trailing-space trick are designed to look safe at a glance.
- **Off-attachment delivery:** QR codes (which SecurityGateway can block) and callback-phishing lures point the recipient toward a payload hosted somewhere else entirely, skipping the attachment scan altogether. 

So the takeaway for administrators is that executable attachments are just as dangerous as they've ever been. Attackers have simply gotten better at hiding them. Blocking or quarantining executable file types at the gateway remains one of the most beneficial controls you can put in place, as it keeps them away from your mail server, and thus away from your users. It just needs to account for executables nested inside archives, not only the ones sitting in plain sight.

To help protect your business, SecurityGateway for Email can reject or quarantine incoming messages containing executable files. Watch our tutorial video below to see it configured step by step.

## **Setting up executable file protection**

To configure executable protection in SecurityGateway:

1. **Define what counts as “executable” for your organization.** The standard list includes .exe, .scr, .bat, .cmd, .com, .pif, .msi, .js, .vbs, .ps1, .jar, and .lnk. Extend or trim it to match your risk tolerance.
2. **Choose reject or quarantine.** Rejecting stops the message outright; quarantining holds it for admin review, which is useful if your organization occasionally needs to receive legitimate executables (e.g., internal software distribution) after inspection.
3. **Layer it with SecurityGateway's other protections:** multi-engine attachment scanning, Office macro screening, and Zero-Hour™ Outbreak Protection, so a file that slips past one check still gets caught by another.

These settings can be found under SecurityGateway's content filtering rules.

## **Why attachment filtering is so important**

When attackers do rely on attachments, a disguised or archive-nested executable remains one of the most reliable ways to get a payload to actually run on a victim's machine. A malicious link can be clicked and abandoned, but a downloaded file that gets double-clicked executes immediately. At the same time, more attackers are shifting toward URL-based delivery (and SecurityGateway’s [URIBL feature](https://help.mdaemon.com/SecurityGateway/en/uri_blocklists_uribl.html) can block these) precisely because attachment filtering has gotten good enough to make file-based payloads a harder sell. That's a sign the control is working, not a reason to loosen it.

SecurityGateway combines executable and attachment filtering with broader protection: data leak prevention (DLP), full SPF/DKIM/DMARC/ARC enforcement, Dynamic Screening against brute-force and reconnaissance attempts, and location-based screening. Together, these give small and mid-sized businesses enterprise-class email security without an enterprise budget.

Click the button below to download your free trial!

[![Download-button](https://blog.mdaemon.com/hs-fs/hubfs/Download-button.jpg?width=302&height=118&name=Download-button.jpg)](https://mdaemon.com/pages/downloads-security-gateway-free-trial)

 

 

 Tags: [Attachments](https://blog.mdaemon.com/topic/attachments), [Email Security](https://blog.mdaemon.com/topic/email-security), [Anti-Virus](https://blog.mdaemon.com/topic/anti-virus)

![Brad Wyro](https://blog.mdaemon.com/hs-fs/hubfs/Brad-2023v2.jpg?width=100&height=100&name=Brad-2023v2.jpg)

#### Written by [Brad Wyro](https://blog.mdaemon.com/author/brad-wyro)

Brad has worked in technical and marketing roles at MDaemon Technologies, where he contributes as Content Marketing Manager. Brad balances technical and creative information to develop easy to understand videos and content to educate prospects and customers.

[![BACK TO ALL ARTICLES](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/6572702/05b24dbb-70a6-4eaa-9507-321cb27f7228.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/6572702/05b24dbb-70a6-4eaa-9507-321cb27f7228)

### Subscribe to Email Updates

- [Popular](https://blog.mdaemon.com/how-to-block-executable-files-in-securitygateway-for-email#tab-2)
- [Recent](https://blog.mdaemon.com/how-to-block-executable-files-in-securitygateway-for-email#tab-1)
- [Categories](https://blog.mdaemon.com/how-to-block-executable-files-in-securitygateway-for-email#tab-3)

