Analysis modes

Prev Next

The manner in which the Email Security — Server appliance receives emails and the actions it takes after it analyzes them depends on its deployment mode and associated analysis mode.

Caution

Trellix strongly recommends the Block analysis mode. This is the most effective option, because the appliance scans every email and prevents malicious emails from being delivered to the intended recipients. This is the default analysis mode. If you are considering another analysis mode, make sure you understand the implications of changing the mode.

Feature-by-Feature comparison

The following table provides a quick comparison of the features available with each deployment and analysis mode.

Feature

Block

(MTA)

Monitor (MTA)

Drop (BCC)

Tap/Span (SPAN/TAP)

Analyze original emails

Yes

No

No

No

Store original malicious emails in quarantine folder

Yes

No

No

No

Store copies of malicious emails in quarantine folder

No

Yes

Yes

Yes

Release malicious emails from quarantine folder

Yes

No

No

No

Remove copies of malicious emails from quarantine folder

Yes

Yes

Yes

Yes

Forward all emails to intended recipients

No

Yes

No

No

Forward only non-malicious emails to intended recipients

Yes

No

No

No

Block delivery of malicious emails to intended recipients

Yes

No

No

No

Send "block" notice to intended recipients

Yes

No

No

No

Analyze copies of emails

No

Yes

Yes

Yes

Send "admin" notice to administrators

Yes

Yes

Yes

Yes

Send "bcc" notice with copy of malicious email to forensic analysts

Yes

Yes

Yes

Yes

Physical connection between the appliance and anti-spam gateway, MTA, or mail server

Yes

Yes

Yes

No