In two hours one day this week, my inbox offered me $5 million in working capital, a tanker of jet fuel that doesn’t exist and an invoice for antivirus software I never bought.
The money came from somebody whose CEO had supposedly asked them to reach out, signed off with a fake “Sent from my iPhone.” The fuel was a petroleum broker selling Mazut, diesel and “JP54,” a jet fuel that exists only in scam emails. Two different “family offices” wrote to follow up on notes they’d never sent me, each under a different name with the same pitch reworded. And a fake Webroot renewal invoice for $351.71 wanted me to call “support” right away.
That was just the last two hours. It went on like that all day, every day, roughly 100 of them.
I’m not new to this fight. I spent 33 years in enterprise IT, much of it in security, and I’ve been maintaining my own spam rules for years. It wasn’t enough anymore. So I stopped adding rules behind my mail server and put a bouncer in front of it.
Why didn’t hand-built spam filters work?
Because spammers have more domains than I have patience.
My mail server runs Sieve, a scripting language for filtering mail on the server before it ever reaches my inbox. Over the years I built up a long script: hundreds of individual address and domain blocks, plus content rules for the obvious patterns. And it worked, in the sense that whack-a-mole works. Every block I added caught one sender. The next morning the same pitch arrived from a brand new throwaway domain.
That’s how the professional spammers operate now. Merchant-cash-advance shops cycle through cheap domains constantly. The fuel brokers run a long-standing advance-fee fraud that’s been around for years under endless names. Those fake “following up on my note” emails reference messages that never existed, because pretending you’ve already met makes a stranger feel familiar. The fake antivirus invoices are callback scams. They want you on the phone so they can talk you into remote access or a fake refund.
None of that is new to me. What changed was the volume. A filter that depends on me noticing each new domain and typing it in can’t keep up with people who register new domains by the hundred.
What is an email security gateway?
It’s a filter that sits in front of your mail server instead of inside it.
Every domain has MX records, the DNS entries that tell the rest of the internet where to deliver its email. Normally they point straight at your mail server. With a gateway, you point them at the gateway instead. It receives all of your incoming mail, scans it, and forwards only the clean messages on to your real server. Your mailbox doesn’t change. Your email client doesn’t change. Your existing server-side rules keep running exactly as before.
The difference is what the gateway brings to the job. It isn’t one guy with a list. It runs machine-learning filters trained on huge volumes of mail, checks every message against shared reputation data, checks the sender’s SPF, DKIM and DMARC records and scans attachments and links for malware. A domain that turned up yesterday spamming a thousand other people is already known by the time it tries me.
The one catch is that this works at the domain level. You need your own domain and access to its DNS settings. If your email is a free Gmail or Yahoo address, this isn’t for you.
What is MXGuardian and how much does it cost?
MXGuardian is a small, US-based email security company in Sacramento, California, formerly known as MX Guarddog. It does inbound filtering, and it’s priced for normal people.
For a single user, the Standard plan is $3.00 a month and the Professional plan is $4.50. The price per user drops as the user count grows, down to 55 cents a user at 3,000 users and up. That bulk rate is the number you’ll see quoted on review sites, so don’t expect it for one mailbox. There are no contracts, messages are unlimited, and there’s a 30-day free trial that doesn’t ask for a credit card.
What sold me was how it counts users. Aliases, distribution lists and extra domains are free. You pay by real mailbox. I have one mailbox and seven aliases spread across more than one domain, and all of it runs under the one-user price.
Both plans include the Bayesian filtering, several antivirus engines, malicious attachment and URL detection, SPF, DKIM and DMARC checks, spear-phishing detection, allow and block lists, quarantine with daily reports and a 30-day searchable archive. If your own mail server goes down, it holds your mail for up to five days and gives you an emergency read-only inbox. Professional adds custom banners, SMS alerts, failover to a backup mail server, directory sync and an outbound relay.
I went with Professional, one user, $4.50 a month after the free month.
