Zix wins 5-vendor email encryption shootout

Reviews
Mar 13, 201729 mins

Email encryption has come a long way since our last review

email encryption
Credit: Thinkstock

Email encryption products have made major strides since we last looked at them nearly two years ago. They have gotten easier to use and deploy, thanks to a combination of user interface and encryption key management improvements, and are at the point where encryption can almost be called effortless on the part of the end user.

Our biggest criticism in 2015 was that the products couldn’t cover multiple use cases, such as when a user switches from reading emails on their smartphone to moving to a webmailer to composing messages on their Outlook desktop client. Fortunately, the products are all doing a better job handling multi-modal email.

In this review, we looked at five email encryption products, four of which employ encryption gateways and one that’s end-to-end. The gateways usually rely on plug-ins to Outlook and browsers so you can continue using your existing email clients. The end-to-end product requires new clients for all encrypted message traffic.

The five vendors include two that we reviewed in 2015: HPE/Voltage Secure Email and Virtru Pro. The other three are Inky (the end-to-end product), Zix Gateway, and Symantec Email Security.cloud.

Winners and losers

The overall winner is Zix. It was easy to install and manage, well-documented, and the encryption features were numerous and solid. The only drawback was that Zix lacks a separate mobile client to compose messages, but having a very responsive mobile web app made up for most of this issue.

If you want a separate end-to-end product, you should look at Inky, which offers its own clients to support S/MIME encryption.

Voltage, Symantec and Virtru are also solid products, but are still behind Zix in terms of the flexibility of various encryption protocols used, along with DLP features that are built-in along with a simple and single pricing structure — all things that Zix excels.

All of these encryption products will cost you a few dollars a month per user. While that doesn’t sound like much, if you have an installation of several thousand users, the price tag could add up. However, the alternative is having your email stream available to anyone with a simple collection of tools that even teens can master.

Trends and bright spots

In 2015, we said that gateways may have fallen out of favor, but that trend has been reversed from what we could see from the current state of the art with these products. The gateways have gotten more capable for three reasons: they can better manage and eliminate any message residue that could be left on a local storage device, they make it easier for enterprises to manage message processing rules for compliance purposes, and they have auto-sensing mechanisms to deliver the best-effort encryption between the sender and recipient, so users don’t have to figure this out on their own.

The biggest overall improvement in these products has been in better encryption key management. The difficulty associated with key management was made infamous last year with a Motherboard story where the reporter tried to get the inventor of Pretty Good Privacy (PGP), Phil Zimmerman, to exchange encrypted messages. Zimmerman sheepishly revealed that he was no longer using his own protocols, due to difficulties in getting a Mac client operational.

Since then, ProtonMail has improved its single-user free encryption tool (adding a Tor-capable version to further hide your email traffic) and Lavabit has relaunched its service (after closing its doors rather than give up its keys to law enforcement as part of the Snowden debacle.)

While these personal encryption products are improvements, there are also steps forward for the enterprise encryption email user. Some products, such as Zix, hide the encryption key process entirely from the user, so well that you might not even know that an encrypted message has passed from sender to recipient.

Others, such as Virtru and HPE/Voltage, use identity-based encryption management to verify a new recipient in their systems. Once a user new to these products clicks on a confirmation email, they are forever allowed access, their emails are automatically decrypted, and there is no need for any further effort to keep track of or to prove who you are.

That is the way all encrypted email products should operate if they are going to get used more often.

The second biggest improvement is the data loss prevention system (DLP) integration that Zix, Symantec and Virtru have as part of their products. Voltage also offers an extra-cost DLP option on top of the basic package. What this means is that all of these systems detect when sensitive information is about to be transmitted via email, and take steps to encrypt or otherwise protect the message in transit and how it will ultimately be consumed on the receiving end.

DLP has gone from something “nice to have” to more essential as part of business compliance and data leak hacks, both of which have increased its importance. Having this integration can be a big selling point of making the move to an encrypted email vendor, and we are glad to see this feature getting easier to use and to manage in these products.

A third improvement is the use of cloud-based services. All of the products tested offer cloud installations in their products, which make setup a breeze. Inky, Zix and Voltage also have on-premises servers, if that is more comfortable. Most of the products could be installed in about an hour, some even in minutes. This is a big change from earlier products that required lots of help from support staff to get up and running.