### Lists by Topic

- [Email Security (72)](https://blog.mdaemon.com/tag/email-security)
- [MDaemon Email Server (44)](https://blog.mdaemon.com/tag/mdaemon-email-server)
- [Email How To (36)](https://blog.mdaemon.com/tag/email-how-to)
- [Email Best Practices (29)](https://blog.mdaemon.com/tag/email-best-practices)
- [Phishing (28)](https://blog.mdaemon.com/tag/phishing)
- [Product Updates (28)](https://blog.mdaemon.com/tag/product-updates)
- [Security Gateway for Email (27)](https://blog.mdaemon.com/tag/security-gateway-for-email)
- [Stop Spam Email (25)](https://blog.mdaemon.com/tag/stop-spam-email)
- [Cybersecurity (24)](https://blog.mdaemon.com/tag/cybersecurity)
- [Email Security Best Practices (22)](https://blog.mdaemon.com/tag/email-security-best-practices)
- [Email Server (22)](https://blog.mdaemon.com/tag/email-server)
- [Two-Factor Authentication (18)](https://blog.mdaemon.com/tag/two-factor-authentication)
- [Email Gateway How-To (17)](https://blog.mdaemon.com/tag/email-gateway-how-to)
- [Email Security Trends (15)](https://blog.mdaemon.com/tag/email-security-trends)
- [Health Care Security (12)](https://blog.mdaemon.com/tag/health-care-security)
- [SecurityGateway (12)](https://blog.mdaemon.com/tag/securitygateway)
- [Spear Phishing (12)](https://blog.mdaemon.com/tag/spear-phishing)
- [Data Leak Prevention (11)](https://blog.mdaemon.com/tag/data-leak-prevention)
- [Email Encryption (11)](https://blog.mdaemon.com/tag/email-encryption)
- [Anti-Spoofing (10)](https://blog.mdaemon.com/tag/anti-spoofing)
- [MDaemon Webmail (10)](https://blog.mdaemon.com/tag/mdaemon-webmail)
- [Email Archiving (8)](https://blog.mdaemon.com/tag/email-archiving)
- [Email Management (8)](https://blog.mdaemon.com/tag/email-management)
- [Email Privacy (8)](https://blog.mdaemon.com/tag/email-privacy)
- [Email Spoofing (8)](https://blog.mdaemon.com/tag/email-spoofing)
- [Business Email Compromise (7)](https://blog.mdaemon.com/tag/business-email-compromise)
- [Anti-Virus (6)](https://blog.mdaemon.com/tag/anti-virus)
- [Email Software (6)](https://blog.mdaemon.com/tag/email-software)
- [Tutorial (6)](https://blog.mdaemon.com/tag/tutorial)
- [Update (6)](https://blog.mdaemon.com/tag/update)
- [Collaboration (5)](https://blog.mdaemon.com/tag/collaboration)
- [Email Authentication (5)](https://blog.mdaemon.com/tag/email-authentication)
- [Compliance (4)](https://blog.mdaemon.com/tag/compliance)
- [Email Remote Administration (4)](https://blog.mdaemon.com/tag/email-remote-administration)
- [MailStore Archive Server (4)](https://blog.mdaemon.com/tag/mailstore-archive-server)
- [Microsoft 365 Exchange Alternative (4)](https://blog.mdaemon.com/tag/microsoft-365-exchange-alternative)
- [Passwords (4)](https://blog.mdaemon.com/tag/passwords)
- [Software update (4)](https://blog.mdaemon.com/tag/software-update)
- [Archive (3)](https://blog.mdaemon.com/tag/archive)
- [Attachments (2)](https://blog.mdaemon.com/tag/attachments)
- [Business Email (2)](https://blog.mdaemon.com/tag/business-email)
- [Cloud (2)](https://blog.mdaemon.com/tag/cloud)
- [DMARC (2)](https://blog.mdaemon.com/tag/dmarc)
- [Industry Insight (2)](https://blog.mdaemon.com/tag/industry-insight)
- [MDaemon (2)](https://blog.mdaemon.com/tag/mdaemon)
- [insider threats (2)](https://blog.mdaemon.com/tag/insider-threats)
- [msp (2)](https://blog.mdaemon.com/tag/msp)
- [Anti-Relay (1)](https://blog.mdaemon.com/tag/anti-relay)
- [BEC (1)](https://blog.mdaemon.com/tag/bec)
- [Backscatter (1)](https://blog.mdaemon.com/tag/backscatter)
- [Bayesian Learning (1)](https://blog.mdaemon.com/tag/bayesian-learning)
- [Content Filter (1)](https://blog.mdaemon.com/tag/content-filter)
- [DNS-BL (1)](https://blog.mdaemon.com/tag/dns-bl)
- [Disaster Recovery (1)](https://blog.mdaemon.com/tag/disaster-recovery)
- [Email Collaboration (1)](https://blog.mdaemon.com/tag/email-collaboration)
- [Email Software Reviews (1)](https://blog.mdaemon.com/tag/email-software-reviews)
- [Encrypt (1)](https://blog.mdaemon.com/tag/encrypt)
- [External Email Threats (1)](https://blog.mdaemon.com/tag/external-email-threats)
- [Gateway (1)](https://blog.mdaemon.com/tag/gateway)
- [Inbox (1)](https://blog.mdaemon.com/tag/inbox)
- [Inbox Zero (1)](https://blog.mdaemon.com/tag/inbox-zero)
- [Macros (1)](https://blog.mdaemon.com/tag/macros)
- [Monitoring (1)](https://blog.mdaemon.com/tag/monitoring)
- [Quarantine (1)](https://blog.mdaemon.com/tag/quarantine)
- [RelayFax (1)](https://blog.mdaemon.com/tag/relayfax)
- [Software (1)](https://blog.mdaemon.com/tag/software)
- [Training (1)](https://blog.mdaemon.com/tag/training)
- [Upgrade (1)](https://blog.mdaemon.com/tag/upgrade)
- [Windows Server (1)](https://blog.mdaemon.com/tag/windows-server)
- [internal email threat (1)](https://blog.mdaemon.com/tag/internal-email-threat)
- [ssl (1)](https://blog.mdaemon.com/tag/ssl)
- [tax scams (1)](https://blog.mdaemon.com/tag/tax-scams)

