// Sendio Email Security Gateway™ //

Email security and sender trust, together in one platform.

Opt-Inbox can simply be added to an existing email security stack to reduce clutter and distractions. Adopted as part of Sendio's ESG bundle to provide security and identity enforcement in one platform, simplify admin and queue management in a single pane, and reduce subscription costs and the number of vendors to manage.

INBOUND MAIL LAYER 01 · CONTENT SAFETY Email Security Gateway Is this message dangerous? LAYER 02 · IDENTITY ENFORCEMENT Opt-Inbox Should this sender be allowed to interrupt? DELIVERED
// 01 — The two-layer architecture //

Two questions. One control pane.

Reputable vendors do a good job at addressing email security, but most fall short in dealing with “safe” message desirability, resulting in delivering nuisance messages because they are safe, or withholding desirable messages because they might be spam.

Sendio’s ESG is designed with Opt-Inbox sender identity verification in mind. Bundled, they avoid false positives and overly aggressive ESG filtering, while Opt-Inbox eliminates clutter and distractions.

// Layer 01 // Content safety

"Is this message dangerous?"

Sendio Email Security Gateway

Standards-based threat detection. SPF, DKIM, DMARC, IP reputation, behavioral analysis via Server Recon, multi-engine malware scanning. Reliable and proven, without claims of revolutionary superiority.

// Layer 02 // Identity enforcement

"Should this sender be allowed to interrupt?"

Sendio Opt-Inbox

Recipient-controlled sender verification. Deterministic decisions about who reaches the inbox. No probability scoring, no machine guessing. Each user owns their approved list.

// 02 — Choosing your path //

Any reputable email security plus Opt-Inbox: Same outcome, different complexity

The two approaches below deliver identical recipient-controlled identity enforcement. The right choice depends on whether you prefer best-of-breed procurement or operational consolidation.

Two panes, Two Vendors

Any email security + Opt-Inbox

Keep your current email security vendor (Proofpoint, Mimecast, Microsoft 365, Barracuda, TrendMicro, Sophos, etc.) and add Opt-Inbox as the downstream identity layer. Best-of-breed approach, fully supported.

  • No security vendor change required
  • Add Opt-Inbox identity enforcement
  • Mail flow rules between security and identity layers
// Same outcome //

Email security takes care of threats. Opt-Inbox provides identity enforcement that is recipient-controlled and deterministic, with the same productivity gains.


// 03 — ESG / Opt-Inbox bundle //

Operational benefits, easier administration.

The Sendio bundle combines full email security protection with natively integrated sender identity verification.

01 1

Vendor consolidation

Single contract, single renewal cycle, lower costs, single support relationship. Reduce the number of vendor relationships your team manages.

02

Unified administration

Manage security policies and identity policies from one interface. No console switching, no separate dashboards, no fragmented audit trail, no need to chase internal designees for responsibility or action.

03

Native architecture

ESG is designed with Opt-Inbox as a downstream assumption. Security thresholds are tuned for the presence of identity enforcement rather than having to assume its absence, as standalone security platforms must.

04

Simplified operations

No manual coordination between separate security and identity systems. The two layers were designed to work together, so day-to-day operations are smoother.

// 04 — Native integration in practice //

Security decisions defer to sender identity.

Traditional security platforms make binary decisions without sender context, sometimes causing false positives. ESG performs all needed security checks before handing off the desirability question to Opt-Inbox, which means spam scoring and bulk handling can be more flexible (and more accurate) than they would be otherwise.

[potentially remove this table] // Example: how a high spam score is handled //

Sender identity state changes the disposition

Sender approved
Sender unknown
Sender blocked
No Threat High spam
Flagged Recipient wants this sender
Held Awaiting identity decision
Held No further evaluation
No Threat Medium spam
Flagged Approved bulk is wanted bulk
Held Identity decision pending
Held Permanent rejection
No Threat Low spam
Deliver Recipient wants this sender
Held Awaiting identity decision
Held immediately No further evaluation

The result: fewer false positives at the security layer, because borderline cases that would otherwise be quarantined are deferred to deterministic identity enforcement downstream.

// 04 — What ESG's security layer actually does //

Standards-based, AI facilitated, human controlled.

ESG implements the email security fundamentals reliably. When you want a single pane, it is a proven security solution that integrates natively with Opt‑Inbox identity enforcement.

// Capability 01 //

Authentication enforcement

SPF, DKIM, and DMARC validation with configurable policy enforcement at the domain and group level.

// Capability 02 //

Connection security

IP reputation filtering, DNS validation, and protocol enforcement at the SMTP layer.

// Capability 03 //

Server Recon™

Behavioral reputation layer that monitors SMTP-level sender behavior for spam patterns and emerging threats. Sendio's signature contribution to the security stack.

// Capability 04 //

Threat detection

Malware scanning, anti-virus and anti-spam, heuristic analysis for zero-hour threats, link inspection, and content filtering.

// Capability 05 //

Policy management

Configurable disposition rules (quarantine, reject, defer) and a managed quarantine surface.

// Capability 06 //

TLS encryption

Server-to-server encryption included by default. Email is encrypted from the moment it leaves Sendio's infrastructure to the moment it reaches the recipient's mail server.

