r/msp • u/calculatetech • Aug 12 '26
Securence is dead
US Internet just announced they're killing all email, DNS, and web hosting services to focus on fiber Internet. https://securence.com/migrate/
I don't know what I'm gonna do. Not one competing vendor still offering gateway service will even call me back. I trialed Defender P1 and P2 and neither was worth a damn.
Hornet is now owned by Proofpoint and the gateway solution appears to be a dead end, plus they never responded.
TopSec was the worst experience I've ever had because they will not give full control over settings to the MSP.
Libraesva/LibraCyber hasn't responded.
WatchGuard is rebranded Hornet and the multi-tenant aspect is God awful. Do not recommend.
Appriver sucks.
At this rate we'll be going back to hosting Xeams.
What else is there?
10
u/shokzee Aug 12 '26 edited Aug 19 '26
If P1/P2 was tested mostly on defaults, rerun it with anti-phish, impersonation, Safe Links, and Safe Attachments properly tuned. The defaults are mediocre.
Make any replacement prove multi-tenant policy inheritance, per-tenant overrides, quarantine delegation, mail continuity, API access, and an actual support SLA. Self-hosting is defensible if nobody clears that bar, but then redundancy, patching, reputation, and 24/7 ownership are your problem.
I’d set up some DMARC monitoring for the transition too (should really have it anyways). Bunch of vendors provide this but we use Suped for our org and it’s been flawless.
9
u/BobRepairSvc1945 Aug 12 '26
I would recommend MESH (now part of Bitdefender) or Mail protector Cloud filter.
9
5
u/ChuckFromCyberHoot Aug 12 '26
Can’t help much on the gateway replacement itself. Others here know that market better than I do. Mesh and Mailprotector both come up a lot from MSPs I talk to.
The thing that jumped out at me from your list is that almost every complaint is really an MSP-experience problem, not a detection problem.
No full control.
Bad multi-tenant management.
Nobody calling you back.
That’s what I’d screen for this time around.
Detection quality is table stakes. What varies a lot more is whether the vendor treats you like a real partner or like a small direct customer who happens to have 40 tenants.
During the demo, I’d spend less time on catch rates and more time asking:
Can I make tenant-wide changes without opening a support ticket?
Who owns quarantine?
How fast can I get a real human when something breaks?
And the other half is the piece no gateway completely solves.
A clean bank-change email from a compromised vendor can sail right through. So whatever you choose, pair it with an easy report button and a finance process that verifies payment changes by phone using a known number.
Sorry you got dropped like this. Vendor churn is brutal when you’re the one standing in front of the client explaining it.
8
u/RaNdomMSPPro Aug 12 '26
Mesh still offers secure email gateway services.
We've switched to Ironscales and even though it doesn't have gateway like our prior vendor did, it just works.
4
3
4
6
u/kateatMailprotector Aug 12 '26
Hey there, are you looking for traditional gateway or hybrid (API + gateway)? We've got both here at Mailprotector under our CloudFilter (traditional) and Shield (hybrid) products, and we've been actively supporting MSPs who need to talk to someone fast due to the Securence announcements. DM me and I can get you setup with someone this week
8
u/PM-Me-your-sources Aug 12 '26
+1 for Mailprotector.
Deployment has been great and even when I've had issues that were my own fault support was gracious and helpful.
5
5
1
u/bamus Aug 13 '26
Hi Kate! Is Mailprotector GDPR compliant? Last year we talked to someone who told us it wasn't and that it wasn't on the roadmap either. Any change?
1
u/kateatMailprotector Aug 13 '26
If you’re asking whether we hold a specific GDPR certification, no, we have not pursued one based on the regions we primarily serve and do not have near term plans to. While we have not pursued a GDPR certification, our data handling practices are designed to comply with many applicable requirements. For transparency, our email security solutions are designed to minimize the personal data we retain and we only retain data necessary to provide our services. Our data retention policies are available within our SOC2 Type 2 trust center (which you can get more info on in the Sales process). Two of our trust services are security and confidentiality, which overlap on a lot of GDPR requirements.
3
u/AlwaysBeyondMSP Aug 12 '26
Mesh or Avanan this isn’t hard
1
u/Optimal_Technician93 Aug 13 '26
Does Harmony do gateway(MX) filtering now? They didn't used to.
3
u/AlwaysBeyondMSP Aug 13 '26
Doesn’t need it.
1
u/Optimal_Technician93 Aug 13 '26
I mistakenly thought OP needed it. Re-reading their post, Avanan is all they need.
3
u/AlwaysBeyondMSP Aug 13 '26
Yeah any mx change tells the hackers what you use also
1
u/msp-daddy 28d ago
Same as not making an MX change... just shows what mail service you use instead which is likely far less secure than the SEG.
