You can enable or disable blocking emails based on riskware detection policy rules by using the Email Security - Server appliance Web UI or CLI:
When a matched policy rule is enabled to block an email based on riskware detection on the Email Security - Server appliance, traffic matching the submission is marked as custom riskware and is included for further analysis. The Email Security - Server appliance blocks the email from being delivered to the intended recipient and marks the email for quarantine. When a matched policy rule is not enabled to block an email based on riskware detection, traffic matching the submission is marked as custom riskware and it will be excluded from further analysis. After you have configured the Email Security - Server appliance to detect matched policy rules from emails that are blocked based on riskware detection, you can view the analysis results on the eAlerts > Alerts page in the Web UI. For details about how to view the matched riskware alerts that are blocked, see Viewing Riskware Block Alert Details in the Web UI .
Prerequisites
Administrator or Operator access to the Email Security - Server appliance
An established connection to the Internet
A connection to the DTI Cloud
Download and install the latest security content with new riskware policy rules by using the
fenet security-content apply-updatecommand. For details about how to update security content, refer to the System Administration Guide.Enable blocking emails based on riskware detection policy rules. For details about how to enable blocking emails based on riskware detection policy rules, see Enabling or disabling blocking emails based on riskware detection using the Web UI or Enabling or disabling blocking emails based on riskware detection using the CLI.