(Previously known as Trustwave SEG)
Last Revision:
November 25, 2025
These notes are additional to the MailMarshal User Guide and supersede information supplied in that Guide.
The information in this document is current as of the date of publication. To check for any later information, please see Trustwave Knowledge Base article Q21250.
For the latest updates and information, customers should subscribe to the Notifications forum.
New Features
System Requirements
Upgrade Instructions
Uninstalling
Release History
For more information about additional minor features and bug fixes, see the release history.
The following system requirements are the minimum levels required for a typical installation of the Trustwave MailMarshal Array Manager and selected database.
| Category | Requirements |
|---|---|
| Processor | Core i5 or similar performance |
| Disk Space | 20GB (NTFS), and additional space to support email archiving |
| Memory | 8GB (6GB available to MailMarshal plus 2GB for operating system). Allow an additional 2GB if SQL Express is installed locally. |
| Supported Operating System |
|
| Network Access |
|
| Software |
|
| Port Access |
|
Please review the MailMarshal User Guide before upgrading.
Trustwave MailMarshal 11.3 supports a direct upgrade from MailMarshal 10.1.0 and above.
If your installed version does not support direct upgrade, you can upgrade in steps.
A standalone tool is available to check prerequisites and potential configuration issues before upgrade. See the product download page.
To upgrade a single MailMarshal server from any version supporting direct upgrade, install the new version on the existing server. You do not need to uninstall your existing version. The database will be upgraded in place, if necessary.
You must upgrade each server by logging on locally.
In the MailMarshal Server Tool, if you select a database that can be upgraded (version 8.2.3 or later 8.2.X), you will be given the option to upgrade and use the database.
After installing MailMarshal 11.X, you can import a configuration backup from version 8.2.3 or later 8.X version.
MMConvConfig
command line tool found
in the MailMarshal 11.X installation folder.
Import the converted configuration zip file using the Restore function in
the Management Interface, or the MMExportConfig command line
tool.
For full information about these tools see the User Guide.
To upgrade from a MailMarshal version prior to 10.1.0, except 8.3.2, first upgrade to 10.1.0. For version 8.3.2, first upgrade to 10.2.5. Full details about upgrading from older versions can be found in the documentation for the target version.
Note: The information in this document is current as of the date of publication. To check for any later information, please see Trustwave Knowledge Base article Q21250.
Read the notes for all versions newer than your installed version. This list only includes information about version 10.1 and above. For upgrade changes in earlier versions, see the release notes of each version.
http://urlscanner.mailmarshal.cloud
and https://urlscanner.mailmarshal.cloud
https://stats.btm.protection.mailmarshal.cloud
MailMarshal can be installed in a variety of scenarios. For full information on uninstalling MailMarshal from a production environment, see the Trustwave MailMarshal User Guide.
To uninstall a trial installation on a single computer:
The following additional items have been changed or updated in the specific build versions of Trustwave MailMarshal (previously Trustwave SEG) listed.
Note: The information in this document is current as of the date of publication. To check for any later information, please see Trustwave Knowledge Base article Q21250.
