show email-analysis policy xheader

Prev Next

Displays the customization settings for the X-Header.

Syntax

show email-analysis policy xheader

Parameters

None

Output fields

The following table describes the output fields for the show email-analysis policy xheader command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Default Xheader Title

The default value is "X-FireEye".

Configured Xheader Title

Custom header title (for example, X-MyCompany).

Default Xheader Clean

The default value is "Clean".

Configured Xheader Clean

Custom text for the verdict that the email was clean

Default Xheader Not-Scanned

The default value is "Not Scanned".

Configured Xheader Not-Scanned

Custom text for the verdict that the email was not scanned because the appliance was oversubscribed.

Default Mal. Attach Found

The default value is "Malicious Attachment Found".

Configured Mal. Attach Found

Custom text for the verdict that the email contained a malicious attachment.

Default Mal. URL Found

The default value is "Malicious URL Found".

Configured Mal. URL Found

Custom text for the verdict that the email contained a malicious URL.

Default Mal. Header Found

The default value is "Suspicious Header/Body/MIME Contents Found".

Configured Mal. Header Found

Custom text for an email that contained a YARA rule match on the header and within an email message body of the header.

Default Mal. Attach & Header Found

The default value is "Malicious Attachment and Suspicious Header/Body/MIME Contents Found".

Configured Mal. Attach & Header Found

Custom text for an email that contained a malicious attachment and a YARA rule match on the header.

Default Mal. URL & Header Found

The default value is "Malicious URL and Suspicious Header/Body/MIME Contents Found".

Configured Mal. URL & Header Found

Custom text for an email that contained a malicious URL and a YARA rule match on the header.

Default Mal. Attach & URL Found

The default value is "Malicious Attachment and URL Found".

Configured Mal. Attach & URL Found

Custom text for an email that contained both a malicious attachment and URL.

Default Mal. Attach,URL & Header Found

The default value is "Malicious Attachment, URL and Suspicious Header/Body/MIME Contents Found".

Configured Mal. Attach,URL & Header Found

Custom text for an email that contained a malicious attachment, URL, and YARA rule match on the header.

Default Xheader Incomplete Scan

The default value is "Scan Incomplete".

Configured Xheader Incomplete Scan

Custom text if one or more objects within the email message was not analyzed completely.

Default Xheader Riskware Match:

The default value is "Riskware Match".

Configured Xheader Riskware Match:

Custom text for an email that contained a riskware match on the header.

Default Xheader Riskware Block:

The default value is "Riskware Block".

Configured Xheader Riskware Block:

Custom text for an email that contained a riskware block on the header.

Example

The following example displays the current X-Header customizations.

hostname # show email-analysis policy xheader
XHeader values:
Default Xheader Title:                     X-FireEye
Configured Xheader Title:                  X-MyCompany
Default Xheader Clean:                     Clean
Configured Xheader Clean:                  Clean - Blue
Default Xheader Not-Scanned:               Not Scanned
Configured Xheader Not-Scanned:            Not Scanned - YELLOW
Default Mal. Attach Found:                 Malicious Attachment Found
Configured Mal. Attach Found:              Malicious Attachment Found - RED
Default Mal. URL Found:                    Malicious URL Found
Configured Mal. URL Found:                 Malicious URL Found - RED
Default Mal. Header Found:                 Suspicious Header/Body/MIME Contents Found
Configured Mal. Header Found:              Suspicious Header/Body/MIME Contents Found - RED
Default Mal. Attach & Header Found:        Malicious Attachment and Suspicious Header/Body/MIME Contents Found
Configured Mal. Attach & Header Found:     Malicious Attachment and Suspicious Header/Body/MIME Contents Found - RED
Default Mal. URL & Header Found:           Malicious URL and Suspicious Header/Body/MIME Contents Found
Configured Mal. URL & Header Found:        Malicious URL and Suspicious Header/Body/MIME Contents Found - RED
Default Mal. Attach & URL Found:           Malicious Attachment and URL Found
Configured Mal. Attach & URL Found:        Malicious Attachment and URL Found - RED
Default Mal. Attach,URL & Header Found:    Malicious Attachment, URL and Suspicious Header/Body/MIME Contents Found
Configured Mal. Attach,URL & Header Found: Malicious Attachment, URL and Suspicious Header/Body/MIME Contents Found - RED
Default Xheader Incomplete Scan:           Scan Incomplete
Configured Xheader Incomplete Scan:        Incomplete Scan
Default Xheader Riskware Match:	           Riskware Match
Configured Xheader Riskware Match:         Riskware Match - RED
Default Xheader Riskware Block:            Riskware Block
Configured Xheader Riskware Block:         Riskware Block - RED

User role

Admin, Analyst, Operator, or Monitor

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Before Release 7.9.1. Command output was enhanced to include the Default Xheader Incomplete Scan and Configured Xheader Incomplete Scan fields in Release 8.0.2.