A file that cannot be scanned can put your network at risk if it contains a threat. Mail Security provides the following default rules to address unscannable and encrypted files:
These rules are always enabled.
To configure rules to address unscannable and encrypted files
In the console on the primary navigation bar, click Policies.
In the sidebar under General, click Exceptions.
In the Exceptions table, select one of the following rules that you want to view or modify:
In the preview pane, in the Action to take list, use the drop-down menu to select the action to take when a violation is detected.
In the Replacement text box, type your customized message if you want to replace the message or the attachment body with a text message.
The default text is: Symantec Mail Security replaced %attachment% with this text message. The original file was unscannable and was %action%.
You can use variables in your customized text.
Check the option Enable list of trusted domains or users if you want to enter a list of domains or email addresses.
For each of the three rules, you can enter a list of trusted domains or users, and can set different actions for these trusted domains or users.
From the Action to take drop-down menu, select an action that you want to take on the list of trusted domains or users.
In the Replacement text box, type your customized message if you want to replace the message or the attachment body with a text message.
The default text is: Symantec Mail Security replaced %attachment% with this text message. The original file was unscannable and was %action%.
Check one or more of the following to send email notifications about the detection:
Notify administrators
Click the down arrow and then type your customized text in the Subject line box and the Message body box. The default Subject line and Message body text is as follows:
Default subject line text: Administrator Alert: Symantec Mail Security detected a message with an unscannable attachment or body
Default message body text: Location of the message: %location% Sender of the message: %sender% Subject of the message %subject% The attachment(s) "%attachment%" was %action%. This was done due to the following Symantec Mail Security settings: Scan: %scan% Rule: %rule%
Notify internal sender
Click the down arrow and then type your customized text in the Subject line box and the Message body box. The default Subject line and Message body text is as follows:
Notify external sender
Click the down arrow and then type your customized text in the Subject line box and the Message body box. The default Subject line and Message body text is as follows:
On the toolbar, click Deploy changes to apply your changes.
Registry keys can be used to bypass actions on unscannable malformed files. For more information refer the Mail Security Knowledge Base.