Your mail server will go down.
Your mail flow won't.
KumoGuard sits in front of your existing infrastructure with active-active geo-distributed gateway redundancy (10+ independent nodes), sub-14ms multi-engine inspection (SpamAssassin, ClamAV, Bayesian auto-learning), and a 96-hour zero-loss spool vault — so a dead primary server is a maintenance ticket, not an outage.
Three independent layers between threats and your inbox.
Most spam filtering runs as one inline hop. When it drops — patch failure, DDoS, expired cert — inbound mail doesn't queue politely. It bounces, or routes around your filtering entirely. That 20-minute window is how ransomware gets in.
Anycast Gateway Routing — Active-Active Geo-Distributed
Every domain resolves to a minimum of three independent gateway nodes via Anycast DNS. If a node fails health checks, traffic withdraws in seconds — no propagation delay, no manual failover, no single node carrying 100% of your risk.
NODE-C: 13ms — ALL ACTIVE
Multi-Layer MX Failover & Spool Vault
If your primary mail server is unreachable, KumoGuard holds it. The Spool Vault retains clean, scanned mail for up to 96 hours, retrying on a backoff schedule, and releases the full queue automatically once your server is reachable. Zero-loss, not best-effort.
QUEUED: 0 · LAST FLUSH: N/A
Inline Multi-Engine Inspection
Every message is scored through SpamAssassin's rule-based engine, scanned by ClamAV for malware and Trojans, checked against SURBL/DNSBL reputation lists and SPF — adding under 14ms of latency. A self-tuning Bayesian filter learns from confirmed spam/ham over time, sharpening detection without manual rule-writing.
ENGINES: SPAMASSASSIN + CLAMAV + BAYES
cPanel's SpamAssassin vs. other anti-spam vs. KumoGuard.
Most sysadmins are running SpamAssassin bundled into cPanel, or a third-party cloud spam filter sitting in front of it. Here's where each one actually stands.
Comparison reflects general, publicly documented behavior. Specific vendors and hosting providers vary — confirm against your current setup.
Auditable engines, not a black box.
KumoGuard's filtering layer is built on proven, widely-deployed scanning engines — not a proprietary black box.
Gateway uptime — trailing 12 months, all Anycast nodes
Average inline inspection latency added to mail flow
Maximum Spool Vault retention during upstream outage
Inbound mail is inspected through battle-tested spam scoring, Bayesian filtering, and antivirus engines before it ever reaches your mail server, so the detection logic you're evaluating is auditable, not a sealed vendor algorithm you're trusting blind.
Flat per-domain pricing. No surprise tiers.
S$8 per domain per month, billed yearly. Enterprise volume discounts available. 14-day free trial, no credit card required.
Billed yearly
- Active-Active geo-distributed gateway network (10+ nodes)
- 96-hour zero-loss Spool Vault
- Real-time adaptive threat analytics
- Dedicated spam panel
- Optional whitelabel of spam panel
- Enterprise volume discounts available
No credit card required
Questions before you migrate MX records.
Answers to what technical buyers ask before procurement.
Anycast DNS routing means client connections fail over to the next healthy node in under a few seconds — no single node's failure stops inbound mail. With 10+ independent active nodes across geographic regions, multiple simultaneous node failures can be absorbed without service degradation.
Most cloud filters are a single inline hop with no spooling — if your mail server is down, mail bounces. KumoGuard adds a 96-hour Spool Vault to remove that failure mode entirely, rather than leaving you exposed to a single point of failure.
Yes — MX cutover is the only DNS change required. Most migrations are a TTL-bounded cutover window, not a maintenance outage.
Full production feature access — active-active geo-distributed routing, Spool Vault, and a dedicated spam panel — on your real domain, no credit card required. Inbound mail is inspected through battle-tested spam scoring and antivirus engines, so you're evaluating it under real mail load, not a sandboxed demo.
Under 14ms average for inline multi-engine inspection (SpamAssassin + ClamAV + Bayesian filter + SURBL/DNSBL checks) — the scan time added per message, not a batch-processing delay.
Stop treating mail gateway uptime as someone else's problem.
Deploy active-active geo-distributed spam filtering with zero-loss spooling in front of your existing mail server — fully operational proof-of-concept in under a day.
Start Your 14-Day Free Trial →