email-analysis blocked-list md5sum <MD5_checksum_attachment>

Prev Next

Configures the block policy rule based on the MD5 checksum attachment.

No further analysis is performed on the MD5 checksum attachment. All the recipients will receive a copy of the original malicious email with a different subject. In the Email Security — Server Web UI, an email can either be deleted or released from the eQuarantine page.

Files matching the block policy rule for the MD5 checksum is case-sensitive.

Note

When you remove the rule based on the MD5 checksum attachment from a blocked list, files matching that rule are automatically marked as malicious without analysis. You can specify how long to retain the last analyzed attachment with the same MD5 checksum by using the blacklist files auto past_hours command. The default time to retain the files is four hours.

For details about how to configure a blocked list, refer to the "Rule Configuration on Allowed and Blocked Lists" chapter of the Email Security — Server User Guide.

Syntax

[no] email-analysis blocked-list md5sum <MD5_checksum_attachment>

Parameters

no

Deletes the block policy rule based on the MD5 checksum attachment.

<MD5_checksum_attachment>

MD5 checksum attachment of the block policy rule.

Examples

The following example adds the MD5 checksum attachment to a blocked list:

hostname (config) # email-analysis blocked-list md5sum d41d8cd98f00b204e9800998ecf8427e

The following example deletes the MD5 checksum attachment from a blocked list:

hostname (config) # no email-analysis blocked-list md5sum d41d8cd98f00b204e9800998ecf8427e

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 7.6