This is the latest release of Trellix Email Security - Cloud.
This release improves performance and detection through infrastructure and capacity enhancements to Trellix Email Security - Cloud 2026.2. This update also includes an enhanced user interface for a smoother user experience.
Announcements
Following their deprecation in December 2025 and end of support in March 2026, Alerts version 1 endpoints are officially decommissioned in this release.
Moving forward, please transition to using Alerts version 2 endpoints.
New Features and Enhancements
Justify releasing emails from quarantine
Trellix Email Security - Cloud now requires users and administrators to provide a justification when they release emails from quarantine.
You can configure this feature in two ways:
On the Quarantine page, select the checkboxes for the desired emails and select Release.
In the End User Features section, enable Justification for Quarantine release.
Monitor system warnings
Trellix Email Security - Cloud provides real-time visibility into the health of external integrations. You receive alerts when the system cannot communicate with authorization servers.
Monitor real-time connectivity errors and warnings for your integrations.
To access warnings from the past seven days, select the Bell icon in the upper-right corner of the page.
For XConsole users, select the Bell icon in the navigation menu.
View and filter user activity logs
You can view and filter user activity logs on the Trellix Email Security - Cloud. The system retains these logs for a maximum of 90 days. You can filter and search activities by date, action type, IP address, or subnet.
Configure quarantine reports for out-of-band domains
Trellix Email Security - Cloud now supports outbound quarantine reports for out-of-band (OOB) mode domains. Email Security - Cloud quarantines outbound messages that violate data loss prevention or custom policies.
Users receive an email digest and notifications for quarantined outbound messages. Administrators can associate quarantine report policies with OOB domains to monitor outbound traffic.
OOB domains display outbound quarantine report settings in the Policies - Outbound section.
Note
Email Security - Cloud does not display inbound quarantine settings for OOB domains. These domains only analyze email copies. They do not process inbound traffic inline.
Use new dashboard widgets and export data
The dashboard includes three new widgets: Threat Source, DMARC Authentication Report, and Campaign Activity. You can now export data to a CSV file for all the dashboard widgets.
Automated Cleanup for inactive users
End users with more than six months of inactivity are now automatically purged from the Users tab to maintain an optimized user list.
Fix for password-protected riskware detection
Password-protected files contained within archives will be detected and categorized as Riskware.
Resolved issues
The following issues were resolved in this release.
Tracking number | Description |
|---|---|
ETP-76145 | Fixes the issue where API requests using client credentials without associated domains returned a silent null response. The update now provides a clear warning message instructing users to configure domain access in the ETP portal. |
ETP-76553 | Fixes the issue where the On-Demand Quarantine email defaults to the standard template instead of the user's customized layout when an administrator resends an expired digest link. The update ensures that custom branding and logos are correctly applied during both link resets and new user creations. |
ETP-77309 | Fixes a TLS bypass bug where newly introduced tcp4 and tcp6 protocol options silently fell back to plaintext for Rsyslog integration. |