| MM-3515 | Insert of statistic data to the database is updated to avoid duplicate entry conflicts. |
| MM-6669 | More rule conditions now have an option for "is/is not matched". |
| MM-11363 | URLs extracted from QR codes can be evaluated by rule conditions. |
| MM-11852 | For Service Provider Edition installations, the From address of notifications was unexpectedly blank in certain cases. Fixed. |
| MM-12194 | Message authentication properties are captured to the database. |
| MM-12209 | The version of the PDF unpacker that is included in the installation has been updated. |
| MM-12211 | The version of the web automation client library included is updated. |
| MM-12215 | The version of the archive extraction software included in the installation has been updated. |
| MM-12239 | On upgrade, previous minor versions of .NET are removed. |
| MM-12242 | The SQL client used by the Configuration Service is updated. |
| MM-12252 | Node restart management is introduced to restart one processing node at a time. |
| MM-12268 | The length of URLs rewritten for Blended Threats evaluation is increased to 7900 characters. |
| MM-12276 | The Unpacker can now extract URLs from QR codes for further evaluation (where licensed). |
| MM-12290 | NDR messages were sent for certain messages marked with "do not NDR". Fixed. |
| MM-12309 | Reputation service lookups exclude non-routable IP ranges. |
| MM-12340 | The upgrade installer stops the SpamProfiler process if it is running. |
| MM-12352 | The version of .NET installed is updated. |
| MM-12353 | The SpamProfiler cartridge (executable) included in the release has been updated. |
| MM-12397 | HTTPS validation of the Array Manager connection by the RPC Proxy is improved. |
| MM-12400 | Sending of DMARC reports to aggregator domains failed for some values of the required authorization DNS record. Fixed. |
| MM-12403 | Entra groups with 100 or more members were not synchronized. Fixed. |
| MM-12404 | Visibility of URLs extracted from QR codes is improved. |
| MM-12409 | Additional mail security related message properties are logged to the database. |
| MM-12415 | Logging of Header Rewrite actions is improved. |
| MM-12428 | By default, restarting the Receiver does not restart the SpamProfiler process. |
| MM-12429 | MailMarshal database did not support case-sensitive collations. Fixed. Use of case-sensitive collation is discouraged. |
| MM-12435 | DMARC reporting included messages received from non-routable IP addresses. Fixed. |
| MM-9086 | The MMUpdater service is removed. Upgrade of nodes from the Array Manager is not supported in current releases. |
| MM-9223 | Sender thread count limits have been adjusted. |
| MM-11003 | MailMarshal includes a new proprietary anti-phishing detection layer, D-Fence. |
| MM-11886 | MailMarshal supports SMTP TLS Reporting (RFC-8460). |
| MM-11918 | DKIM record checking validates the retrieved record against the expected value. |
| MM-11939 | The version of the PDF unpacker that is included in the installation has been updated. |
| MM-11940 | Default URLs for Blended Threat scanning and statistics retrieval are changed. |
| MM-11968 | User group name validation allows dots and backslashes. |
| MM-12093 | DMARC reports that cannot be delivered are no longer retried. |
| MM-12097 | Performance issues related to User Statistics queries are resolved. |
| MM-12103 | When the sending server triggers an IP reputation block in the Receiver, the connection is terminated. |
| MM-12112 | Performance of insertion of DBLOG files to the database is improved with changes to SQL procedures and indexing. |
| MM-12132 | For Service Provider Edition installations, configuration reload error handling is improved. |
| MM-12133 | The Array Manager log includes better information if an invalid configuration string is detected. |
| MM-12134 | Excess log lines from the DNS resolver are removed. |
| MM-12138 | After upgrade, the Management Console website was unresponsive in browsers until a CTRL F5 full refresh was issued. Fixed. |
| MM-12155 | Internet access from the Array Manager did not use the configured name servers. Fixed. |
| MM-12158 | User statistic purge behavior is optimized. |
| MM-12159 | The version of TLS libraries included is updated. |
| MM-12176 | Sanitizing of URLs in the initial message body seen in digests is improved. |
| MM-12180 | DNS lookup performance is optimized for higher loads. |
| MM-12183 | DNSSEC status could be incorrectly returned as "bogus". Fixed: additional signature algorithms are made available. |
| MM-12190 | DKIM key provision to processing nodes stopped on the first failed domain. Fixed: all available keys will be provided. |
| MM-12207 | Reputation service lookups could fail in a small number of cases due to handling by specific DNS forwarders. Fixed. |
| MM-12212 | The SpamProfiler cartridge (executable) included in the release has been updated. |
| MM-12213 | The version of Visual C++ redistributable included in the install is updated. |
| MM-12214 | The SpamProfiler cartridge (executable) included in the release has been updated. |
| MM-12219 | ARC-SEAL generation handles messages with a null FROM address. |
