• Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
  • English English English en
  • Deutsch Deutsch German de
Sales: +49 5251 304-800 | Support: +49 5251 304-636
NoSpamProxy
  • PRODUCT
    • NoSpamProxy Cloud
    • NoSpamProxy Protection
    • NoSpamProxy Encryption
    • NoSpamProxy Large Files
    • NoSpamProxy Disclaimer
    • NoSpamProxy 25Reports
  • SOLUTIONS
    • M365 Mail Security
    • Managed Certificates
    • 32Guards
  • RESOURCES
    • Documentation
    • Forum
    • Webcast Training
    • Training Courses
    • Support
    • Software Download
  • PARTNERS
    • Finding Resellers
    • Becoming Reseller
    • Partner Portal
    • NFR Licenses
  • COMPANY
    • Contact
    • Testimonials
    • Team
    • Career
    • Events
    • Awards
  • PRICES
  • BLOG
    • Blog
    • Newsletter Subscription
  • FREE TRIAL VERSION
    • Price Request
    • Free Trial Version
  • English
    • Deutsch
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • VS-NfD Verschlusssache nur für den Dienstgebrauch

VS-NfD and email security: What IT administrators need to know

Stefan Feist | Technischer Redakteur
Author: Stefan FeistTechnical Writerhttps://www.linkedin.com/in/stefan-feist-23b257b0/–Connect on LinkedIn

The term VS-NfD is often used in connection with the secure handling of sensitive information in public authorities and companies. In our blog article, you can find out what VS-NfD is, why knowledge of it can be essential for your IT security, and how NoSpamProxy can also protect your organization securely.

08.09.2025|Last edited:05.09.2025

What is VS-NfD?

The abbreviation stands for “Verschlusssache – Nur für den Dienstgebrauch” (confidential information – for official use only) and denotes the lowest of the four official levels of confidentiality in Germany. It is used when unauthorized access to information may not be life-threatening, but could nevertheless be harmful to federal interests.

Examples include the communication of internal technical documentation by a government agency or the disclosure of confidential contract details by a company in the context of a public contract – both typically fall under the VS-NfD category.

In addition to VS-NfD, there are three other levels of confidentiality:

  • VS-Vertraulich (Confidential)

  • VS-Geheim (Classified)

  • VS-Streng geheim (Top Secret)

With each level, the requirements for organization, technology, and data handling increase. However, VS-NfD is by no means a “ relaxed” classification.

VS-NfD entails clear security requirements, particularly with regard to email communication, because information, for example on internal processes at public authorities or the police, could help attackers. However, because this information is not classified as state secrets (but “only” organizational details worthy of protection), it is not upgraded.

VS-NfDVS-Vertraulich (Confidential)Geheim (Classified)Streng geheim (Top Secret)
For official use onlyIf disclosure could harm the interests of the Federal Republic of GermanyIf disclosure could seriously jeopardize the security of the Federal Republic of GermanyIf disclosure could jeopardize the existence or vital interests of the Federal Republic of Germany
VS-NfDVS-Vertraulich (Confidential)Geheim (Classified)Streng geheim (Top Secret)
For official use onlyIf disclosure could harm the interests of the Federal Republic of GermanyIf disclosure could seriously jeopardize the security of the Federal Republic of GermanyIf disclosure could jeopardize the existence or vital interests of the Federal Republic of Germany

What are the VS-NfD requirements?

The requirements for email communication under VS-NfD can be summarized in three key points:

    • Confidentiality

    • Integrity

    • Protection against malware

    The confidentiality of communications should be ensured by strong encryption, typically using OpenPGP or S/MIME, implemented with algorithms such as AES-256 or RSA-4096.

    The integrity and authenticity of messages should be secured by digital signatures so that the recipient can immediately recognize whether an email actually originates from the specified sender and is unaltered.

    Malware detection is also a key issue. Encrypted emails must be decrypted and checked in a protected environment without compromising the security of the classified information.

    Secure email gateways and VS-NfD

    To ensure VS-NfD-compliant operation, a gateway must offer functions that go beyond pure transport encryption. The tool should support centralized encryption and signing, operate as automated as possible, and simplify certificate management.

