About the email quarantine

Prev Next

The email quarantine allows an Email Security - Server administrator to view all the emails that have been blocked because infections were detected, and then to release or delete the emails from the quarantine. The Email Security - Server appliance blocks spear phishing emails by analyzing every attachment and URL using the Multi-Vector Virtual Execution (MVX) engine to identify advanced attacks. After malware is identified, the Email Security - Server appliance can quarantine the malicious emails that contain the malicious attachments or URLs for further analysis or deletion. The Email Security - Server appliance safely stores the malicious emails for a period of time in the quarantine. The Email Security - Server appliance can block malicious emails from being delivered to the intended recipient.

When the Email Security - Server appliance is deployed in Block analysis mode, an administrator can release or remove the emails from the quarantine. When the Email Security - Server appliance is deployed in Drop analysis mode, Monitor analysis mode, or Tap/Span analysis mode, an administrator can only remove the emails from the quarantine. An administrator cannot release the emails because they are only copies of the original emails. For details about how each mode operates, refer to the "Analysis Mode Configuration" chapter in the Email Security — Server System Administration Guide.

Note

Administrator, Analyst, and Monitor roles can access the eQuarantine page. The Monitor role has read-only access to the eQuarantine page.

Task list for managing the email quarantine

Complete the steps for managing the email quarantine in the following order:

  1. Log in to the Web UI or CLI.

  2. Configure the settings for the quarantine by using the Email Security - Server appliance Web UI or CLI. For details about how to configure the quarantine settings, see Configuring the quarantine settings using the Web UI or configuring the quarantine settings using the CLI.

  3. View the message content of the malicious emails in the quarantine. For details, see Viewing the message content in the quarantine.