Using Content Encryption for Messaging Gateway
search cancel

Using Content Encryption for Messaging Gateway

book

Article ID: 413037

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

Table of Contents

  • Changes to Content Encryption for existing Messaging Gateway (SMG) Customers
  • Obtaining a Policy Based Encryption (PBE) license
  • Provisioning of the PBE infrastructure
  • Configuring Messaging Gateway Content Encryption relay and rules
  • Renewing Content Encryption through a third-party provider

Resolution

Changes to Content Encryption for existing Messaging Gateway (SMG) Customers

Beginning in September 2025, with the release of Messaging Gateway 10.9.2, the Content Encryption feature no longer requires a separate license to enable and configure. New licenses and renewals specifically for the Messaging Gateway Content Encryption feature are discontinued.

Note: The SMG 10.9.2 licensing page (Administration > Licenses) still shows a line item for Content Encryption. This license status is now ignored by Messaging Gateway and will be removed in a future release.

Obtaining a Broadcom Policy Based Encryption License

Although Messaging Gateway itself no longer requires a license to configure an use the Content Encryption relay features, to continue using email content encryption provided by Broadcom, the service must be licensed under the Email Security Cloud Policy Based Encryption (PBE-PGP-EMAIL-SUB) SKU.

Engage with Broadcom or your partner sales team to purchase a license for Email Security Cloud Policy Based Encryption (PBE-PGP-EMAIL-SUB)

Provisioning Content Encryption

Reprovisioning the service for Broadcom Policy Based Encryption (PBE) is required for all customers to update the content encryption relay.

  1. Complete the provisioning form included with the Email Cloud Policy Based Encryption order. You must fill out the provided provisioning form to start the creation of the secure portal instance. If you have not received this form, reach out to your sales team who is currently helping you with this purchase. A copy is also attached to this article.
  2. Once the provisioning form has been completed and submitted it will take approximately five business days to provision the new Content Encryption / Policy Base Encryption infrastructure.
  3. Once the administrative contact listed on the provisioning form receives an email notification with the SMTP host and port once provisioning is complete.

Configuring Messaging Gateway Content Encryption relay and rules

The notification that provisioning is complete will include the SMTP host and port for the Content Encryption relay. Messaging Gateway must be configured with this information to route email traffic to the new infrastructure.

  1. Log into the SMG Control Center as an adminisrator
  2. Navigate to Content > Content Encryption.
  3. Enter the provided SMTP host and port in the relay host configuration.

Once the Content Encryption relay has been configured, the "Deliver with Content Encryption" policy action can be applied to Messaging Gateway Content Filtering policies to securely deliver messages to the email encryption service

To renew Content Encryption through a third party encryption service provider

  1. Engage with your encryption service provider of choice and complete their provisioning process
  2. The encryption provider should provide a hostname or IP address to which SMG should deliver messages for content encryption
  3. Configure Messaging Gateway to use the provided relay host via the Content > Content Encryption page

Note: Third party encryption providers may have additional requirements to access their content encryption servers.

Additional Information

Attachments

PGP Email - Customer Provisioning Form - Sept 2025.docx get_app