Trustwave MailMarshal 11.3 Release Notes

(Previously known as Trustwave SEG)

Last Revision: November 25, 2025

These notes are additional to the MailMarshal User Guide and supersede information supplied in that Guide.

The information in this document is current as of the date of publication. To check for any later information, please see Trustwave Knowledge Base article Q21250.

For the latest updates and information, customers should subscribe to the Notifications forum.

Table of Contents

New Features
System Requirements
Upgrade Instructions
Uninstalling
Release History

New Features

For more information about additional minor features and bug fixes, see the release history.

Features New in 11.3

Features New in 11.2

Features New in 11.1

Features New in 10.2.5

Features New in 10.2.0

Features New in 10.1.0

System Requirements

The following system requirements are the minimum levels required for a typical installation of the Trustwave MailMarshal Array Manager and selected database.

Table 1: System Requirements
Category Requirements
Processor Core i5 or similar performance
Disk Space 20GB (NTFS), and additional space to support email archiving
Memory 8GB (6GB available to MailMarshal plus 2GB for operating system). Allow an additional 2GB if SQL Express is installed locally.
Supported Operating System
  • Windows Server 2016, Server 2019, Server 2022, Server 2025 (Essentials Edition or above)
  • Windows 11 (Allowed but not recommended)
Network Access
  • TCP/IP protocol
  • Domain structure
  • External DNS name resolution - DNS MX record to allow Trustwave MailMarshal Server to receive inbound email
Software
  • Microsoft .NET Framework 4.6.2 (or later 4.X)
    • MailMarshal will install additional software as needed, including .NET 8 and C++ Runtimes.
    • If you have installed a later release/patch version of .NET 8, you must install the identical version of the Hosting, Runtime, and Desktop packages
  • Database server (managed cloud service): Azure SQL Database
  • Database server: SQL Server 2025, SQL Server 2022, SQL Server 2019, SQL Server 2017
  • Database server (free versions): SQL 2025 Express, SQL 2022 Express, SQL 2019 Express, SQL 2017 Express

    (Service packs listed are the minimum required for compatibility with all supported operating systems)

  • Web browser (for Management Console connection): Chrome, Edge, Firefox, or Safari. (Internet Explorer is not supported).
  • IIS (array manager only).
    • Windows Authentication must be enabled in IIS.
    • Note: WebDAV must not be active on the MailMarshal websites. For WebDAV removal, see Trustwave Knowledge Base article Q21096.
Port Access
  • Port 53 - for DNS external email server name resolution
  • Port 80 (HTTP) and Port 443 (HTTPS) - for SpamCensor updates
  • Port 1433 - for connection to SQL Server database and Reports console computers
  • Port 19001 - between Array Manager and Processing Nodes
    Note: Additional ports are required by the Nodes for email and updates.
  • Port 19006 and port 19007 (HTTPS) - for communication between components on the Array Manager. If the MailMarshal API is in use from other servers to the array manager, these ports must be open from the API client to the Array Manager.

 

Upgrade Instructions

Please review the MailMarshal User Guide before upgrading.

Trustwave MailMarshal 11.3 supports a direct upgrade from MailMarshal 10.1.0 and above.

If your installed version does not support direct upgrade, you can upgrade in steps.

Upgrade Preview

A standalone tool is available to check prerequisites and potential configuration issues before upgrade. See the product download page.

Database Prerequisites

Upgrading a Single Server

To upgrade a single MailMarshal server from any version supporting direct upgrade, install the new version on the existing server. You do not need to uninstall your existing version. The database will be upgraded in place, if necessary.

Upgrading an Array of Servers

You must upgrade each server by logging on locally.

Upgrading a Database

In the MailMarshal Server Tool, if you select a database that can be upgraded (version 8.2.3 or later 8.2.X), you will be given the option to upgrade and use the database.

Importing an 8.X Configuration Backup

After installing MailMarshal 11.X, you can import a configuration backup from version 8.2.3 or later 8.X version.