| MM-12235 | Older .mdmp files were not automatically deleted on a standalone Array Manager. Fixed. |
| MM-12245 | The version of the archive extraction software included in the installation has been updated. |
| MM-12248 | On import of older configurations, a file used by older versions of Image Analyzer is removed. |
| MM-12307 | The installer check for the version of MSOLEDBSQL installed has been corrected. |
| MM-6913 | MTA-STS validation is supported. |
| MM-8604 | ARC-SEAL signing is supported. |
| MM-10986 | The Receiver could become unresponsive after user group synchronization. Fixed. |
| MM-11112 | Certain web access calls from processing node servers did not use the DNS servers configured in MailMarshal. Fixed. |
| MM-11413 | The "commit configuration changes" notice could be slow to display for changes in mail server options. Fixed. |
| MM-11703 | The version of the MSOLEDB driver included has been updated. |
| MM-11712 | Encrypted connections to the SQL Server are supported. |
| MM-11747 | Upgrade validation did not allow the fullstop character in user group names. Fixed. |
| MM-11748 | The version of the web automation client library included is updated. |
| MM-11752 | The version of TLS libraries included is updated. |
| MM-11767 | For Service Provider Edition installations, TLS is not used on local loopback connections. |
| MM-11769 | Settings and functions related to the former Cloud Email Archiving Service are removed from the product. |
| MM-11772 | The MMArchiver service is removed. The Cloud archive functionality is no longer supported. |
| MM-11788 | Email templates can now include a display name for the sender. |
| MM-11794 | The Receiver could stop unexpectedly when checking certain malformed DKIM signatures. Fixed. |
| MM-11809 | Labels on the Management Console Local Domains page did not display correctly. Fixed. |
| MM-11828 | The Server Tool interface had minor display issues when run on Windows 11 or Windows Server 2025. Fixed. |
| MM-11829 | The database schema is expanded to allow additional information about messages to be captured. Some examples of information captured in this release are: Message-Id, Return-Path, Reply-To, TLS information, Source Country, DKIM and ARC-Seal signatures, Threat Category, and time taken in processing. |
| MM-11831 | The SpamProfiler cartridge (executable) included in the release has been updated. |
| MM-11835 | The SHA256 hash of content files is logged to the database and available in Syslog templates. |
| MM-11857 | DKIM selector names are correctly validated. |
| MM-11860 | The version of the archive extraction software included in the installation has been updated. |
| MM-11872 | The Receiver logs the source country for connecting IP addresses. |
| MM-11873 | A timeout setting is available for TextCensor evaluation. |
| MM-11879 | Default retention of DMARC data is reduced to 5 days. |
| MM-11896 | The maximum size of images passed to Image Analyzer is increased. |
| MM-11902 | When an image is oversized or invalid for scanning, Image Analyzer logs details in the message envelope to allow further actions. |
| MM-11907 | URLs extracted from QR codes by Image Analyzer are reported in the Content Analysis log. |
| MM-11908 | On upgrade, DKIM signing algorithm of SHA256 is enforced. |
| MM-11931 | Notification of delay or failure in delivery over TLS is improved. |
| MM-11955 | The Image Analyzer version included in the release has been updated. |
| MM-12047 | The Controller service exists gracefully if the Json configuration file is invalid or missing. |
| MM-7378 | The Console includes the ability to generate a plain language summary of email policy. |
| MM-7426 | The Console validates copied and moved rules to prevent "go to rule" loops. |
| MM-7532 | The Console includes the ability to copy a rule from one policy group to another. |
| MM-7592 | The Console message viewer includes buttons to view the next or previous message. |
| MM-8950 | Connector User Group selections for SpamProfiler and DHA did not display properly. Fixed. |
| MM-11421 | The SQM Search function did not apply the user selection for delegated access to another user's messages. Fixed. |
| MM-11577 | The Controller service could stop unexpectedly when processing certain recursive DNS CNAME queries. Fixed. |
| MM-11601 | For group retrieval from Active Directory, the Array Manager logs the full path of the query, including the Domain Controller actually queried. |
| MM-11605 | In release 10.2.0, the notice of available product upgrades was not presented on the Dashboard. Fixed. |
| MM-11660 | After a change in system time format, login to the Management Console could fail. Fixed. |
| MM-11663 | The Array Manager could stop unexpectedly when parsing certain unexpected values for Syslog logging. |
| MM-11665 | The Connection rule "Reject non-matching TLS Client Certificates" is disabled by default for new installations. |
| MM-11667 | The Console prevents copying rules with certain actions, based on the applicable direction. |
| MM-11684 | The version of .NET installed is updated. |
| MM-11685 | The version of Visual C++ redistributable included in the install is updated. |
