You can enable or disable blocking emails based on riskware detected by Trellix Riskware rules by using the Email Security - Server appliance Web UI or CLI:
When you enable riskware detection both to generate a riskware alert and to block an email, the Email Security - Server appliance blocks emails that might be suspicious. In this scenario, a malware object event notification is generated if the sample is detected as riskware. You can view the analysis results on the eAlerts > Alerts page in the Web UI.
Note
Blocking emails based on the riskware detection feature is disabled by default.
Prerequisites
Administrator or Operator access to the Email Security - Server appliance
An established connection to the Internet
A connection to the DTI Cloud
Download and install the latest security content with new riskware policy rules by using the
fenet security-content apply-updatecommand, For details about how to update security content, refer to the System Administration Guide.