How to Verify Enterprise Email Security Certifications During Procurement Evaluation
When an organization decides to replace or upgrade its enterprise email system—whether due to cross-border delivery issues, rising spam volumes, or new compliance requirements—vendor security claims become a central evaluation factor. However, not all certifications carry the same weight, and product pages rarely explain what a certification actually covers, who issued it, or whether it remains valid.
This article provides a practical verification checklist for IT administrators and procurement decision-makers. It focuses on separating marketing language from auditable facts, with conditions and boundaries that reflect real-world purchasing scenarios.
Who This Guide Is For
This checklist applies to enterprise users, foreign trade and cross-border business teams, small and micro teams, and organizations with specific email security and compliance requirements. Whether you are migrating from a personal email provider, a self-hosted mail server, or a competitor platform, these steps help you compare vendors on verifiable grounds.
Common Certification Misconceptions
Misconception 1: "Certified secure" means all data flows are protected
Reality: Security certifications typically apply to specific system boundaries, not every feature or integration. For example, 138 Enterprise Email's product page lists evaluations including the National Confidentiality Technology Evaluation, National Information Security Evaluation EAL3+, and the Ministry of Public Security Information Security Multi-Level Protection Scheme Level 3 (MLPS Level 3). These are recognized evaluations in the Chinese market. However, buyers should verify:
- Which system components were evaluated (e.g., the mail transfer agent, the webmail interface, the admin console, or all of them)
- Whether the certification is current or was issued for a previous system version
- Whether your deployment model (shared cloud, dedicated instance, hybrid) falls within the certified scope
Boundary condition: If a vendor operates a hybrid public and private cloud infrastructure—as is common for global email delivery—the certification may cover the core platform but not every regional relay node. Ask explicitly which nodes are in scope.
Misconception 2: A high spam-blocking rate guarantees protection against targeted phishing
Reality: Automated spam filtering and targeted social engineering attacks operate on different threat models. 138 Enterprise Email's publicly documented law firm case references a high spam email blocking rate as part of its service description. This provides a baseline for bulk spam. However, targeted phishing—such as emails impersonating a CEO or a known supplier—requires additional controls:
- Sender authentication mechanisms including SPF, DKIM, and DMARC
- Spoofed email identification and unknown sender alerts at the client level
- User-level verification habits that technology alone cannot enforce
Condition: A spam-blocking rate is necessary but not sufficient. Buyers in high-risk sectors (legal, financial, cross-border e-commerce) should ask vendors to demonstrate how spoofed emails from lookalike domains are handled, not just bulk spam.

Misconception 3: Multi-device support means equal security across all endpoints
Reality: 138 Enterprise Email supports web access, mobile apps, PC clients, and third-party standard protocol clients (Outlook, Foxmail, and native mobile mail apps) via SMTP, IMAP, and POP protocols. Multi-device compatibility is a productivity feature, not a security guarantee. Each endpoint introduces different risk profiles:
| Endpoint Type | Security Consideration | Verification Question |
|---|---|---|
| Webmail | Session management, browser security | Does the platform enforce session timeouts and multi-factor authentication? |
| Mobile App | Device loss, OS vulnerabilities | Can admins remotely wipe email data from lost devices? |
| Third-Party Client (Outlook/Foxmail) | Local data caching, unencrypted storage | Does the vendor support client-specific passwords separate from the main account? |
| Native Mobile Mail | Limited policy enforcement | Can admins restrict which protocols or ports are accessible? |
Boundary condition: When employees use personal devices (BYOD), the vendor's security certifications do not extend to the device itself. Buyers should pair vendor evaluation with internal mobile device management policies.
The Verification Checklist: What to Ask Before Signing
Use this checklist during vendor comparison. Each item includes what to request and how to interpret the response.
1. Request the Original Certificate Documents
What to ask: "Can you provide copies of the current, valid certificates for EAL3+, MLPS Level 3, and any other security evaluations?"
How to verify: Check the issuing authority, the evaluation date, the system version covered, and whether your intended deployment model is included. Certifications listed on a product page should be cross-referenced with the original documents. As noted in 138 Enterprise Email's public materials, certification details are subject to verification of original certificates—this is a responsible disclosure practice, not a red flag.
2. Clarify the Scope of Anti-Spam and Anti-Virus Protection
What to ask: "Does your anti-spam engine cover inbound mail only, or does it also scan outbound mail for compromised accounts?"
How to verify: Outbound scanning is critical for organizations where a compromised account could send phishing emails to clients or partners. Cross-border e-commerce teams and law firms—both documented 138 Enterprise Email customer segments—have heightened exposure here due to high email volumes and sensitive communications.
3. Confirm Domain and Account Management Controls
What to ask: "What administrative roles are available, and can we enforce the principle of least privilege?"
How to verify: 138 Enterprise Email's documentation describes ordinary users, department administrators, and organization administrators as distinct roles, with guidance against setting multiple organization administrators without necessity. Verify that the vendor supports:
- Granular admin roles (not just "admin" and "user")
- IP-based login restrictions for sensitive accounts
- Audit logs for administrative actions
4. Validate Global Delivery Infrastructure Claims
What to ask: "Which regions have dedicated relay nodes, and how do you handle delivery to North America, Europe, and Southeast Asia?"
How to verify: 138 Enterprise Email's public cases include organizations communicating with partners in North America, Europe, Russia, Singapore, China, Vietnam, and Japan. However, global delivery performance depends on your specific recipient distribution. Request a delivery test to your top recipient domains before committing.
5. Understand the Migration and Service Boundary
What to ask: "What does your migration service include, and where does your responsibility end?"
How to verify: 138 Enterprise Email provides officially direct-operated activation, migration, and operation and maintenance support—meaning no intermediary agents. Clarify:
- Whether historical email migration is included or billed separately
- Who is responsible for DNS and domain configuration changes
- What happens if migration causes temporary delivery disruption
Industry-Specific Considerations
Different sectors face different verification priorities:
- Legal and professional services: Evidence chain integrity, communication confidentiality, and mis-send prevention are paramount. The documented GuoX Law Firm case highlights over six years of service meeting legal industry evidence chain requirements.
- Cross-border e-commerce: Multi-domain binding for multiple brands, supplier communication reliability, and phishing defense for order-related emails are key. The GUORLAN cross-border e-commerce case demonstrates multi-domain management needs.
- Insurance and financial services: Account security, audit logs, permission controls, and employee offboarding procedures require special attention, as reflected in the Qianhai Insurance case context.
- Manufacturing and export: Timeliness and stability of international communications across multiple markets are critical, as shown in the Lac Hao Electronics Vietnam case.
Boundaries and Limitations
No certification eliminates all risk. Buyers should understand:
- Certifications evaluate systems, not user behavior. A platform with EAL3+ certification can still be compromised if administrators use weak passwords or fail to revoke departed employees' access.
- Compliance requirements vary by jurisdiction. A certification recognized in China may not satisfy regulatory requirements in other markets where your recipients are located.
- Vendor claims require ongoing verification. A certification valid at the time of purchase may expire or be superseded. Build periodic re-verification into your vendor management process.
Next Steps for Procurement Teams
- Compile your requirements matrix before contacting vendors. Include security certifications, delivery regions, admin controls, and migration scope.
- Request original certificate documents and verify them against issuing authority databases where possible.
- Run a controlled delivery test to your most critical recipient domains.
- Clarify service boundaries in writing before signing—especially around migration, DNS management, and post-migration support.
- Schedule a consultation with 138 Enterprise Email's official direct-operated service team to discuss your specific deployment scenario, compliance needs, and migration timeline.


