Enabling or disabling the advanced X-header

Prev Next

You can enable or disable an advanced X-header feature by using the Email Security - Server appliance CLI.

When you enable the advanced X-header feature, the Email Security - Server appliance does the following

  • Inserts the X-header "Scan Incomplete" line if one or more objects within the email message was not analyzed completely.

    When this feature is disabled, the Email Security - Server appliance inserts the X-header "Clean" line. The Email Security - Server appliance does not insert the X-header "Scan Incomplete" line if the email message contained a malicious attachment. When the Email Security - Server appliance identifies a scan as incomplete, the output of the show submission id command shows the submission status as failed, ae_start_failed, dnld_couldnt_resolve_host, dnld_couldnt_connect, dnld_operation_timedout, dnld_other, dnld_http_returned_error, dnld_too_many_redirects, or file_not_found.

  • Inserts the X-Hheader "X-FireEye: Riskware Block" line in copy of email message when the Email Security - Server appliance is in monitor analysis mode.

  • Inserts the X-header "X-FireEye: Riskware Match" line when analysis found a matched riskware policy rule.

The advanced X-header feature is disabled by default.

Important

Emails that are tagged "X-Trellix: Scan Incomplete" are marked with the verdict "Clean" on the Search Emails > Processed Emails page in the Web UI.

Prerequisites