These are all great strides forward. But there are still a few issues, including the lack of support for Mac and Linux desktops. Most of the products offer a web-based alternative to reading and sending encrypted email on these endpoints, but only a few offer native clients or plug-ins for browsers or Outlook running on anything other than Windows.

There are other potential gotchas contained in the fine print, such as limits on attachment size (shown in our summary table) or subtle configuration parameters that will require a call to the vendor’s support line to complete the setup. We discuss those items in the individual reviews.

Frictionless encryption

In the past, encryption was frankly a pain in the neck. Users hated it, either because they had to manage their own encryption key stores or had to go through additional steps to encrypt and decrypt their message traffic.

If a recipient wasn’t using the same encryption provider, it was another painful process, which could quickly be multiplied by the number of different systems employed. We can see those days coming to an end, where encryption is almost completely frictionless.

So will that be enough to convince users to start using encryption for normal everyday emailing? We hope so. As the number of attacks and malware infections increase, enterprises need all the protection that they can muster and encrypting emails is a great place to start.

ScoreCard

HPE/Voltage: Solid features and privacy protections

Voltage has been around for more than a decade and has 75 million mailboxes at some very large installations. It was purchased a few years ago by HP, now called HPE, and the product has been made more appealing for smaller businesses. It comes in two versions: one for the cloud and one as an on-premises server. The cloud version doesn’t store any message traffic offsite.

There are two plug-ins: one for Windows Outlook/Office versions only and one for Office 365. If you are going to deploy Voltage, you will need to study the specific OS and Office requirements, because they are numerous and picky.

For example, you’ll need to apply SP2 if you are running Office 2010 and be running Windows 7 with SP1. It supports Outlook across Office 2010, 2013 and 2016. There are also mobile versions for at least iOS v5.1, Android 2.3 and even Blackberry from v5 and later.

There is a web-based client that Voltage pioneered several years ago that anyone can use: a message contains a HTML link that will self-register new users, similar to what its competitors now do.

When a new recipient receives an encrypted message, they are directed to download the mobile app (if they are reading it on their phones) or to click on the HTML attachment where they are taken to the web portal to read the message. This is not as effortless as we’d like nor as easy as what Symantec or Zix offers.

The Windows plug-in also adds “encryption” buttons to other Office applications like Excel, Word and Powerpoint. This allows a user to encrypt files and define who can open or edit a file. Encrypted files can then be saved to cloud collaboration platforms such as Office 365 or Dropbox.

With the mobile versions, I had trouble with the iOS app but the Android app worked fine. Voltage has a bit of a clunky method for its mobile apps: once they are installed, you still click on the attachment icon in your usual email client, then the app takes over and decrypts and displays the contents.

When you want to send a message from within Outlook, there is a special button above the normal Outlook “send” button that will encrypt your message. That is pretty simple. For any other Office app, you have a special Voltage menu that will get things going: you can add users, specify the access rights (editor, viewer or owner of the message) and press encrypt and off it goes. It is all rather plain and somewhat unimpressive, compared to its more feature-rich competitors.

Voltage, like other gateways, puts a limit on encrypted file attachments. You can get around this by using a separate utility program. This is part of the plug-in installation, and adds the ability to send files encrypted by just right-clicking on them in Windows Explorer. It will share addresses with your Outlook address book. The file sending feature is part of the trial version of software, but this is typically an extra-cost option.

Unlike the other products, Voltage’s web management portal is pretty bare-bones. You can download the plug-ins, connect to the webmail pickup portal, or manage your end user licenses. 

Voltage doesn’t have any built-in DLP features, but does support integration with a third-party tool from Digital Guardian. Another limitation is that Voltage only supports Google/Gmail POP connections and not IMAP, like some of its competitors. There is also a confusing set of error or warning messages about certificate expiration.

The conflict is between the Windows-based Voltage client and what you see on its online management portal. This is because the desktop certificate is only valid for a week, but it is automatically renewed. Most of your users probably will never venture into these screens anyway, so this is mostly a non-issue.

Voltage is sold either on a per-seat or per-enterprise installation with pricing starting at $99 per user per year. This per-seat price drops for larger installations. There are free trials for up to five users and 14 days.

