Customizing or resetting the X-header text using the Web UI

Prev Next

Use the Configure XHeader area in the Email Policy Configuration page to customize or reset the header name and the content of the header message (for example, X-MyCompany: Malicious URL Found, X-MyCompany: Clean, and so on) using the Web UI.

EX_X-HeaderCustom_scap.png

Important

Make sure the X-header feature is enabled before you customize the text for a header message. For details about how to enable the X-header feature, see Enabling or disabling the X-header using the Web UI or Enabling or disabling the X-header using the CLI.

Note

You cannot specify a text string associated with a verdict in the Web UI for an email that was not scanned properly.

To customize the X-header text:
  1. In the Web UI, choose Settings > Email Policy.

  2. In the X header field, clear any existing text, and then enter the custom header title (for example, X-MyCompany). You can enter up to 32 characters.

    You can display the default "X-Trellix" value by hovering over the question mark (?) icon.

  3. In the Clean field, clear any existing text, and then enter a text string associated with a verdict for the email that was detected as clean. You can enter up to 128 characters.

    You can display the default "Clean" value by hovering over the question mark (?) icon.

  4. In the Malicious URL Found field, clear any existing text, and then enter a text string associated with a verdict for the email that contained a malicious URL. You can enter up to 128 characters.

    You can display the default "Malicious URL Found" value by hovering over the question mark (?) icon.

  5. In the Malicious Attachment and Header Found field, clear any existing text, and then enter a text string associated with a verdict for the email that contained a malicious attachment, and in which a YARA rule match was also found on the header and within an email message body of the header. You can enter up to 128 characters.

    You can display the default "Malicious Attachment and Suspicious Header/Body/MIME Contents Found" value by hovering over the question mark (?) icon.

  6. In the Malicious Attachment, URL and Header Found field, clear any existing text, and then enter a text string associated with a verdict for the email that contained both a malicious attachment and URL, and in which a YARA rule match was also found on the header and within an email message body of the header. You can enter up to 128 characters.

    You can display the default "Malicious Attachment, URL and Suspicious Header/Body/MIME Contents Found" value by hovering over the question mark (?) icon.

  7. In the Not Scanned field, clear any existing text, and then enter a text string associated with a verdict for the email that was not scanned because the appliance was oversubscribed. You can enter up to 128 characters.

    You can display the default "Not Scanned" value by hovering over the question mark (?) icon.

  8. In the Malicious Attachment Found field, clear any existing text, and then enter a text string associated with a verdict for the email that contained a malicious attachment. You can enter up to 128 characters.

    You can display the default "Malicious Attachment Found" value by hovering over the question mark (?) icon.

  9. In the Suspicious Header Found field, clear any existing text, and then enter a text string associated with a verdict for the email that contained a YARA rule match on the header and within an email message body of the header. You can enter up to 128 characters.

    You can display the default "Suspicious Header/Body/MIME Contents Found" value by hovering over the question mark (?) icon.

  10. In the Malicious Attachment and URL Found field, clear any existing text, and then enter a text string associated with a verdict for the email that contained both a malicious attachment and URL. You can enter up to 128 characters.

    You can display the default "Malicious Attachment and URL Found" value by hovering over the question mark (?) icon.

  11. In the Malicious URL and Header Found field, clear any existing text, and then enter a text string associated with a verdict for the email that contained a malicious URL, and in which a YARA rule match was also found on the header and within an email message body of the header. You can enter up to 128 characters.

    You can display the default "Malicious URL and Suspicious Header/Body/MIME Contents Found" value by hovering over the question mark (?) icon.

  12. Click Apply to save your changes.

    • If the X-header customization succeeds, the following message appears:

      EX_X-HeaderCustomizeSuccess_scap.png
    • If the X-header customization fails, the following message appears. Enable the X-header feature to configure the relevant text string for each header message.

      EX_X-HeaderCustomizeError_scap.png
    • If the text string contains an invalid character, the following message appears:

      EX_X-HeaderCustomizeInvalidCharacter_scap.png
  13. Click Reset to reset the X-header text back to the default values.

  14. Restart the SMTP interface.