An alternative to Mimecast and Proofpoint
Gauntlet
Every inbound message runs the gauntlet before it reaches you.
Gauntlet is a standalone, multi-tenant inbound mail security gateway. Point your domain's MX at it and it filters spam and viruses and checks SPF, DKIM and DMARC, then relays clean mail on to wherever your mailbox actually lives — ChainMail, Microsoft 365, Google Workspace or on-prem Exchange.

- Built on
- A filtering instance of its own, never shared with ChainMail's
- Works with
- ChainMail, Microsoft 365, Google Workspace or on-prem Exchange
- Checks
- Spam, antivirus, SPF, DKIM, DMARC and greylisting
- Admin portal
- Domains, policy, quarantine and branded digest, per tenant
- Quarantine release
- Signed, single-use links — no login needed to release your own mail
Your mailbox can live anywhere
Point your domain's MX at Gauntlet and it relays clean mail on to wherever you actually keep it. Nobody has to migrate mailboxes to get the filtering, and it works whether that mailbox is ChainMail, Microsoft 365, Google Workspace or an on-prem Exchange server.
A dedicated gateway, not a shared one
Gauntlet runs on its own filtering instance, separate from the one ChainMail uses for its own mail. One tenant's spam volume or a misbehaving domain never degrades another tenant's, or ChainMail's.
Quarantine you can act on without logging in
Held mail gets a branded daily digest with signed, single-use release and whitelist links. Releasing one message does not hand out a standing password — the link expires and only ever works once.
The engine underneath is never exposed
No client or tenant ever talks to the filtering engine directly. Every action goes through Gauntlet's own API and admin portal, which is what makes it safe to run one shared engine for many tenants at all.
Policy checks that actually check
SPF, DKIM and DMARC are validated against the sending domain's own published records, not assumed from a header a message happens to carry.