Overall, Voltage is showing its age and hasn’t kept up with the competitors: its screens are rather plain and while it covers a solid collection of encryption use cases, it is time for a major UI overhaul to bring it into the modern era.

Inky writes an end-to-end story

Inky was the sole end-to-end product in this review. It has five components: a separate desktop or mobile client that accesses various cloud-based servers running in AWS: a profile server (that provides encryption features), an identity server (which contains the private key database and certificate authority), a public key server, and the email verification server that replies with the encrypted email traffic.

All of those servers are operating outside of any user’s view: the only thing that is relevant is their endpoint client. Inky has assembled a solid encryption infrastructure — but more importantly, it is an infrastructure that you don’t have to worry about, because your messages are protected end-to-end as they traverse the internet. They have a white paper that goes into the details of their cryptographic prowess that convinced me that they know what they are doing. The product is based on S/MIME standards, and they have designed it without having to fuss about encryption certificates that have long hobbled its use in the past.

The way Inky works is that the client rides on top of your standard email account. So you can still make use of this account and whatever existing client (Outlook, webmailer, etc.) you have — you just don’t get any encryption benefits from using your old client. For that, you will need to sign into the Inky client. On the desktop, this is somewhat inconvenient, because you are trading off the feature-rich things you are used to if you use Outlook, et al.

On a mobile device, it is somewhat at parity with the Google and Apple email clients, and here you can think of Inky as a better mobile device management tool when it comes to protecting your emails than what these vendors offer. Setting up your account is fairly painless: Inky has built-in routines to configure itself for Google, Microsoft Exchange, Office 365, Live and Outlook online, Yahoo, AOL, and iCloud email systems.

Inky’s email clients support Android 4.0, iOS 8, Mac OS X 10.8 and Windows 7, and up. This means that you can’t use its encryption features with Outlook or webmailers. Once you install the client, you set up a special username and password to access your emails. There is a nice feature, which provides feedback on how secure your password and about how long it will take to crack it (whether this is accurate or not, still a nice reminder to set something complex). The Inky client supports using multiple email accounts for one user too.

While the email client includes a calendar, it doesn’t have a separate contact manager, and will pull contacts from the linked email account that it is sitting on top of. Inky will extract contacts from your sent folder and order them by frequency of emailing and then try to autocomplete the contact as you type it in. This isn’t as convenient as having full access to your contacts and being able to edit this information on the fly, such as to add phone numbers and other data to the contact record as you would an ordinary Outlook or Gmail contact.

The Inky client is pretty much bare-bones. There is a separate settings screen where you can add S/MIME digital signing, customize the text sent to indicate an encrypted message, set it as your default mail client, and other features.

One plus is the ability to quickly search your mailbox, and I found the search feature to be easier to use than the typical Gmail mobile client. All data is stored encrypted on the client on your local hard drive. There is a long list of configuration settings on each client, including showing a warning if you forget to attach a file, only send encrypted mail to other Inky users, customize the text when you send a message to a non-Inky user, and set Inky as your default email client.

A recently added feature is being able to send email to a non-Inky user. Like the other products reviewed here, the recipient gets a message with a URL that requests you first authenticate, and then sends another message to your recipient’s email inbox that you can click on to view the contents. This is the only way to enter its webmailer to view and respond to an encrypted message. These links expire within 60 minutes, according to the default policies. This time period can be changed if you contact Inky support. A future version of Inky will have a menu to set the expiration period on your own. Message attachment size can be controlled within the settings sheets, the default is 32GB.

While I was testing Inky, several times it reported that my Google IMAP connection was slow. One of the settings will show you instantaneous bandwidth usage, both up and downlinks. While this is nice to know, I wasn’t sure what to do with the information. Inky also stores this in a log file to document the issue.

Pricing is based on a freemium model. Inky is free for individuals using Gmail, Outlook.com and iCloud. Otherwise, it is $5 per month per user, with corporate discounts available. There is a premium level with additional charges for MDM features and on-premises deployments. There are free trials too. They have several customers with more than 20,000 end users.

