Performance and detection have been improved through infrastructure and capacity enhancements to Trellix Email Security - Cloud 2025.3.
Announcements
License expiry announcement on the dashboard
If your Trellix Email Security - Cloud licenses are set to expire, it will be announced in a yellow banner on the top of your dashboard 30 days prior to expiry. Once your licenses expire, an announcement in a red banner will highlight a grace period of 90 days.
For more details, see Licenses.
End-of-life for Alerts version 1 APIs
The existing set of Alerts APIs will be deprecated by 15th December, 2025. A new set of Alerts APIs was introduced in the previous release. See Alerts APIs version 2 for the new set of Alerts APIs.
The older set of APIs will be called as Version 1/V1 and the new set of APIs will be called as Version 2/V2.
New features
Integration of alerts with threat intelligence
Indicators of compromise (IOCs) can now be analyzed using threat intelligence. You can now avail detailed information about MD5, SHA256, IPS, domains and URLs in the Threat Intelligence tab in the Message Details page of an alert. You can view the last seen date and time, severity, campaign details and source for all IOCs.
For more details, see Alert details.
Set spam threshold level
You can now set the spam threshold level for message analysis policies to filter out probable spam messages. You can select from a menu of three levels - low, medium and high. You can also search for emails in the Email trace page using the Spam level tag.
For more details, see Message analysis policy under Hygiene settings.
Enhancements
Managing connect rules in bulk
You can now enter or delete multiple connect rules as line-separated values. If your values are in a CSV file, you can copy the column of required values altogether and paste in the specific field.
For more details, see Connect rules.
Entering multiple options for custom rules
You can now add multiple options separated by the OR condition for Apply the rule if in custom rules. For example, if you add 4 OR options, the custom rule will be applied even if any one of them is true.
For more details, see Custom rules.
Associate additional policies with newly created domains
While configuring a domain using the domain provisioning workflow you can now select additional policies in the 5th section, Additional Policies, to associate with the domains : custom rules, YARA rules, connect rules, advanced threat engine configuration, quarantine report and riskware policy.
For more details, see Domain provisioning workflow.
Release or delete quarantined messages in bulk
You can now release or delete all or filtered emails in bulk, from the Quarantine tab. This feature is available for both inbound and outbound emails. You can release or delete a maximum of 10000 messages at once.
For more details, see Managing quarantined emails.
Searching user activity
You can now search user activity logs by IPs as well as subnets since both IPv4 and IPv6 addresses are logged.
For more details, see User activity logs.
Resolved issues
The following issues were resolved in this release.
Tracking number | Description |
|---|---|
ETP-70282 | Fixes an issue where the RBL evaluation verdict was unable to provide adequate information about detection. |
ETP-72478 | Fixes an issue on the Alerts page where the order of sorting the table changed on applying other filters. |
ETP-72963 | Fixes an issue where alert notification emails for alerts generated due to an inbound email were being sent to both inbound and outbound additional recipients, instead of only inbound recipients (and vice versa for outbound alerts). |
ETP-73106 | Fixes an issue where the quarantine API endpoint was unable to filter results using the From field. |
ETP-73117 | Fixes an issue where the queue threshold monitoring was not honoring domain RBAC rules. |
ETP-73198 | Fixes an issue where new client credential usage was not being properly registered, resulting in unexpected errors. |