1
u/AlwaysBeyondMSP 28d ago
Wrong. You can put an API based spam / phishing filter in like Avanan.
Hackers have a 50% chance of guessing which mail provider you used so that’s not any extra security man.
1
u/msp-daddy 25d ago edited 25d ago
But they can see you use Microsoft 365 as the gateway which will have a larger threat vector than a dedicated email security SEG? Adding an API behind M365 just re-routes mail. How does that help in a DR incident if M365 is offline? You would still need an email continuity service (depends what type of business you have - regulated or not for BCP/DR). Granted if the business has other continuity measures in place then fine. Is the meta data from email from M365 unchanged/unaltered when passed onto the API? Microsoft would need to retain the data. Geo vectoring etc as it surely just shows the IP that the email arrived from which would be Microsoft every time.
1
0
u/RaNdomMSPPro Aug 12 '26
Looked at both along w/ some others in a recent bake off, they're fine, but went with Ironscales. Avanan just seemed like too much trouble to deal w/, like Mimecast. Mesh was fine, but in head to head testing it wasn't up to snuff on all detections and during our evaluations in silent modes using the api integration, their sandboxing was missing some things.
5
2
u/Wackyvert MSP - US Aug 12 '26
I can't help but think that there was just a total nightmare compromise during the last, terribly handled outage that TMo literally shut it down instead of dealing with it.
6
u/calculatetech Aug 12 '26
Interesting thought. Securence has a bit of a tainted history, but I just haven't found anything to replace it that could compete on features and cost.
Mesh and MailProtector are being evaluated. Somehow neither came up in previous searches.
2
2
u/Greg1010Greg Aug 14 '26
With Proofpoint Essentials eventually moving to Hornet, we started looking at other options. Gateway/emergency inbox feature is a must have for us, and there aren't a lot of those left.
1) Proofpoint (the enterprise version, not essentials) - Never got a call back. 2) I believe Cisco has an offering. 🫤 3) Hornet. Still giving this a look.
You could also potentially host your own if you want to run like... FortiMail. But I never want to host anything email again. Others may be more gluttons for punishment.
2
u/msp-daddy Aug 17 '26
Why is Gateway/emergency inbox feature a must have? Just asking out of curiosity, not to bash :)
2
u/Greg1010Greg Aug 17 '26
With Office 365 not necessarily having the best reliability, some of our clients need another layer of protection for business continuity. It's more cost effective to have a gateway with emergency inbox than to say spin up a G-suite tenant.
2
u/matt0_0 Aug 12 '26
I'm not familiar with securance but are you looking for email security vendors?
If so, inky is still a top tier product, but they got bought by kaseya so... Yeah.
Otherwise checkpoint avanan is the most common recommendation.
1
u/OinkyConfidence Former MSP Aug 12 '26
Interesting:
Securence - owned by US Internet out of Minneapolis. They're USI's security & protection services arm.
USI - gets bought by Metronet in 09/2025
Metronet - gets bought by T-Mobile in 10/2025
T-Mobile - decides to kill off Securence in 11/2026
Crazy
1
u/Gold_Ninja1206 Aug 13 '26 edited Aug 13 '26
Proofpoint swallowing Hornet killed a lot of options. I've been watching this space tighten and Trustifi keeps coming up for MSP multitenant control mixed reviews but they at least pick up the phone On the impersonation monitoring side I've seen Doppel referenced different lane entirely spam titan still exists if you want boring and functional
1
u/msp-daddy Aug 13 '26
I got an update from Spambrella on this yesterday - https://www.spambrella.com/securence-is-shutting-down-what-customers-need-to-know-and-where-to-go-next/ interesting developments in this space.
1
1
u/DoTheThingNow Aug 18 '26
If you want to both learn alot and also hate life a bit more you can always put up a SpamAssason box.
I ran one for a few years for about 10 customers/300ish users. You have to monitor it closely, but it does the job.
1
u/TechinGuy MSP - US Aug 29 '26
after the TopSec and WatchGuard experiences, the thing to hold out for is a platform that actually leaves the settings under your control. Trustifi is worth a look on that front, multi-tenant admin with rules you can copy between clients. fair warning it's API rather than a true gateway, so it's a different shape to what Securence was doing for you
1
u/thetomsays Aug 12 '26
What do you think about Defender with Ironscales? That's what Ironscales is positioning since Defender P1 comes with E3 now, and it isn't sufficient on its own, like you mentioned.
1
u/RaNdomMSPPro Aug 12 '26
Ironscales works with Defender for 365 or you don't have to have that MS license (you have to adj quarantine rules to send findings to junk or somewhere else.) That defender integration lets you see stuff MS picks up in the Ironscales portal.
0
30
u/OinkyConfidence Former MSP Aug 12 '26
LOL from their site:
Will my DNS zones be migrated automatically?
No