  1. Convert the backup to the 11.X backup format (zip file) using the MMConvConfig command line tool found in the MailMarshal 11.X installation folder.
  2. Import the converted configuration zip file using the Restore function in the Management Interface, or the MMExportConfig command line tool.

For full information about these tools see the User Guide.

Upgrading From Older Versions

To upgrade from a MailMarshal version prior to 10.1.0, except 8.3.2, first upgrade to 10.1.0. For version 8.3.2, first upgrade to 10.2.5. Full details about upgrading from older versions can be found in the documentation for the target version.

Notes on Upgrading

Note: The information in this document is current as of the date of publication. To check for any later information, please see Trustwave Knowledge Base article Q21250.

Read the notes for all versions newer than your installed version. This list only includes information about version 10.1 and above. For upgrade changes in earlier versions, see the release notes of each version.

Uninstalling

MailMarshal can be installed in a variety of scenarios. For full information on uninstalling MailMarshal from a production environment, see the Trustwave MailMarshal User Guide.

To uninstall a trial installation on a single computer:

  1. Close all instances of the MailMarshal Management Console website and helper applications such as Server Tool.
  2. Use Add/Remove Programs from the Windows Control Panel to remove Trustwave MailMarshal.
  3. Use Add/Remove Programs from the Windows Control Panel to remove additional components you may have installed, such as Web components or the Marshal Reporting Console.
  4. If you have installed any components (such as the Web components) on other computers, uninstall them.
  5. If you have installed SQL Express specifically to support MailMarshal and no other applications are using it, uninstall SQL Express.

Release History

The following additional items have been changed or updated in the specific build versions of Trustwave MailMarshal (previously Trustwave SEG) listed.

Note: The information in this document is current as of the date of publication. To check for any later information, please see Trustwave Knowledge Base article Q21250.

11.3.0 (November 25, 2025)

MM-3515 Insert of statistic data to the database is updated to avoid duplicate entry conflicts.
MM-6669 More rule conditions now have an option for "is/is not matched".
MM-11363 URLs extracted from QR codes can be evaluated by rule conditions.
MM-11852 For Service Provider Edition installations, the From address of notifications was unexpectedly blank in certain cases. Fixed.
MM-12194 Message authentication properties are captured to the database.
MM-12209 The version of the PDF unpacker that is included in the installation has been updated.
MM-12211 The version of the web automation client library included is updated.
MM-12215 The version of the archive extraction software included in the installation has been updated.
MM-12239 On upgrade, previous minor versions of .NET are removed.
MM-12242 The SQL client used by the Configuration Service is updated.
MM-12252 Node restart management is introduced to restart one processing node at a time.
MM-12268 The length of URLs rewritten for Blended Threats evaluation is increased to 7900 characters.
MM-12276 The Unpacker can now extract URLs from QR codes for further evaluation (where licensed).
MM-12290 NDR messages were sent for certain messages marked with "do not NDR". Fixed.
MM-12309 Reputation service lookups exclude non-routable IP ranges.
MM-12340 The upgrade installer stops the SpamProfiler process if it is running.
MM-12352 The version of .NET installed is updated.
MM-12353 The SpamProfiler cartridge (executable) included in the release has been updated.
MM-12397 HTTPS validation of the Array Manager connection by the RPC Proxy is improved.
MM-12400 Sending of DMARC reports to aggregator domains failed for some values of the required authorization DNS record. Fixed.
MM-12403 Entra groups with 100 or more members were not synchronized. Fixed.
MM-12404 Visibility of URLs extracted from QR codes is improved.
MM-12409 Additional mail security related message properties are logged to the database.
MM-12415 Logging of Header Rewrite actions is improved.
MM-12428 By default, restarting the Receiver does not restart the SpamProfiler process.
MM-12429 MailMarshal database did not support case-sensitive collations. Fixed. Use of case-sensitive collation is discouraged.
MM-12435 DMARC reporting included messages received from non-routable IP addresses. Fixed.