see all

### Posts by Topic

- [Email Security (72)](https://blog.mdaemon.com/tag/email-security)
- [MDaemon Email Server (44)](https://blog.mdaemon.com/tag/mdaemon-email-server)
- [Email How To (36)](https://blog.mdaemon.com/tag/email-how-to)
- [Email Best Practices (29)](https://blog.mdaemon.com/tag/email-best-practices)
- [Phishing (28)](https://blog.mdaemon.com/tag/phishing)
- [Product Updates (28)](https://blog.mdaemon.com/tag/product-updates)
- [Security Gateway for Email (27)](https://blog.mdaemon.com/tag/security-gateway-for-email)
- [Stop Spam Email (25)](https://blog.mdaemon.com/tag/stop-spam-email)
- [Cybersecurity (24)](https://blog.mdaemon.com/tag/cybersecurity)
- [Email Security Best Practices (22)](https://blog.mdaemon.com/tag/email-security-best-practices)
- [Email Server (22)](https://blog.mdaemon.com/tag/email-server)
- [Two-Factor Authentication (18)](https://blog.mdaemon.com/tag/two-factor-authentication)
- [Email Gateway How-To (17)](https://blog.mdaemon.com/tag/email-gateway-how-to)
- [Email Security Trends (15)](https://blog.mdaemon.com/tag/email-security-trends)
- [Health Care Security (12)](https://blog.mdaemon.com/tag/health-care-security)
- [SecurityGateway (12)](https://blog.mdaemon.com/tag/securitygateway)
- [Spear Phishing (12)](https://blog.mdaemon.com/tag/spear-phishing)
- [Data Leak Prevention (11)](https://blog.mdaemon.com/tag/data-leak-prevention)
- [Email Encryption (11)](https://blog.mdaemon.com/tag/email-encryption)
- [Anti-Spoofing (10)](https://blog.mdaemon.com/tag/anti-spoofing)
- [MDaemon Webmail (10)](https://blog.mdaemon.com/tag/mdaemon-webmail)
- [Email Archiving (8)](https://blog.mdaemon.com/tag/email-archiving)
- [Email Management (8)](https://blog.mdaemon.com/tag/email-management)
- [Email Privacy (8)](https://blog.mdaemon.com/tag/email-privacy)
- [Email Spoofing (8)](https://blog.mdaemon.com/tag/email-spoofing)
- [Business Email Compromise (7)](https://blog.mdaemon.com/tag/business-email-compromise)
- [Anti-Virus (6)](https://blog.mdaemon.com/tag/anti-virus)
- [Email Software (6)](https://blog.mdaemon.com/tag/email-software)
- [Tutorial (6)](https://blog.mdaemon.com/tag/tutorial)
- [Update (6)](https://blog.mdaemon.com/tag/update)
- [Collaboration (5)](https://blog.mdaemon.com/tag/collaboration)
- [Email Authentication (5)](https://blog.mdaemon.com/tag/email-authentication)
- [Compliance (4)](https://blog.mdaemon.com/tag/compliance)
- [Email Remote Administration (4)](https://blog.mdaemon.com/tag/email-remote-administration)
- [MailStore Archive Server (4)](https://blog.mdaemon.com/tag/mailstore-archive-server)
- [Microsoft 365 Exchange Alternative (4)](https://blog.mdaemon.com/tag/microsoft-365-exchange-alternative)
- [Passwords (4)](https://blog.mdaemon.com/tag/passwords)
- [Software update (4)](https://blog.mdaemon.com/tag/software-update)
- [Archive (3)](https://blog.mdaemon.com/tag/archive)
- [Attachments (2)](https://blog.mdaemon.com/tag/attachments)
- [Business Email (2)](https://blog.mdaemon.com/tag/business-email)
- [Cloud (2)](https://blog.mdaemon.com/tag/cloud)
- [DMARC (2)](https://blog.mdaemon.com/tag/dmarc)
- [Industry Insight (2)](https://blog.mdaemon.com/tag/industry-insight)
- [MDaemon (2)](https://blog.mdaemon.com/tag/mdaemon)
- [insider threats (2)](https://blog.mdaemon.com/tag/insider-threats)
- [msp (2)](https://blog.mdaemon.com/tag/msp)
- [Anti-Relay (1)](https://blog.mdaemon.com/tag/anti-relay)
- [BEC (1)](https://blog.mdaemon.com/tag/bec)
- [Backscatter (1)](https://blog.mdaemon.com/tag/backscatter)
- [Bayesian Learning (1)](https://blog.mdaemon.com/tag/bayesian-learning)
- [Content Filter (1)](https://blog.mdaemon.com/tag/content-filter)
- [DNS-BL (1)](https://blog.mdaemon.com/tag/dns-bl)
- [Disaster Recovery (1)](https://blog.mdaemon.com/tag/disaster-recovery)
- [Email Collaboration (1)](https://blog.mdaemon.com/tag/email-collaboration)
- [Email Software Reviews (1)](https://blog.mdaemon.com/tag/email-software-reviews)
- [Encrypt (1)](https://blog.mdaemon.com/tag/encrypt)
- [External Email Threats (1)](https://blog.mdaemon.com/tag/external-email-threats)
- [Gateway (1)](https://blog.mdaemon.com/tag/gateway)
- [Inbox (1)](https://blog.mdaemon.com/tag/inbox)
- [Inbox Zero (1)](https://blog.mdaemon.com/tag/inbox-zero)
- [Macros (1)](https://blog.mdaemon.com/tag/macros)
- [Monitoring (1)](https://blog.mdaemon.com/tag/monitoring)
- [Quarantine (1)](https://blog.mdaemon.com/tag/quarantine)
- [RelayFax (1)](https://blog.mdaemon.com/tag/relayfax)
- [Software (1)](https://blog.mdaemon.com/tag/software)
- [Training (1)](https://blog.mdaemon.com/tag/training)
- [Upgrade (1)](https://blog.mdaemon.com/tag/upgrade)
- [Windows Server (1)](https://blog.mdaemon.com/tag/windows-server)
- [internal email threat (1)](https://blog.mdaemon.com/tag/internal-email-threat)
- [ssl (1)](https://blog.mdaemon.com/tag/ssl)
- [tax scams (1)](https://blog.mdaemon.com/tag/tax-scams)