| MM-11689 | The version of the archive extraction software included in the installation has been updated. |
| MM-11695 | The Array Manager could stop unexpectedly due to exceptions in Dashboard data processing. Fixed. |
| MM-11802 | Message subjects containing the + symbol in plain text could be misinterpreted as Unicode. This issue has been fixed for many common cases. |
| MM-6930 | Including certain characters in Executive Name text caused the Engine to stop. Fixed. |
| MM-10604 | Manual backups of configuration could return a "task was cancelled" error due to timeout of the web interface. The backup was actually created. Addressed with a longer timeout in the web interface. |
| MM-11293 | Message history could fail to display a message when the HTML body was invalid. Fixed. |
| MM-11114 | Syslog could be enabled in the Console when no Syslog database was configured. Fixed. |
| MM-11415 | The version of TLS libraries included is updated. |
| MM-11446 | The calculations of trends over time used in the Dashboard could be incorrect for certain periods. Fixed. |
| MM-11447 | The calculations of security scores in the Dashboard did not take account of rules that apply to both incoming and outgoing messages. Fixed. |
| MM-11449 | DANE delivery was disabled when TLSA lookup returned a TempFail. Fixed: this temporary DNS failure will result in a retry. |
| MM-11455 | It is possible to specify the AD domain controller to query for all uses of AD authentication. |
| MM-11456 | MailMarshal supports SAML Single Sign On for the Management Console. |
| MM-11458 | MailMarshal provides auditing of user account creation, permission assignments, and logins to the Management Console. |
| MM-11460 | The version of .NET installed is updated. |
| MM-11509 | Some files related to the Configuration Service were not correctly versioned. Fixed. |
| MM-11511 | Deletion of nested unpacking folders could fail in rare cases. Fixed. |
| MM-11513 | Image Analyzer logged excessive information. Fixed. |
| MM-11519 | The list of file types passed to Image Analyzer has been optimized. |
| MM-11522 | Deliveries that encountered certain failures in DANE evaluation were retried excessively. Fixed. |
| MM-11529 | User groups used directly in rules and also as child groups, could be lost from the in memory copy in rare cases. Fixed. |
| MM-11530 | Additional indexing of DMARC tables in the database has been included for performance where large numbers of domains are reported on. |
| MM-11534 | The Image Analyzer version included in the release has been updated. |
| MM-11537 | The SpamProfiler cartridge (executable) included in the release has been updated. |
| MM-11544 | On upgrade to 10.1.0 if a specific named user group existed upgrade failed. Fixed. |
| MM-11566 | Resource management for Image Analyzer is improved. |
| MM-11572 | Child user groups could be lost from the in memory copy in rare cases. Fixed. |
| MM-11576 | Management of resources used by Image Analyzer is improved. |
| MM-7272 | In previous 10.X releases, the Management Console did not correctly display DKIM record status. Fixed. |
| MM-7413 | Image Analyzer rules could be created when the feature was not licensed. Fixed. |
| MM-10759 | The location of the Controller Temp folder can be configured with an entry in the JSON configuration file. |
| MM-10822 | The limit on length of folder descriptions was not validated on entry in the Management Console. Fixed. |
| MM-10843 | Certain values of Marshal Reputation Service credentials were not recognized as valid by the test in the Management Console. Fixed. |
| MM-10920 | The FolderRetention variable is now available for use in notification templates as well as in digest templates. |
| MM-10955 | The Receiver could stop unexpectedly when evaluating certain badly formed DKIM signatures. Fixed. |
| MM-10961 | Logic to throttle message acceptance under high load is improved. |
| MM-10983 | The version of .NET installed is updated. |
| MM-10984 | For Service Provider Edition installations, the Syslog service uses the globally configured certificate for all customers. |
| MM-10985 | Array Manager retry behavior during transient database errors is improved. |
| MM-11031 | For Service Provider Edition installations, an option is provided to reject messages addressed with a domain part that is a non-routable IP address. |
| MM-11036 | When editing the "Skip to specific rule" action it was possible to select a rule in a disabled policy group. Fixed. |
| MM-11037 | Handling of failed Active Directory based authentication attempts in the Receiver is improved. |
| MM-11038 | Validation of HTML entry in stamp and template editors disallowed the text "start". Fixed. |
| MM-11041 | In release 10.0.7, if update of Visual C++ executables required a system restart, the installer exited with no warning. Fixed. |
| MM-11042 | Parameters used to generate the certificate for the REST server have been updated for compatibility with current operating systems. |
| MM-11044 | Management of unexpected conditions in Syslog record processing is improved. |