100 spam emails a day is about 3,000 a month. At $4.50, that’s a fifth of a cent for each one I never have to see. Well worth it. – Richard LoweShare on X
A hundred junk emails a day is roughly 3,000 a month. At $4.50 a month, I’m paying about a fifth of a cent per spam email I never have to look at. To stop being harassed by a hundred spam emails a day, that’s well worth it.
How hard is it to set up a spam gateway?
It took me one evening, and most of that was waiting on DNS.
I signed up for the free trial and added my domain. Then I changed the domain’s MX records to point at MXGuardian. Its onboarding says there’s no downtime during the switch. While DNS catches up, anywhere from minutes to hours depending on how your records are cached, some mail goes through the gateway and some still goes direct, but nothing gets lost.
Then I added my other addresses as aliases of my one user, seven in all. Mail was flowing through the gateway the same night. It’s all set up with my seven aliases, and it all works. Super easy.
The admin panel is plain and useful. There are tabs for domain settings, allow and block lists, users, messages, statistics and diagnostics. Every message shows its status, whether delivered, quarantined or blocked, along with a spam score. One click marks something as spam, releases it, deletes it or blocks the sender or the whole domain.
Does MXGuardian work?
This was the first half hour, from my own admin screen. A negative spam score means clearly legitimate. A high positive score means spam.
At 7:01 p.m., my own test message from Outlook came through at minus 10.2, delivered. At 7:03, a real payment receipt scored minus 2.58, delivered. At 7:09, a “1 HOUR LEFT” pitch for unlimited AI at a launch price, from a sender dressed up as a Gmail address, scored 16.26 and got blocked.
At 7:17, a test from a Gmail account scored minus 9.55, delivered. At 7:30, a Japanese-language “this month’s notice” spam from a rental-box domain scored 32.47, blocked. At 7:35, a test to an alias on my second domain came in at minus 10.2, delivered.
Two pieces of spam stopped, every legitimate message delivered and no false positives.
Half an hour proves the setup works. It doesn’t prove the filter will catch everything forever, and no filter does.
The public reviews I found are on Capterra, GetApp and Software Advice, sixteen of them, every one five stars. The recurring themes are that it blocks nearly all spam while catching very little real mail, it’s simple to run, and it costs much less than the alternatives. One reviewer made the fair point that nothing stops all spam, but this does a very good job. It’s a small, low-profile company, and there’s not much independent discussion beyond those sites. I went in with a free trial for exactly that reason.
Do you still need your own spam rules?
I kept mine, and now they do a different job.
The gateway sits in front and handles the volume: forged senders, malware, known spam sources and anything the shared reputation data already knows about. My Sieve rules still run behind it on my own server, catching anything specific to me that slips through. That’s two layers instead of one, the same principle I’ve written about in defense in layers. One scanner is zero scanners.
Quarantined mail doesn’t land in my inbox at all. It sits on MXGuardian’s servers, and I can skim the quarantine on my own schedule. If something legitimate got caught, I release it and add the sender to the allow list. My inbox gets my mail, and the junk waits in a room I visit when I feel like it.
Even my antivirus got paranoid
One funny detail. The first time I went to MXGuardian’s website, Bitdefender flagged it as a possible fraud page.
That’s not as strange as it sounds. Email security companies’ domains show up constantly in spam headers and quarantine links, because they’re the ones handling the spam. Add login and payment pages on a lesser-known domain, and an anti-fraud scanner gets nervous. The service turned out to be perfectly legitimate. Even your security software can catch spam-filter paranoia.
A bouncer at the door
I spent years standing at my own inbox checking IDs one at a time, and the line never got shorter. Now there’s a bouncer at the door for $4.50 a month, and I only see the guests who belong there.
If you own your domain and you’re drowning in junk, try a gateway on a free trial before you write another rule. My home computer security guide covers the rest of what I do to keep my own machines safe, and author scam emails walks through the cons aimed at writers.
