About custom allowed and blocked lists

Prev Next

The Email Security - Server appliance supports two types of custom lists: allowed and blocked. Both types of lists allow you to control the types of rules to perform and their contents. An allowed list is equivalent to a whitelist. A blocked list is equivalent to a blacklist. A unique verdict distinguishes whitelisted or blacklisted email from email that was analyzed and considered to be non-malicious or malicious by the Multi-Vector Virtual Execution (MVX) engine. All incoming email is compared against your rules in both the allowed and blocked lists. A blocked list takes precedence over an allowed list if the email matches entries in both lists. If the incoming email does not match the entries in either an allowed list or a blocked list, the Email Security - Server appliance extracts the URLs and MD5 checksum attachments from the email for analysis. The Email Security - Server appliance bypasses scanning non-malicious emails that do not contain attachments or URLs. You can define a total of 10,240 rules in both types of lists combined.

Allowed list

An allowed list allows you to control which messages, URLs and other entities can be bypassed based on the matched email entries. The Email Security - Server appliance will scan an email for malicious content except the sender email address, sender domain, sender IP address, or recipient email address that you defined. An allowed list supports IPv4 and IPv6 addresses. Both the URL and MD5 checksum attachment are automatically whitelisted.

When an email matches an allowed list, an email is either delivered or discarded based on your mode selection. If you select monitor or block mode, the email will be delivered. If you select drop or TAP/SPAN mode, the email will be discarded.

Blocked list

A blocked list allows you to control which messages must be considered as malicious based on the matched email entries. The Email Security - Server appliance immediately marks an email for quarantine if it includes the sender email address, sender domain, or sender IP address that you defined. A blocked list supports IPv4 and IPv6 addresses.

No further analysis is performed on either the URL or MD5 checksum attachment. All the recipients do not receive a copy of the original malicious email. An email can either be deleted or released from the eQuarantine page.

Task list for managing allowed and blocked lists

Complete the steps for managing allowed and blocked lists in the following order:

  1. Log in to the Web UI or CLI to configure the custom email actions.

  2. Verify the total number of emails that were not scanned or that were blocked because they matched an allowed list or a blocked list using either the show email-analysis allowed-list statistics command or show email-analysis blocked-list statistics command. For details about both commands, refer to the Trellix CLI Reference.

  3. Determine the type of rules that you want to define in an allowed list. For details about how to configure rules on an allowed list, see Configuring rules on an allowed list.

    Determine the type of rules that you want to define for a blocked list. For details about how to configure rules on a blocked list, see Configuring rules on a blocked list.

  4. View the statistics for each allow policy rule. For details about how to view the statistics on an allowed list, see Viewing the statistics on an allowed list.

    View the statistics for each block policy rule. For details about how to view the statistics on a blocked list, see Viewing the statistics on a blocked list.

  5. View the details of an email that matched entries that you defined in the blocked list. For details about how to view the blocked email details in the Web UI, see Viewing the blocked email details in the Web UI.