See all

#### About MDaemon Technologies

MDaemon Technologies is a pioneer in developing email and email security software helping to protect customers from evolving cyber-security threats. Its products and services are trusted by thousands of organizations in over 140 countries. For more than two decades, the company’s products have been developed with the ongoing input of IT professionals who demand reliable, affordable software that requires minimal effort to manage.

The software can be deployed in virtual, hosted cloud, on-premises, or hybrid network environments. The company sells its software and services directly and through a network of global channel partners.

For more information, visit [www.mdaemon.com](https://www.altn.com/).

Copyright © 1996-2026 MDaemon Technologies.  View [privacy policy](https://mdaemon.com/policies/privacy-policy).

 

###### Contact Us

 +1.817-601-3222

[sales@help.mdaemon.com](mailto:sales@help.mdaemon.com)

 6340 Lake Worth Blvd.  
 Fort Worth, TX 76135

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Brad Wyro",
    "url" : "https://blog.mdaemon.com/author/brad-wyro"
  },
  "dateModified" : "2026-07-15T19:54:42.344Z",
  "datePublished" : "2024-04-03T20:27:48.000Z",
  "headline" : "How to Block Executable Files in SecurityGateway™ for Email",
  "image" : [ "https://blog.mdaemon.com/hubfs/How%20to%20Block%20or%20Quarantine%20executable%20Attachments-TN.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.mdaemon.com/how-to-block-executable-files-in-securitygateway-for-email",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.mdaemon.com/hubfs/MDaemon-Technologies_logo_large.png"
    },
    "name" : "MDaemon Technologies"
  }
}
```