Performance and detection have been improved through infrastructure and capacity enhancements to Trellix Email Security - Cloud 2025.4
Announcements
Trellix IAM for federated organizations
Trellix IAM is now active for federated organizations. To manage Email Security — Cloud, administrators must enroll in Trellix IAM. This requirement does not apply to regular users who are protected by the service.
XConsole integration
XConsole is now enabled by default, providing direct access to Email Security - Cloud from a single, unified platform.
End-of-life for Alerts version 1 APIs
The existing set of Alerts APIs will be deprecated by 15th December, 2025. A new set of Alerts APIs was introduced in the release 2025.2. See Alerts APIs version 2 for the new set of Alerts APIs.
The older set of APIs will be called as Version 1/V1 and the new set of APIs will be called as Version 2/V2.
New features
ACE Alert filter
Managing alerts is now simpler with the addition of the 'Alert Type' filter. For quicker identification, alerts created by the Advanced Correlation Engine (ACE) via the Network Security appliance integration will be visually highlighted using the new ACE icon.
For more details, see Filtering alerts.
Scheduling campaigns using Phishing Simulator
You can now schedule Phishing Simulator campaigns to run at a future date and time. This provides greater flexibility, allowing campaigns to be sent to all users at once or staggered in smaller batches over a period.
For more details, see Managing campaigns.
Enhancements
Improved user sync
The API integration enhancement with Microsoft and Google reduces the activation time for push notifications. As a result of this improvement, the manual Sync button has been removed from the Domain setting page.
Search history for Alerts
You can now manage your search history in the Alerts tab. In Advanced mode, you can view past searches, delete individual entries, or clear the entire history.
For more details, see Filtering alerts.
Alerts casefile download options
The password-protected zipped case file from the Alerts details page now contains an alert.json file along with the existing the malware case file, a copy of the malicious email, and the associated malware.
For more details, see Alert details.
Improved Portal Access and Alert Notifications UI
The Portal Access and Alert Notifications pages now has an improved user interface design. You can now bulk-manage IP addresses by entering or deleting multiple line-separated values at once. This allows you to easily copy and paste an entire column of values directly from a CSV file.
For more details, see Portal access and Alert notifications.
Resolved issues
The following issues were resolved in this release.
Tracking number | Description |
|---|---|
ETP-73477 | Fixes an issue where a custom rule policy could not be saved on using a hash character. |
ETP-73579 | Fixes a web UI issue in Custom rules where a group of Except if conditions incorrectly showed AND operators, when the actual logic being applied is OR. |
ETP-73903 | Fixes an issue where the outbound delivery test would fail with a contact hostname error when TLS was enabled. |