11.2.0 (September 4, 2025)

MM-9086 The MMUpdater service is removed. Upgrade of nodes from the Array Manager is not supported in current releases.
MM-9223 Sender thread count limits have been adjusted.
MM-11003 MailMarshal includes a new proprietary anti-phishing detection layer, D-Fence.
MM-11886 MailMarshal supports SMTP TLS Reporting (RFC-8460).
MM-11918 DKIM record checking validates the retrieved record against the expected value.
MM-11939 The version of the PDF unpacker that is included in the installation has been updated.
MM-11940 Default URLs for Blended Threat scanning and statistics retrieval are changed.
MM-11968 User group name validation allows dots and backslashes.
MM-12093 DMARC reports that cannot be delivered are no longer retried.
MM-12097 Performance issues related to User Statistics queries are resolved.
MM-12103 When the sending server triggers an IP reputation block in the Receiver, the connection is terminated.
MM-12112 Performance of insertion of DBLOG files to the database is improved with changes to SQL procedures and indexing.
MM-12132 For Service Provider Edition installations, configuration reload error handling is improved.
MM-12133 The Array Manager log includes better information if an invalid configuration string is detected.
MM-12134 Excess log lines from the DNS resolver are removed.
MM-12138 After upgrade, the Management Console website was unresponsive in browsers until a CTRL F5 full refresh was issued. Fixed.
MM-12155 Internet access from the Array Manager did not use the configured name servers. Fixed.
MM-12158 User statistic purge behavior is optimized.
MM-12159 The version of TLS libraries included is updated.
MM-12176 Sanitizing of URLs in the initial message body seen in digests is improved.
MM-12180 DNS lookup performance is optimized for higher loads.
MM-12183 DNSSEC status could be incorrectly returned as "bogus". Fixed: additional signature algorithms are made available.
MM-12190 DKIM key provision to processing nodes stopped on the first failed domain. Fixed: all available keys will be provided.
MM-12207 Reputation service lookups could fail in a small number of cases due to handling by specific DNS forwarders. Fixed.
MM-12212 The SpamProfiler cartridge (executable) included in the release has been updated.
MM-12213 The version of Visual C++ redistributable included in the install is updated.
MM-12214 The SpamProfiler cartridge (executable) included in the release has been updated.
MM-12219 ARC-SEAL generation handles messages with a null FROM address.
MM-12235 Older .mdmp files were not automatically deleted on a standalone Array Manager. Fixed.
MM-12245 The version of the archive extraction software included in the installation has been updated.
MM-12248 On import of older configurations, a file used by older versions of Image Analyzer is removed.
MM-12307 The installer check for the version of MSOLEDBSQL installed has been corrected.

11.1.0 (May 28, 2024)

