Managing quarantined emails

Prev Next

The quarantine can be used to release, rescan, or delete emails. You can release, rescan, or delete multiple emails by selecting the boxes next to each specific email. To select all emails on the page, select the box to the left of the Date & Time column. Only emails received within the last 30 days can be released, rescanned, or deleted.

Release email(s) from quarantine

  1. Select the boxes next to the emails you want to release.

  2. Click Release and confirm that you want to release the emails.

  3. (Optional) Select Report as "NOT SPAM" to enhance future Email Security — Cloud detection capabilities.

  4. (Optional) Enter the reason for releasing the emails in the Justification box.

  5. Click Yes, release email.

  6. Select Confirm Release to release the emails.

Caution

The released email may contain LIVE malware. Proceed with caution.

Delete emails from quarantine

  1. Select the boxes next to the emails you want to delete.

  2. Click Delete to delete the messages.

  3. Click Yes, delete email.

Quarantined email rescanning

Quarantined messages can be rescanned by Email Security - Cloud when a false positive is suspected. Rescanning will be skipped for messages that are quarantined due to policy violation. Connect rules, custom rules, and the end user allow/block policy are not re-evaluated during the rescan process.

If a quarantined message is determined to be non-malicious during the rescan process, the message will be automatically released.

Note

Rescanning is available for inbound messages only.

To rescan emails in the quarantine:

  1. Select the boxes next to the emails you want to rescan.

  2. Click Rescan to rescan the messages.

Rescan with password

Use the Rescan with Password button to rescan emails that contain password-protected attachments and quarantined under riskware rule ID 65066. You need to provide candidate passwords to enable Email Security — Cloud to decrypt and analyze the attachment during the rescan. You can submit multiple passwords per request.

Emails containing password-protected attachments are marked with the Encrypted Attachment tag.

Note

Riskware rule ID 65066 must be set to “Alert + Quarantine.”

Justifying releasing emails

When releasing emails from quarantine, you can provide a reason for the action by entering an explanation in the Justification box before final confirmation. This maintains an audit trail explaining why potentially sensitive or flagged content was permitted into the environment.

You can provide a justification in two ways:

  • On the Quarantine page, select the checkboxes for the desired emails and click Release.

  • Click on an email on the Quarantine page to go its Message Details page. Select Release.

You can make adding justifications optional or mandatory for end-users for both inbound and outbound emails.

  1. Navigate to Quarantine Report Setting and select a Setting to go to the settings page.

  2. Under End User Features, enable or disable Justification for Quarantine release.

Review release justifications in the following locations:

  • Message Details > Email Summary > Quarantine History

  • Message Details > Events

Locating emails with release justifications

You can view emails containing justifications in the following locations:

  • Email Trace > Add the Justification column to your table view.

  • Email Trace > Download the CSV file to view justification for an email.

  • Email Trace > Advanced Search > Use the parameter, Has Release Justification.

  • Email Trace REST API > /api/v1/messages/trace > request attribute, hasReleaseJustification.