email-analysis policy xheader mal-att-url-hdr <malicious_attachment_URL_header_text>

Prev Next

Configures a text string associated with a verdict for the email that contained both a malicious attachment and URL, and in which a YARA rule match was also found on the header and within an email message body of the header.

Follow these usage guidelines when you customize the content of the header message:

  • The content of the custom X-Header message can contain up to 128 characters.

  • Custom X-Header text can include letters (a–z, A–Z), numbers, dashes (-), slashes (/), underscores (_), spaces, and commas (,). When specifying an X-Header text string that contains spaces, enclose the string in double quotation marks.

  • The custom X-Header text string cannot contain a period (.).

Important

Your customization changes will not take effect until you disable the X-Header and enable the X-Header again.

Use the no email-analysis policy xheader enable command to disable the X-Header.

Use the email-analysis policy xheader enable command to enable the X-Header.

After you change the X-Header, use the email-analysis mta smtp start command to restart the SMTP interface.

The default value is "Malicious Attachment, URL and Suspicious Header/Body/MIME Contents Found".

Important

Do not change the X-Header while the appliance is processing email traffic.

For details about the X-Header, refer to the Email Security — Server User Guide.

Syntax

[no] email-analysis policy xheader mal-att-url-hdr <malicious_attachment_URL_header_text>

Parameters

no

Resets the custom X-Header text for email that contained a malicious attachment, URL, and a YARA rule match on the header to the default "Malicious Attachment, URL and Suspicious Header/Body/MIME Contents Found" value.

<malicious_attachment_URL_header_text>

Text string for an email that contained a malicious attachment, URL, and YARA rule match on the header.

Examples

The following example changes the X-Header text string for an email that contained a malicious attachment, URL, and YARA rule match on the header:

hostname (config) # email-analysis policy xheader mal-att-url-hdr "Malicious Attachment, URL and Suspicious Header/Body/MIME Contents Found - RED"

The following example resets the custom X-Header text for email that contained a malicious attachment, URL, and a YARA rule match on the header to the default "Malicious Attachment, URL and Suspicious Header/Body/MIME Contents Found" value:

hostname (config) # no email-analysis policy xheader mal-att-url-hdr

User role

Admin and Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 7.9.1