MM-6913 MTA-STS validation is supported.
MM-8604 ARC-SEAL signing is supported.
MM-10986 The Receiver could become unresponsive after user group synchronization. Fixed.
MM-11112 Certain web access calls from processing node servers did not use the DNS servers configured in MailMarshal. Fixed.
MM-11413 The "commit configuration changes" notice could be slow to display for changes in mail server options. Fixed.
MM-11703 The version of the MSOLEDB driver included has been updated.
MM-11712 Encrypted connections to the SQL Server are supported.
MM-11747 Upgrade validation did not allow the fullstop character in user group names. Fixed.
MM-11748 The version of the web automation client library included is updated.
MM-11752 The version of TLS libraries included is updated.
MM-11767 For Service Provider Edition installations, TLS is not used on local loopback connections.
MM-11769 Settings and functions related to the former Cloud Email Archiving Service are removed from the product.
MM-11772 The MMArchiver service is removed. The Cloud archive functionality is no longer supported.
MM-11788 Email templates can now include a display name for the sender.
MM-11794 The Receiver could stop unexpectedly when checking certain malformed DKIM signatures. Fixed.
MM-11809 Labels on the Management Console Local Domains page did not display correctly. Fixed.
MM-11828 The Server Tool interface had minor display issues when run on Windows 11 or Windows Server 2025. Fixed.
MM-11829 The database schema is expanded to allow additional information about messages to be captured. Some examples of information captured in this release are: Message-Id, Return-Path, Reply-To, TLS information, Source Country, DKIM and ARC-Seal signatures, Threat Category, and time taken in processing.
MM-11831 The SpamProfiler cartridge (executable) included in the release has been updated.
MM-11835 The SHA256 hash of content files is logged to the database and available in Syslog templates.
MM-11857 DKIM selector names are correctly validated.
MM-11860 The version of the archive extraction software included in the installation has been updated.
MM-11872 The Receiver logs the source country for connecting IP addresses.
MM-11873 A timeout setting is available for TextCensor evaluation.
MM-11879 Default retention of DMARC data is reduced to 5 days.
MM-11896 The maximum size of images passed to Image Analyzer is increased.
MM-11902 When an image is oversized or invalid for scanning, Image Analyzer logs details in the message envelope to allow further actions.
MM-11907 URLs extracted from QR codes by Image Analyzer are reported in the Content Analysis log.
MM-11908 On upgrade, DKIM signing algorithm of SHA256 is enforced.
MM-11931 Notification of delay or failure in delivery over TLS is improved.
MM-11955 The Image Analyzer version included in the release has been updated.
MM-12047 The Controller service exists gracefully if the Json configuration file is invalid or missing.

10.2.5 (September 10, 2024)

MM-7378 The Console includes the ability to generate a plain language summary of email policy.
MM-7426 The Console validates copied and moved rules to prevent "go to rule" loops.
MM-7532 The Console includes the ability to copy a rule from one policy group to another.
MM-7592 The Console message viewer includes buttons to view the next or previous message.
MM-8950 Connector User Group selections for SpamProfiler and DHA did not display properly. Fixed.
MM-11421 The SQM Search function did not apply the user selection for delegated access to another user's messages. Fixed.
MM-11577 The Controller service could stop unexpectedly when processing certain recursive DNS CNAME queries. Fixed.
MM-11601 For group retrieval from Active Directory, the Array Manager logs the full path of the query, including the Domain Controller actually queried.
MM-11605 In release 10.2.0, the notice of available product upgrades was not presented on the Dashboard. Fixed.
MM-11660 After a change in system time format, login to the Management Console could fail. Fixed.
MM-11663 The Array Manager could stop unexpectedly when parsing certain unexpected values for Syslog logging.
MM-11665 The Connection rule "Reject non-matching TLS Client Certificates" is disabled by default for new installations.
MM-11667 The Console prevents copying rules with certain actions, based on the applicable direction.
MM-11684 The version of .NET installed is updated.
MM-11685 The version of Visual C++ redistributable included in the install is updated.
MM-11689 The version of the archive extraction software included in the installation has been updated.
MM-11695 The Array Manager could stop unexpectedly due to exceptions in Dashboard data processing. Fixed.
MM-11802 Message subjects containing the + symbol in plain text could be misinterpreted as Unicode. This issue has been fixed for many common cases.

10.2.0 (July 2, 2024)