| MM-11049 | The "last seen" column is removed from the IP Groups member detail listing. "Last seen" is not implemented for IP addresses. |
| MM-11097 | DNS lookup supports DNSSEC. |
| MM-11108 | The database connection string includes the "ApplicationName" attribute for better tracking. |
| MM-11160 | Saving changes to Connector definitions did not correctly validate unchanged passwords. Fixed. |
| MM-11169 | In rare cases, changes in user group membership were not propagated to processing nodes. Fixed. |
| MM-11210 | The message move and delete actions now require selection of a "category" (malware, phishing, spam, or none) for use in the Dashboard. |
| MM-11232 | Export of files from the Management Console failed with a "network issue" error in some recent client browser versions. Fixed. |
| MM-11242 | Release 10.0.7 did not allow upgrade from 8.3.X releases. Fixed. |
| MM-11250 | Image Analyzer now offers detection of many types of image content. |
| MM-11280 | Outbound email delivery supports DANE. |
| MM-11359 | The SpamProfiler cartridge (executable) included in the release has been updated. HTTPS communication with the SpamProfiler updater is enforced by default. |
| MM-11360 | The version of Visual C++ redistributable included in the install is updated. |
| MM-7326 | Quarantine Audit history can be viewed and searched from the Management Console. |
| MM-7416 | In earlier 10.X versions, node servers could not be deleted from the installation through the Console. Fixed. |
| MM-8657 | Specific formatting of IP address values in the HELO string caused SPF evaluation to fail. Fixed. |
| MM-10504 | In earlier 10.X versions, some log lines were omitted from the Receiver logs. Fixed. |
| MM-10687 | Outbound digests were not generated when the "operational user" was used for SQL connection. Fixed. |
| MM-10813 | In the Management Console, selecting from a checkbox list with hundreds of entries returned the wrong item. Fixed. |
| MM-10830 | SPF evaluation over-counted the number of DNS lookups required. Fixed. |
| MM-10845 | SPF record macro expansion did not correctly expand IPv6 addresses. Fixed. |
| MM-10850 | Import of configurations could fail if some specific values were included, due to an issue with parsing XML paths. Fixed. |
| MM-10909 | MailMarshal uses an updated version of the TLS/SSL library. |
| MM-10926 | Links containing querystrings in the text of a HTML message body (not within a HREF tag) were treated incorrectly by the BTM rewriter. Fixed. |
| MM-10954 | Text logs showed an incorrect delay time on Syslog queue inserts for some actions. Fixed. |
| MM-10967 | IP group membership was not correctly propagated to processing servers after complete refresh of the group with some continuing members. Fixed. |
| MM-10983 | The version of .NET installed is updated to the current .NET 6 release 6.0.20 |
| MM-10988 | The SpamProfiler cartridge (executable) included in the release has been updated. |
| MM-10991 | The version of Visual C++ redistributable included in the install is updated. |
| MM-10992 | Universal C runtime updating is removed from the installer (not required by supported OS versions). |
To review Release History for earlier releases, please see the Release Notes for the specific versions.
Copyright © 2025 Trustwave Holdings, Inc.
All rights reserved. This document is protected by copyright and any distribution, reproduction, copying, or decompilation is strictly prohibited without the prior written consent of Trustwave. No part of this document may be reproduced in any form or by any means without the prior written authorization of Trustwave. Trustwave assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.
The authors make no representation or warranties with respect to the accuracy or
completeness of the contents of this document and specifically disclaim any
implied warranties of merchantability or fitness for a particular purpose. No
warranty may be created or extended by sales representatives or written sales
materials. The advice and strategies contained herein may not be suitable for
your situation. You should consult with a professional where appropriate.
Neither the author nor Trustwave shall be liable for any loss of profit or any
commercial damages, including but not limited to direct, indirect, special,
incidental, consequential, or other damages.
Trustwave and the Trustwave logo are trademarks of Trustwave. Such trademarks shall not be used, copied, or disseminated in any manner without the prior written permission of Trustwave.
Trustwave helps businesses fight cybercrime, protect data and reduce security risk. With cloud and managed security services, integrated technologies and a team of security experts, ethical hackers and researchers, Trustwave enables businesses to transform the way they manage their information security and compliance programs. More than three million businesses are enrolled in the Trustwave Fusion® cloud platform, through which Trustwave delivers automated, efficient and cost-effective threat, vulnerability and compliance management. Trustwave is headquartered in Chicago, with customers in 96 countries. For more information about Trustwave, visit https://www.trustwave.com.