// 05 — Unified administration //

Single pane. End-to-end visibility.

When you operate ESG and Opt-Inbox as a bundle, the administrative experience is meaningfully simpler than running two products from two vendors.

// Single interface //

Manage both layers without console switching

Security policies (ESG) and identity policies (Opt-Inbox) configured from the same admin surface. No tab juggling, no context switching between disconnected dashboards.

// Unified reporting //

Total filtering effectiveness in one dashboard

One report shows threats blocked (ESG) and unwanted senders held (Opt-Inbox). The combined view tells the complete story of what mail reached your team and what didn't.

// User management //

Single provisioning workflow

Adding a user applies both security and identity configurations in one step. No double-entry, no risk of drift between systems.

// AAdmin drill down made easy //

Complete message journey, end to end

Track each message from arrival through ESG processing, through Opt-Inbox evaluation, to delivery. Troubleshoot disposition decisions without correlating logs across vendors.

// 06 — Platform options //

Deploy how you need to.

Three deployment modes, identical product capabilities. The choice depends on your infrastructure preferences and regulatory requirements.

Self-hosted

Virtual appliance

VM-based deployment for VMware or Hyper-V environments. Suitable for on-premises or air-gapped deployments where the appliance must live on your infrastructure.

Dedicated hardware

Physical appliance

Dedicated hardware for high-volume mail flow or regulatory environments that require physical control of the security appliance.

// Support //

Human agents only.

No automated responses, no chatbots, no AI-generated replies during business hours (9 AM - 8 PM ET, M-F). Every support interaction reaches a real engineer.

// Critical response //

Sub-30-minute commitment

Human engineers respond to mail flow emergencies 24/7 with a sub-30-minute response commitment.

// Proactive monitoring //

Always on monitoring

Sendio engineers monitor and address issues, generally before users experience disruption, and contact customer admins if action on their side is required.

// 07 — Outcomes //

Productivity improvement across deployments. Whichever path you choose.

Both deployment paths (existing security + Opt-Inbox, or the Sendio bundle) deliver the same identity enforcement and the same productivity gains. These ranges reflect observed results across customer organizations.

// Volume //
50%
average reduction in inbound mail volume, with zero loss of wanted mail. Roughly half is typically stopped by email security and half by Opt-Inbox.
Sendio / Customer telemetry
// Time per user //
20-25mins
Estimated daily productivity lost to unwanted email triage and distraction
Gated Inbox Intelligence (2022)
Kaspersky Workspace Spam Analysis (2022)
UC Irvine interruption research
Sendio Telemetry
// Annual reclaim //
10–13days
of productive time reclaimed per employee, per year.
Gated Inbox Intelligence (2022)
Kaspersky Workspace Spam Analysis (2022)
UC Irvine interruption research
Sendio Telemetry
// 08 — Common questions //

The bundle, explained.

Is ESG required to use Opt-Inbox?
No. Opt-Inbox is fully supported as an add-on behind any existing email security platform: Microsoft 365 Defender, Proofpoint, Mimecast, Barracuda, Sophos, Trend Micro, and others. The Sendio bundle (ESG + Opt-Inbox) is an alternative deployment path, not a requirement.
Why would I choose the bundle over keeping my existing security?
Three reasons typically drive that choice: vendor consolidation (fewer contracts to manage), unified administration (one console instead of two), and native architecture (ESG is tuned for downstream Opt-Inbox identity enforcement). If those operational benefits aren't important to your team, the add-on path is often the simpler choice.
Is ESG better at threat detection than Proofpoint or Mimecast?
No, and Sendio doesn't position it that way. ESG implements standards-based email security reliably. The differentiator in the Sendio platform is not ESG's threat detection capability, it's the native two-layer integration with Opt-Inbox identity enforcement.
What does "native two-layer architecture" actually mean in practice?
ESG security thresholds and bulk-handling rules are designed assuming Opt-Inbox identity enforcement runs downstream. Spam scoring is tuned more flexibly, IP reputation is calibrated knowing identity will handle desirability, and bulk mail handling defers to sender state. This produces fewer false positives at the security layer than traditional platforms that must guess at desirability without identity context.
Can I migrate to the bundle from a third-party security platform later?
Yes. Most customers start on the add-on path and some migrate to the bundle later, typically during their existing security vendor's renewal cycle. The Opt-Inbox configuration carries over; only the security layer changes.
What deployment options are available?
Three: cloud-hosted (Sendio manages infrastructure), virtual appliance (VMware or Hyper-V on your infrastructure), and physical appliance (dedicated hardware). All three modes deliver identical product capabilities.
What does support look like?
Human agents only, with no chatbots or AI-generated responses during business hours. Critical outage response runs 24/7 with a sub-30-minute commitment. Sendio also proactively contacts customers when monitoring detects issues before users experience disruption.
What's the guarantee?
30-day money-back guarantee. Evaluate the bundle in production and cancel within the first 30 days for a full refund if it isn't working the way you expected.
// Ready to evaluate //

One vendor, two layers, same outcomes.

Schedule a 30-minute walkthrough to see ESG and Opt-Inbox running as a native bundle. We'll cover the architecture, the deployment options for your environment, and the practical differences from your current setup.