Configures a text string associated with a verdict for the email that contained a malicious attachment, and in which a YARA rule match was also found on the header and within an email message body of the header.
Follow these usage guidelines when you customize the content of the header message:
The content of the custom X-Header message can contain up to 128 characters.
Custom X-Header text can include letters (a–z, A–Z), numbers, dashes (-), slashes (/), underscores (_), spaces, and commas (,). When specifying an X-Header text string that contains spaces, enclose the string in double quotation marks.
The custom X-Header text string cannot contain a period (.).
Important
Your customization changes will not take effect until you disable the X-Header and enable the X-Header again.
Use the
no email-analysis policy xheader enablecommand to disable the X-Header.Use the
email-analysis policy xheader enablecommand to enable the X-Header.
After you change the X-Header, use the email-analysis mta smtp start command to restart the SMTP interface.
The default value is "Malicious Attachment and Suspicious Header/Body/MIME Contents Found".
Important
Do not change the X-Header while the appliance is processing email traffic.
For details about the X-Header, refer to the Email Security — Server User Guide.
Syntax
[no] email-analysis policy xheader mal-att-hdr <malicious_attachment_header_text>
Parameters
no
Resets the custom X-Header text for email that contained a malicious attachment and a YARA rule match on the header to the default "Malicious Attachment and Suspicious Header/Body/MIME Contents Found" value.
<malicious_attachment_header_text>
Text string for an email that contained a malicious attachment and a YARA rule match on the header.
Examples
The following example changes the X-Header text string for an email that contained a malicious attachment and a YARA rule match on the header:
hostname (config) # email-analysis policy xheader mal-att-hdr "Malicious Attachment and Suspicious Header/Body/MIME Contents Found - RED"
The following example resets the custom X-Header text for email that contained a malicious attachment and a YARA rule match on the header to the default "Malicious Attachment and Suspicious Header/Body/MIME Contents Found" value:
hostname (config) # no email-analysis policy xheader mal-att-hdr
User role
Admin and Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 7.9.1