This section covers the following information:
About a blocked list
A blocked list allows you to control which messages must be considered as malicious based on the matched email entries. The Email Security - Server appliance immediately marks an email for quarantine if it includes the sender email address, sender domain, or sender IP address that you defined.
No further analysis is performed on either the URL or MD5 checksum attachment. All the recipients do not receive a copy of the original malicious email. An email can either be deleted or released from the eQuarantine page.
Email entries matching the block policy rules that you defined for the sender email address and sender domain are case-insensitive.
To apply a wildcard match on a domain name, omit the protocol. For example, the rule yahoo.com matches http://finance.yahoo.com, https://finance.yahoo.com, http://yahoo.com, https://www.yahoo.com, and so on.
Usage guidelines for configuring rules on a blocked list
Follow these usage guidelines when you are configuring rules on a blocked list:
Exact match as well as partial match for a URL rule and MD5 checksum is supported; substrings, wildcards, and regular expressions are not supported.
IPv4 and IPv6 addresses are supported. Use a regular expression to define blocked IP addresses, for example, ^192.0.2.1$.
You cannot use non-ASCII characters when adding a rule for the sender domain.
When you remove the rule based on the MD5 checksum attachment from a blocked list, files matching that rule are automatically marked as malicious without analysis. You can specify how long to retain the last analyzed attachment with the same MD5 checksum by using the
blacklist files auto past_hourscommand. The default value to retain the files is four hours.You can import the rules that you defined on a blocked list to your appliance from a single CSV file. For details about how to create the CSV file, see Importing or exporting a blocked list.
Prerequisites
Administrator or Operator access to the Email Security - Server appliance