MM-6930 Including certain characters in Executive Name text caused the Engine to stop. Fixed.
MM-10604 Manual backups of configuration could return a "task was cancelled" error due to timeout of the web interface. The backup was actually created. Addressed with a longer timeout in the web interface.
MM-11293 Message history could fail to display a message when the HTML body was invalid. Fixed.
MM-11114 Syslog could be enabled in the Console when no Syslog database was configured. Fixed.
MM-11415 The version of TLS libraries included is updated.
MM-11446 The calculations of trends over time used in the Dashboard could be incorrect for certain periods. Fixed.
MM-11447 The calculations of security scores in the Dashboard did not take account of rules that apply to both incoming and outgoing messages. Fixed.
MM-11449 DANE delivery was disabled when TLSA lookup returned a TempFail. Fixed: this temporary DNS failure will result in a retry.
MM-11455 It is possible to specify the AD domain controller to query for all uses of AD authentication.
MM-11456 MailMarshal supports SAML Single Sign On for the Management Console.
MM-11458 MailMarshal provides auditing of user account creation, permission assignments, and logins to the Management Console.
MM-11460 The version of .NET installed is updated.
MM-11509 Some files related to the Configuration Service were not correctly versioned. Fixed.
MM-11511 Deletion of nested unpacking folders could fail in rare cases. Fixed.
MM-11513 Image Analyzer logged excessive information. Fixed.
MM-11519 The list of file types passed to Image Analyzer has been optimized.
MM-11522 Deliveries that encountered certain failures in DANE evaluation were retried excessively. Fixed.
MM-11529 User groups used directly in rules and also as child groups, could be lost from the in memory copy in rare cases. Fixed.
MM-11530 Additional indexing of DMARC tables in the database has been included for performance where large numbers of domains are reported on.
MM-11534 The Image Analyzer version included in the release has been updated.
MM-11537 The SpamProfiler cartridge (executable) included in the release has been updated.
MM-11544 On upgrade to 10.1.0 if a specific named user group existed upgrade failed. Fixed.
MM-11566 Resource management for Image Analyzer is improved.
MM-11572 Child user groups could be lost from the in memory copy in rare cases. Fixed.
MM-11576 Management of resources used by Image Analyzer is improved.

10.1.0 (April 3, 2024)

MM-7272 In previous 10.X releases, the Management Console did not correctly display DKIM record status. Fixed.
MM-7413 Image Analyzer rules could be created when the feature was not licensed. Fixed.
MM-10759 The location of the Controller Temp folder can be configured with an entry in the JSON configuration file.
MM-10822 The limit on length of folder descriptions was not validated on entry in the Management Console. Fixed.
MM-10843 Certain values of Marshal Reputation Service credentials were not recognized as valid by the test in the Management Console. Fixed.
MM-10920 The FolderRetention variable is now available for use in notification templates as well as in digest templates.
MM-10955 The Receiver could stop unexpectedly when evaluating certain badly formed DKIM signatures. Fixed.
MM-10961 Logic to throttle message acceptance under high load is improved.
MM-10983 The version of .NET installed is updated.
MM-10984 For Service Provider Edition installations, the Syslog service uses the globally configured certificate for all customers.
MM-10985 Array Manager retry behavior during transient database errors is improved.
MM-11031 For Service Provider Edition installations, an option is provided to reject messages addressed with a domain part that is a non-routable IP address.
MM-11036 When editing the "Skip to specific rule" action it was possible to select a rule in a disabled policy group. Fixed.
MM-11037 Handling of failed Active Directory based authentication attempts in the Receiver is improved.
MM-11038 Validation of HTML entry in stamp and template editors disallowed the text "start". Fixed.
MM-11041 In release 10.0.7, if update of Visual C++ executables required a system restart, the installer exited with no warning. Fixed.
MM-11042 Parameters used to generate the certificate for the REST server have been updated for compatibility with current operating systems.
MM-11044 Management of unexpected conditions in Syslog record processing is improved.
MM-11049 The "last seen" column is removed from the IP Groups member detail listing. "Last seen" is not implemented for IP addresses.
MM-11097 DNS lookup supports DNSSEC.
MM-11108 The database connection string includes the "ApplicationName" attribute for better tracking.
MM-11160 Saving changes to Connector definitions did not correctly validate unchanged passwords. Fixed.
MM-11169 In rare cases, changes in user group membership were not propagated to processing nodes. Fixed.
MM-11210 The message move and delete actions now require selection of a "category" (malware, phishing, spam, or none) for use in the Dashboard.
MM-11232 Export of files from the Management Console failed with a "network issue" error in some recent client browser versions. Fixed.
MM-11242 Release 10.0.7 did not allow upgrade from 8.3.X releases. Fixed.
MM-11250 Image Analyzer now offers detection of many types of image content.
MM-11280 Outbound email delivery supports DANE.
MM-11359 The SpamProfiler cartridge (executable) included in the release has been updated. HTTPS communication with the SpamProfiler updater is enforced by default.
MM-11360 The version of Visual C++ redistributable included in the install is updated.

