Kaspersky updates its corporate email security platform
Kaspersky has updated email protection with AI-written message analysis, password-protected document scanning and employee risk profiles.

Contents
On 13 July 2026, Kaspersky announced a new version of Kaspersky Security for Mail Server. The update adds heuristics for suspicious AI-written messages, password-protected document scanning, flexible mail routing and a widget identifying employees who receive more unwanted email than their colleagues. The core Kaspersky Secure Mail Gateway 3.1 was only being prepared for FSTEC certification tests on the announcement date.
Functions added in the release
The extended KSMS Plus licence gained four analysis scenarios:
- detection of suspicious AI-generated messages, including BEC attempts without a malicious link or attachment;
- protection against subscription bombing, where a victim’s address is registered with many legitimate services;
- assessment of newly registered or previously unknown sender domains;
- department-specific policies for promotional email.
The product can now analyse password-protected DOCX, XLSX and PDF documents rather than only archives. It also adds ALD Pro directory integration alongside Active Directory, allowing domain groups to drive mail rules and access to personal quarantine.
How AI-message detection differs from attachment scanning
A conventional email filter looks for a known malicious object, suspicious link, reputation signal or header anomaly. A BEC message may contain no technically malicious component: the sender asks for changed payment details, an urgent document or confidential information.
The new heuristic attempts to identify signals of fraudulent or generated business text. It is an additional indicator, not proof of an attack. A legitimate employee may also use a generative tool to draft an email, while an attacker can manually edit a template. Blocking solely on the presumed writing method therefore creates a false-positive risk.
Using employee risk profiles responsibly
Kaspersky’s internal statistics indicate that most unwanted messages are typically addressed to fewer than 30% of an organisation’s employees. The new widget shows who receives spam, phishing and malicious messages most frequently.
This can prioritise training and protection, but it must not become an assessment of employee blame. High volume may follow from a public role, procurement duties, customer contact or an address published on the company website.
A practical process is to:
- establish whether message volume follows from the employee’s role;
- identify attack types and recurring themes;
- deliver targeted training with relevant examples;
- strengthen multi-factor authentication and payment-change controls;
- measure suspicious-message delivery and interaction again.
Access to the widget and reports should be role-restricted, and retention periods for employee-level statistics should be defined in advance.
Flexible routing: benefit and risk
New rules can add headers based on sender, recipient, subject, content or attachment and route messages through a corporate workflow. An organisation could send suspicious mail to a separate review queue or apply different policies to procurement and public-facing addresses.
A faulty rule may delay an important message or create a filtering bypass. Before enabling blocking, a team should:
- run the rule in tagging-only mode;
- collect a sample of matches;
- assess false positives and false negatives;
- document exceptions and the rule owner;
- monitor the queue and provide an emergency disable path;
- only then enable quarantine or rejection.
The update’s rule search and comments can make maintenance easier if the team records purpose, author, review date and the related incident.
A practical B2B pilot
The safest evaluation uses a copy of mail traffic or a limited user group. Useful metrics include:
- phishing stopped before reaching the inbox;
- false blocks per thousand messages;
- delivery latency while attachments are analysed;
- password-protected documents successfully inspected;
- administrator time spent reviewing quarantine;
- gateway stability under peak traffic;
- correct directory and group integration.
Password-protected document scanning cannot necessarily process every encryption and password-delivery method. The announcement does not specify supported algorithms, file-size limits, time-outs or performance impact. Those parameters need documentation review and tests with the organisation’s representative files.
Limitations and future status
The vendor describes the new functions but does not publish independent accuracy figures for the heuristics. Suspicious AI-text detection does not replace DMARC, DKIM, SPF, multi-factor authentication, out-of-band confirmation of payment changes or employee education.
Preparation of Kaspersky Secure Mail Gateway 3.1 for FSTEC certification testing is a process stage, not an issued certificate. Organisations subject to mandatory requirements must verify the current status in the official registry and match the certified scope to their architecture.
Our guide to FSTEC information-protection requirements covers the broader compliance logic. The backup and fault-tolerance guide can help teams plan recovery of mail infrastructure.
Takeaway
The Kaspersky Security for Mail Server update extends analysis beyond conventional link and file checks. The most useful business combination is technical filtering, risk-based training and controlled routing rules. AI heuristics remain probabilistic, however: a pilot must validate their effectiveness, while critical business operations still need independent confirmation.
Primary source: Kaspersky: update to Kaspersky Security for Mail Server


