When an email is generated it includes standard headers: From, To, Subject, Date,
Message-ID, Received, Cc, and Bcc. An X-Header refers to any non-standard custom header added when the email is sent. The appliance adds X-headers that describe the MVX (Multi-Vector Virtual Execution) engine analysis and detection results. X-headers qualify the status of emails sent by the appliance to the configured next hop. When the appliance is deployed in Block analysis mode, the malicious X-header will not be visible because the appliance quarantined the malicious emails. When the appliance is deployed in both Block analysis mode and Monitor analysis mode, the appliance analyzes the emails and replaces the default X-FireEye: Not Scanned header message with the appropriate message (for example, X-FireEye: Malicious Attachment Found, X-FireEye: Clean, and so on). When the appliance is deployed in either Block analysis mode or Monitor analysis mode and the URL rewrite feature is enabled, malicious URLs found in X-header emails are rewritten and your system will be protected if you click on the link.
Important
You cannot enable the X-header feature when the Email Security - Server appliance is deployed in Drop analysis mode or tap/span analysis mode.
The default X-header uses the format X-Trellix: <text string>. You also can customize the name of the header title and the content of the header message (for example, X-MyCompany: Malicious URL Found, X-MyCompany: Clean, and so on). Only one default Trellix X-header or custom X-header can be inserted in an email. For details about how to customize or reset the X-headers, see Customizing or resetting the X-header text
Important
You cannot enable the custom riskware block and match X-headers on the Email Security - Server appliance using the Web UI.
The following table describes the default X-headers and the associated verdicts based on the actions taken on the email:
X-header | Description |
|---|---|
X-Trellix: Clean | The email message was scanned and found to be clean. Emails that contain no URL or attachment are also tagged with this header. |
X-Trellix: Malicious Attachment Found | The email message was scanned by the Email Security - Server appliance and found to contain a malicious attachment. |
X-Trellix: Malicious URL Found | The email message was analyzed by the Email Security - Server appliance and found to contain a malicious URL. |
X-Trellix: Malicious Attachment and URL Found | The email message was scanned by the Email Security - Server appliance and found to contain both a malicious attachment and URL. |
X-Trellix: Suspicious Header/Body/MIME Contents Found | The email message was scanned and the Email Security - Server appliance found a YARA rule match on the header and within an email message body of the header. |
X-Trellix: Malicious URL and Suspicious Header/Body/MIME Contents Found | The email message was analyzed by the Email Security - Server appliance and found to contain a malicious URL. The appliance was also scanned and found a YARA rule match on the header and within an email message body of the header. |
X-Trellix: Malicious Attachment and Suspicious Header/Body/MIME Contents Found | The email message was scanned by the Email Security - Server appliance and found to contain a malicious attachment. The appliance was also scanned and found a YARA rule match on the header and within an email message body of the header. |
X-Trellix: Malicious Attachment, URL and Suspicious Header/Body/MIME Contents Found | The email message was scanned by the Email Security - Server appliance and found to contain both a malicious attachment and URL. The appliance was also scanned and found a YARA rule match on the header and within an email message body of the header. |
X-Trellix: Not Scanned | The email message was not scanned because the Email Security - Server appliance was oversubscribed. Resources were not available to process this message. These are counted in the statistics as "bypassed" email messages and can be re-routed for analysis. |
X-Trellix: Trellix Generated | Admin notices and BCC copy messages display this header. These are messages created by the Email Security - Server appliance. In Block analysis mode, the recipient receives a block notice message with this header. If the notice is not enabled, the recipient does not receive anything at all. |
X-Trellix: Scan Incomplete | One or more objects within the email message was not analyzed completely by the Email Security - Server appliance. |
X-Trellix: Riskware Block | The email message was blocked and stored in quarantine folder. In monitor analysis mode, a copy of the email message is quarantined and the original message is forwarded to the recipient tagged with this header. |
X-Trellix: Riskware Match | The Email Security - Server appliance found a match to a riskware policy rule. Traffic matching the submission is marked as custom riskware and it will be excluded from further analysis. The recipient receives the email tagged with this header. Analysis results can be viewed on the eAlerts > Riskware page in the Web UI. |