Symantec Email Security.cloud with Advanced Policy-Based Encryption option

Symantec is the current keeper of two important legacy encryption technologies: PGP and the email filtering service MessageLabs, both of which it purchased a while ago and have been kept around as separate product lines. The PGP flame is kept alive with their on-premises product, called Symantec Encryption Server that runs its own Linux-like OS. However, it hasn’t kept up with the times, and we can understand why its inventor (Zimmerman) has moved away from it. We looked briefly at this but decided to test the current incarnation of MessageLabs technology, called Symantec Email Security.cloud. This is intended for smaller businesses and has much better configuration and setup and DLP-like policies.

Email Security.cloud makes use of S/MIME but is much more than email encryption: it offers a full anti-malware email spam filtering and protection suite. But we will just focus on the encryption features. To get the most out of these, you will want to spend the extra money and purchase Symantec’s Policy Based Encryption Advanced (PBE-A) option. This incorporates technology that Symantec acquired from Echoworx, and functions similar to the other cloud-based tools in our review. All of the management features are accessed via a very capable web portal that has a complex series of menus that will take some careful study.

With this option, you can exchange encrypted messages and PDFs with users running Microsoft Office 365, Google Apps, and on premises or hosted Microsoft Exchange. For Outlook users, you install a plug-in. There are actually two plug-in versions: basic and advanced. The advanced version works with PBE-A, the basic version supports the basic Email Security.cloud feature set.

The Advanced plug-ins have more features for Windows Outlook users, and there at least is a plug-in for Mac Outlook users. For example, from the Outlook toolbar, you can set up a variety of passphrases (something mutually shared, for example), encrypt just the attachment, set an expiration period for your message, and provide both pickup confirmation and encryption confirmation.

The Symantec cloud services don’t have any mobile apps. To read your messages on your phones or tablets you’ll need to make use of the web client portal. These are also used when you send a message to an external user for the first time. To access it, you will see a link in your encrypted message where you can register, decrypt and view the contents of your messages. This is similar to what the others offer.

The only difference is that Symantec can authenticate you with one of your social media accounts (such as Google+ or Facebook), although for additional privacy you can set up a new account with a separate password. As with other web portals, you can reply to the message, but can’t compose an encrypted email to a new recipient. When a recipient collects their message (or if they are reaching the end of the period before a message expires), the sender gets notified.

PBE-A has a default maximum message size of 50MB, but you can increase this in the Services/Mail Platform menu. If you are using G-Suite or the other Google email services, you need to first determine if Google’s attachment limits will take precedence.

PBE-A has a long list of default mail processing policies and a very granular policy creation and definition process. There are numerous policy templates included, and they have obvious keywords included so you can differentiate those that filter based on Social Security numbers or other data. All of this is well documented in the Admin Guide.

One of the nice features is being able to maintain separate keyword lists for each policy, so for example you could share all your medical-related keywords for various HIPAA policies. You can apply a policy for particular message parts or even filter by attachment properties too, as well as filter based on inbound or outbound message traffic. And you can group recipients for special treatment. Like a typical firewall rule collection, policy rules are applied from the top down, so you can set up some very sophisticated situations, depending on how you order your policies.

One big drawback of PBE-A is that changes to the policies happen automatically, but don’t take effect for about 30 minutes. So this could slow down your testing of any policy. One small drawback of PBE-A is that its messages are set to expire in 30 days. You can’t change this option, and neither can the Symantec support folks.

For pricing, you first need to purchase the email Safeguard bundle, which costs $2.41 per user per month. Then you need to add the PBE-A bundle will set you back another $3.50 per user per month.

Virtru Pro: Set it and forget it

The Virtru product was one of the more impressive products in 2015 and it has gotten better since then. It offers an interesting twist on the trade-offs of ease of use and functionality, thanks to its nice balance of plug-ins and mobile apps. The net result is that it supports encryption operations across a variety of email circumstances.

If you use Windows Outlook 2010, 2013 or 2016 versions, you can encrypt messages on any SMTP-based email server with a “send secure” button that gets added to the Outlook toolbar. If you make use of Google’s webmail, you can run either the Chrome or Firefox browser extension on any Windows, Mac or Linux computer. And there are mobile apps that support iOS and Android phones.

