The manner in which the Email Security — Server appliance receives emails and the actions it takes after it analyzes them depends on its deployment mode and associated analysis mode.
Caution
Trellix strongly recommends the Block analysis mode. This is the most effective option, because the appliance scans every email and prevents malicious emails from being delivered to the intended recipients. This is the default analysis mode. If you are considering another analysis mode, make sure you understand the implications of changing the mode.
Feature-by-Feature comparison
The following table provides a quick comparison of the features available with each deployment and analysis mode.
Feature | Block (MTA) | Monitor (MTA) | Drop (BCC) | Tap/Span (SPAN/TAP) |
|---|---|---|---|---|
Analyze original emails | Yes | No | No | No |
Store original malicious emails in quarantine folder | Yes | No | No | No |
Store copies of malicious emails in quarantine folder | No | Yes | Yes | Yes |
Release malicious emails from quarantine folder | Yes | No | No | No |
Remove copies of malicious emails from quarantine folder | Yes | Yes | Yes | Yes |
Forward all emails to intended recipients | No | Yes | No | No |
Forward only non-malicious emails to intended recipients | Yes | No | No | No |
Block delivery of malicious emails to intended recipients | Yes | No | No | No |
Send "block" notice to intended recipients | Yes | No | No | No |
Analyze copies of emails | No | Yes | Yes | Yes |
Send "admin" notice to administrators | Yes | Yes | Yes | Yes |
Send "bcc" notice with copy of malicious email to forensic analysts | Yes | Yes | Yes | Yes |
Physical connection between the appliance and anti-spam gateway, MTA, or mail server | Yes | Yes | Yes | No |