2025.5

Prev Next

Performance and detection have been improved through infrastructure and capacity enhancements to Trellix Email Security - Cloud 2025.5

Announcements

End-of-life for Alerts version 1 APIs

The existing set of Alerts APIs will be deprecated by 15th December, 2025. A new set of Alerts APIs was introduced in the release 2025.2. See Alerts APIs version 2 for the new set of Alerts APIs.

The older set of APIs will be called as Version 1/V1 and the new set of APIs will be called as Version 2/V2.

New features

Rescanning encrypted files with passwords

You can now independently rescan encrypted documents quarantined under riskware rule ID 65066 using the Rescan with Password button on the Quarantine page. By submitting one or more candidate passwords, you can enable the system to decrypt and analyze the attachments, eliminating the need for administrative or support intervention.

To improve visibility, emails containing password-protected attachments now has an Encrypted Attachment tag on the Quarantine and Email Trace pages. Also, functionality for both standard rescans and rescans with passwords has been expanded to support emails older than seven days.

License Status Message Updated on the Email Security - Cloud dashboard

The message displayed in the Email Security Cloud web portal license banner has been reworded. For accurate representation of the subscription details, refer to the My Subscription link on Trellix IAM.

Real-time notifications

This release enables instant notifications for emails quarantined by Rule 65066, featuring robust support for multiple verdict handling through QR policy integration. To ensure precise communication, these immediate alerts can be customized using configurable notification templates. Additionally, the interface has been organized for better usability, with the Email Digest template now located under the Notification Template category, along with the Instant Notification template.

Instant notifications can be enabled to notify the recipient when an email is quarantined and requires a password for rescan.

Data protection with Trellix Data Loss Prevention (Trellix DLP)

You can now integrate Email Security - Cloud with the Trellix DLP platform. This feature enables you to define DLP rules within ePO - SaaS and enforce corresponding actions (such as block or quarantine) directly through Email Security - Cloud policies.

Administrators can now leverage Trellix DLP rules to secure email traffic. The workflow consists of two parts:

  • Rule Definition: Configure your data protection rules in the ePO - SaaS platform.

  • Policy Enforcement: Map these rules to specific actions within the Email Security - Cloud policy interface to automate response handling.

    Note

    This feature is currently available in the US and EU regions.

    Trellix DLP is an add-on feature and requires a separate license to remove limitations.

IPv6 support for outbound notifications

Email Security - Cloud now supports IPv6 for rsyslog, offering a more secure and efficient network protocol. You can configure the connection based on your requirements: select TCP or UDP for a dual-stack configuration (IPv6 with IPv4 fallback), TCP6 or UDP6 for strict IPv6 usage, or TCP4 or UDP4 to maintain an IPv4-only environment.

You can modify the notifications settings from the following pages:

  • Trace streaming

  • Alert notifications

DMARC reporting and visualization

New capabilities streamline the management and analysis of Domain-based Message Authentication, Reporting, and Conformance (DMARC).

This feature is not applicable for OOB domain mode and decapsulation (inline domain mode).

  • Aggregate reporting — Email Security Cloud can now generate DMARC RUA reports for the sending domain. Administrators can enable this feature using message analysis policies associated with a domain configured as a first hop.

  • Report visualization — The system automatically processes incoming third-party DMARC RUA reports. You can view human-readable statistics for DKIM, SPF, and DMARC pass/fail rates directly in the user interface to assess your authentication posture.

Phishing simulator web UI updates

  • You can now choose to launch a Campaign immediately after creating it, using the Create Campaign Wizard.

  • You can unschedule and reschedule a Campaign from the Campaign Details page.

  • You can also view the email delivery messages in the Users table on the Campaign Details page.

Email Trace updates

You can now track alerts, alert summaries, and digest emails on the Email Trace page, and verify notifications sent through the relay. These records can be easily located by selecting the new notification tag in the search filter. To ensure reporting accuracy, these notification emails are excluded from general traffic statistics.

Resolved issues

The following issues were resolved in this release.

Tracking number

Description

ETP-72348

Resolves an issue where the Email Trace page did not display logs for digest generation or alert notifications, preventing visibility into generation times and SMTP delivery strings.

ETP-73657

Fixes an issue where the system treated temporary DKIM and SPF failures as permanent DMARC failures, resulting in email rejection. Temporary authentication failures are now correctly handled by deferring the incoming email.

ETP-74016

Fixes an issue where the Top Recipient field in the Spam widget incorrectly displayed the sender address.