Since we looked at it in 2015, it has eliminated support for Yahoo and Outlook.com mailers and doesn’t support Mac Mail clients. This is because as Virtru enhances its product, these older clients can’t keep up with its newest features.

Once you add the plug-in to your email client or browser, you have a simple toggle switch to send an encrypted message. That is pretty much the only decision a user has to make. Email administrators can set policies for what messages are automatically encrypted, which override the user’s choice.

Virtru expanded its attachment limit from 25 MB to 150 MB since our last look in 2015 for its browser clients. For Outlook, it follows whatever the Exchange sysadmin has set for this value.

There is a web-based management portal that works with your Google and Office 365 installations. The portal is similar to what we saw two years ago but has been significantly expanded in terms of features and its UI has been cleaned up somewhat. There are various menus for adding users from your domain to be able to employ Virtru, a series of automatic protection and other mail processing rules to force encryption for specific circumstances, such as including a Social Security number or other personal information.

You can also set mail expiration rules as well as forwarding rules. Its rules aren’t as comprehensive as Zix but still offers a lot of options, and unlike Zix everything is collected under a single dashboard location.

Another feature added recently is the ability to generate message read receipts, along with the ability for users to search their encrypted message store that also includes text in the subject lines and attachments. This search option, along with the ability for mail administrators to make searches of Google’s Vault, are also found on the web portal pages. Administrators can also revoke sent messages, set expiration dates or disable forwarding on any encrypted message or attached file in the domain.

Last year, they announced a SDK to allow software vendors to incorporate their features into their platforms, and the first instance of this was AODocs. Finally, another new feature is being able to use hardware-backed encryption so that administrators can decide where to locate their encryption keys. This feature works with a variety of installations, including hosted on premises, in a private cloud, or on public clouds such as Amazon’s Encryption Key Management service and uses Safenet/Luna’s hardware modules. This means that cloud providers can never see customer encryption keys or be able to decrypt underlying content, and an enterprise can locate its keys in a particular geography to meet local compliance regulations.

Virtru has a free version, and a pro version that will cost $5 a user per month, with a discount for annual purchases. Both are available for 14-day free trials. The free version just does encryption without the additional features, such as message expiration, DLP rules and domain administration that are found in the paid Pro version. Virtru is one of the few email encryption vendors that has very transparent pricing, with a page on their website that spells everything out. I wish more vendors were like them. They have several customers with more than 20,000 end users.

Zix Gateway: Frictionless encryption

Zix has been in the email encryption business for more than a decade, and its product shows. It is an interesting one to review because of how much it does under the covers, making the encryption happen in spite of what any end user is trying to do. This is one reason why they have so many large installations, and could be a reason why the software is so popular. Messages are sent and received without any specific user action, the encryption just happens. This makes Zix one of the most transparent and frictionless encryption products around.

Zix sells two products: the gateway that we tested, and an end-to-end encryption client that either works standalone or works with a Windows-only Outlook plugin to encrypt messages on the desktop before sending. The two systems don’t interoperate. The gateway supports both Office 365 and Google cloud-based mailers. It can make use of OAuth to authenticate a user to both systems.

Getting the Zix Gateway installed will take a matter of hours, which can be reduced with personal support if you want it: it is included as part of the purchase price. Once set up, your employees might never know that their messages have been encrypted and decrypted, it basically operates under the covers and uses a variety of different techniques, depending on who is getting a message and how sensitive the contents. Unlike other products, such as Voltage that have added a “send secure” button, all mail is sent encrypted, if that is how you have set up your policies.

The idea is that Zix will encrypt a message whenever possible, as long as there’s a secure pathway between the sender’s and recipient’s mail systems. You can configure your policies to do this, or to use one of its various secure protocols that are supported. Zix calls this “best method of delivery” and it is an important advantage and why you would want to choose it for your email provider. This means if you are sending email to another Zix customer, you don’t have to do anything special to encrypt your message traffic. If recipients aren’t Zix customers, their messages will be delivered using TLS protocols, or sending an encrypted HTML attachment (this last method is similar to how the other products work).

At the heart of the Zix encryption ecosystem is an innovative email DLP. This is included at no extra charge and perhaps one of the more important motivations for making use of their product. You set up content rules like in other DLP systems, but the rules are very easy to assemble, and you get a dozen or so pre-built ones to get you started that make things even easier.