    Furthermore, on-premises operation is usually necessary to ensure full control over key material and sensitive data. In addition, mechanisms for malware detection are also required for encrypted content.

    It is important to mention that the BSI currently only considers and approves client-based encryption solutions for VS-NfD – gateways are deliberately excluded here. Not because they are considered insecure, but because it would make the corresponding profile considerably more complex.

    For this reason, there will be a separate profile for gateway-based encryption in the future.

    Which solutions does the BSI recommend?

    In recent years, the German Federal Office for Information Security (BSI) has officially approved various solutions for VS-NfD. However, there are currently no secure email gateways on the list of approved products (see above). Nevertheless, many public institutions and authorities use NoSpamProxy because the solution meets many of the key requirements of VS-NfD:

    • Secure encryption (S/MIME, PGP) with modern certificate management
    • Protection against malware through integrated anti-malware module
    • Central control & automation: Key management, encryption, and signing are performed centrally; encrypted emails are processed directly at the gateway.

    NoSpamProxy is BSI-certified*

    NoSpamProxy is the first and so far only email security product to be tested and certified by the BSI as part of its Accelerated Security Certification (BSZ) program. The test involved realistic attack scenarios, penetration tests, and evaluation of the central Protection and Encryption modules. No security vulnerabilities were found.

    This certification is particularly useful for government agencies and security-oriented organizations, as it provides a reliable statement about the product’s resilience.

    Conclusion

    VS-NfD may be the lowest level of confidentiality, but the IT security requirements are high. For administrators, this means that encryption, signatures, malware protection, and secure configuration are mandatory when confidential data is transmitted via email.

    Not yet using NoSpamProxy?

    NoSpamProxy provides reliable protection for your company against dangerous emails. Request your free trial now!

    Get your free NoSpamProxy trial now!

    *NoSpamProxy Server version 14.0.5.62 was used for certification, and the certificate was issued for this version.

    • share 
    • share 
    • share 
    • email 

    SEARCH

    PRODUCT

    • All Topics
    • NoSpamProxy Cloud
    • NoSpamProxy Protection
    • NoSpamProxy Encryption
    • NospamProxy Large Files

    You need support?

    You can find more information about NoSpamProxy in our documentation and forum.

    CATEGORY

    • All Topics
    • News
    • Product
    • Tech & Support
    • Events

    NoSpamProxy Newsletter

    Subscribe to Newsletter
    RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed

    NoSpamProxy

    • NoSpamProxy Cloud
    • NoSpamProxy Encryption
    • NoSpamProxy Large Files
    • NoSpamProxy Disclaimer
    • Price request
    • Team
    • Career
    • General terms and conditions
    • Data Protection Information for Business Partners and Applicants
    • Cybersecurity (PSIRT)

    Partners

    • Becoming a reseller
    • Partners
    • Order Certificates
    • Newsletter

    Categories

    • All topics
    • News
    • Support
    • Updates
    • Order certificates

    Latest News

    • Gelöschter SPF-Eintrag: Warum DNS-Alarmierung unverzichtbar ist 800x800
      When the service provider deletes the SPF record: Why DNS alerts are essential16.01.2026 - 10:00
    • Link Wrapping als Angriffsvektor 800x800
      Link wrapping as an attack vector05.01.2026 - 10:02
    • Info Icon
      React vulnerability: NoSpamProxy is not affected12.12.2025 - 13:00
    IMPRINT • EULA • Privacy Policy • • © 2026 Net at Work GmbH
    • Link to Rss this site
    • Link to LinkedIn
    • Link to Youtube
    • Link to X
    • Link to Instagram
    Link to: NoSpamProxy 25Reports offers full DMARC transparency Link to: NoSpamProxy 25Reports offers full DMARC transparency NoSpamProxy 25Reports offers full DMARC transparency Link to: Attack on node.js: No danger for NoSpamProxy customers Link to: Attack on node.js: No danger for NoSpamProxy customers Info IconAttack on node.js: No danger for NoSpamProxy customers
    Scroll to top Scroll to top Scroll to top