SecurityGateway 12.5 is here, and it brings a refreshed web interface, stronger defenses against disguised and mismatched attachments, more flexible domain administrator controls, faster user verification for Google Workspace domains, DNS-based domain ownership verification, and a new REST API for automation. Together, these updates give administrators more control, better visibility, and stronger protection, with less manual work. Here's a closer look at what's new.
A Cleaner Interface for Faster Admin Work
The SecurityGateway web interface has been refreshed with a cleaner layout and clearer visual hierarchy. Both the default light and dark themes have been updated, mobile support is improved (particularly on the dashboard), and a new classic theme is available if you prefer an experience closer to earlier versions.

Stop Disguised Attachments Before They Reach Users
SecurityGateway can now detect when an attachment's actual file type doesn't match its extension, a common trick spammers use to disguise executables as harmless files like PDFs. When a mismatch is found, you can choose to refuse, quarantine, or accept the message, with optional subject tagging and score adjustments.

Close the Extension-Spoofing Gap in Attachment Filtering
Attachment filtering rules can now match on a file's actual detected type, not just its extension. That means risky file types are still caught by your content filter even if someone renames the extension to try to slip past your filtering rules.
Faster User Verification for Google Workspace Domains
Domains using Google Workspace can now verify local users directly through the Google Workspace API instead of relying on SMTP callbacks, for quicker and more reliable verification.

Give Domain Admins Only the Access They Need
Global administrators can now control which product areas each domain administrator is allowed to manage, including:
- Per-domain maximum user limits
- Domain mail servers
- User verification sources
- Domain admin delegation

Block Unauthorized Domain Setups Automatically
SecurityGateway now lets you require domain ownership verification before a new domain can receive mail. When enabled, each new domain stays in a pending state until its owner confirms control by publishing a simple TXT record to DNS, protecting you from unauthorized or accidental domain setups.

Automate Admin Tasks with a New REST API
SecurityGateway now includes a modern REST/JSON API that helps you automate admin tasks and quickly connect with provisioning tools, identity systems, and your own custom workflows. For details, see the SecurityGateway Release Notes.
Additional Improvements
- Dynamic Screening has been extended with additional controls for how failed authentication attempts are tracked and blocked.h additional controls for how failed authentication attempts are tracked and blocked.
- SecurityGateway now supports the PROXY protocol (v1 and v2), so you can place it behind HAProxy or a similar load balancer and it will still see each connection's real client IP address and SNI hostname instead of the load balancer's.
- SecurityGateway now validates DNSSEC when delivering outbound mail, giving you stronger assurance that messages reach the legitimate recipient server rather than an impostor. This can also help satisfy REQUIRETLS for encrypted delivery, reducing your reliance on MTA-STS so sensitive email stays private with less configuration on your end.
- Custom per-domain quarantine report settings have been added.
- SNI-based domain identification for SMTP connections lets SecurityGateway identify the correct domain earlier in the session, so its SMTP host name is available immediately after STARTTLS.
For a complete list of new features and updates, see the SecurityGateway Release Notes.
Try SecurityGateway 12.5 Free for 30 Days
SecurityGateway 12.5 is available now. Visit the Downloads page to start your 30-day free trial and see these new features in action.