All content is scanned including subject lines, message text and attached files. If the DLP engine finds a match with a policy rule, the mail is encrypted. If you use Outlook, you can also set the “confidential” flag in your message and that will trigger an encryption process.

The email DLP policies also show the power of the product. With some DLP solutions, you have to worry about syntax, encryption certificates, or other plumbing issues. Zix takes care of all of that for you automatically. These rules are all click and set in a series of web screens that are very simple to navigate and the Zix support staff will help you assemble them if you can’t figure them out. So for example you can create a rule that automatically encrypts any email that has a Social Security number or other personally-identifying information in it, or automatically encrypt a message with a particular recipient/sending combination.

You’ll notice that there are no client pieces: you make use of your standard email clients. There is no additional software needed if you choose the gateway approach, since they handle the entire encryption and certificate processes. This also means no plug-ins, which is a nice touch.

One of the nice features is two separate training-based intranet sites (called User Awareness Programs). One is for customers, the other is for employees. Both walk you through the numerous features of the product. It is customized with your own landing pages and screen shots, and is well organized so a new staffer in your organization (or customer) can understand what Zix is doing in about 15 minutes.

Some other advantages: Zix maintains multiple data centers, including one in Europe if that is an issue for customers located there. Also, file attachment limits are set by the support staff from 1M to 50MB.

There are two big drawbacks to Zix. First it doesn’t support sending messages from a smartphone. Like Symantec, there is no specific app that needs to be used, and all email needs to happen in the phone’s browser. You either use a webmail client or respond to a message that you have sent from the Zix web portal. When you access the portal you can see its responsive design that takes into account the smaller browser real estate. The other use cases are all covered: end-to-end encryption with Outlook plug-in, gateway-to-gateway or gateway-to-supported email server.

The second issue is the various web portals that are needed to manage the product. There are many different parts to the product: the gateway code itself, which either runs in the cloud or can be installed as a physical appliance or a VM instance. There is a separate component, which handles quarantines, and a separate Web-based portal for messages that are sent to non-Zix users.

The gateway has a series of different web-based management screens: one for general operations, one for DLP management, one for reports about message traffic and one for handling quarantined messages. Each has its own URL, which means that is a lot of screens to visit, and to train your staff on. Obviously, they are working on consolidating and updating these into a more coherent package.

I had an issue with time-outs on my login screen to the overall web portal. Zix would lock me out during some but not all times when I returned to this screen. I couldn’t recreate this and the company couldn’t track this issue down. There is another issue, its reports lack any real flair and are fairly basic.

Pricing is one of the other advantages of Zix: everything is bundled in one simple all-inclusive price, depending on the number of individual senders that are licensed. This includes whatever server instance (cloud, VM, or appliance), whatever support is needed to get up and running, and minor ongoing support once your system is configured properly to your particular set of circumstances. Sample pricing is $3,500 per year for up to 25 senders, or $53,250 for up to 1,500 senders, based on a three-year commitment. This works out to about $3 a user a month for volume agreements. The one extra-cost option is the quarantine manager, which adds another $115 per year for up to 25 senders or $17,250 for up to 1,500.

How we tested email encryption

We used a combination of Mac and Windows 7 desktop clients, an iPhone and an Android tablet to run the various programs, using Safari and Chrome browsers. We set up several internet-based mail domains, and added plug-ins to Windows 7 machines running Outlook 2013 and any browsers to support the various email products’ encryption features. In setting up this entire infrastructure, we looked at the following evaluation criteria:

1) Enterprise management and control features

These include how a product can recover from error conditions and how useful it is in troubleshooting email problems. We looked at how easy it was to set up new mailboxes or terminate existing ones. We also noted in the summary chart what the attachment size limits, if any, are specified by each vendor, how encryption keys are handled, and if any residue remains on endpoint devices.

2) Documentation

We looked at the user interfaces (Web, mobile and desktop clients) and how they differ and how they are documented or supported with online tutorials and help files.

3) Ease of encryption

Ease of use when it comes to applying encryption is now an important feature. This includes how to recover a lost password, how various endpoints encrypt and decrypt messages, and what DLP-like features are included.