10.0.7 (September 29, 2023)

MM-7326 Quarantine Audit history can be viewed and searched from the Management Console.
MM-7416 In earlier 10.X versions, node servers could not be deleted from the installation through the Console. Fixed.
MM-8657 Specific formatting of IP address values in the HELO string caused SPF evaluation to fail. Fixed.
MM-10504 In earlier 10.X versions, some log lines were omitted from the Receiver logs. Fixed.
MM-10687 Outbound digests were not generated when the "operational user" was used for SQL connection. Fixed.
MM-10813 In the Management Console, selecting from a checkbox list with hundreds of entries returned the wrong item. Fixed.
MM-10830 SPF evaluation over-counted the number of DNS lookups required. Fixed.
MM-10845 SPF record macro expansion did not correctly expand IPv6 addresses. Fixed.
MM-10850 Import of configurations could fail if some specific values were included, due to an issue with parsing XML paths. Fixed.
MM-10909 MailMarshal uses an updated version of the TLS/SSL library.
MM-10926 Links containing querystrings in the text of a HTML message body (not within a HREF tag) were treated incorrectly by the BTM rewriter. Fixed.
MM-10954 Text logs showed an incorrect delay time on Syslog queue inserts for some actions. Fixed.
MM-10967 IP group membership was not correctly propagated to processing servers after complete refresh of the group with some continuing members. Fixed.
MM-10983 The version of .NET installed is updated to the current .NET 6 release 6.0.20
MM-10988 The SpamProfiler cartridge (executable) included in the release has been updated.
MM-10991 The version of Visual C++ redistributable included in the install is updated.
MM-10992 Universal C runtime updating is removed from the installer (not required by supported OS versions).

To review Release History for earlier releases, please see the Release Notes for the specific versions.

Legal Notice

Copyright © 2025 Trustwave Holdings, Inc.

All rights reserved. This document is protected by copyright and any distribution, reproduction, copying, or decompilation is strictly prohibited without the prior written consent of Trustwave. No part of this document may be reproduced in any form or by any means without the prior written authorization of Trustwave. Trustwave assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice.

The authors make no representation or warranties with respect to the accuracy or completeness of the contents of this document and specifically disclaim any implied warranties of merchantability or fitness for a particular purpose. No warranty may be created or extended by sales representatives or written sales materials. The advice and strategies contained herein may not be suitable for your situation. You should consult with a professional where appropriate. Neither the author nor Trustwave shall be liable for any loss of profit or any commercial damages, including but not limited to direct, indirect, special, incidental, consequential, or other damages.

Trademarks

Trustwave and the Trustwave logo are trademarks of Trustwave. Such trademarks shall not be used, copied, or disseminated in any manner without the prior written permission of Trustwave.

About Trustwave®

Trustwave helps businesses fight cybercrime, protect data and reduce security risk. With cloud and managed security services, integrated technologies and a team of security experts, ethical hackers and researchers, Trustwave enables businesses to transform the way they manage their information security and compliance programs. More than three million businesses are enrolled in the Trustwave Fusion® cloud platform, through which Trustwave delivers automated, efficient and cost-effective threat, vulnerability and compliance management. Trustwave is headquartered in Chicago, with customers in 96 countries. For more information about Trustwave, visit https://www.trustwave.com.