How to Identify attached zip file's content blocked by Data Protection rule
search cancel

How to Identify attached zip file's content blocked by Data Protection rule

book

Article ID: 205037

calendar_today

Updated On:

Products

Email Security.cloud

Issue/Introduction

One of a Data Protection rule is configured to block the email if some specific file types are attached within that email. This article describes why the .zip file and other archive types (ie: .rar) are not included in blocked file type list and how identify the attached zip file content.

Environment

Email Security.cloud

Cause

The service uses decompression tools which attempt to analyse a compressed file and open it if possible, this is used by the Anti-malware, Anti-spam, Cynic (Sandbox), Data Protection modules.

If the file is password protected, Email Security.cloud is unable to scan the contents of zip file. In this situation however, we'll check if a password is present in the email and attempt to open the file.

If the file is not password protected Email Security.cloud will scan it, should there be any suspicious content within the file it will be blocked.

Resolution

To identify the Zip file's content, you need to enable the below option:

  • Navigate to Services > Data Protection.
  • Click on Settings and under the Reporting section, select "Show matched content on reports" and "Show surrounding text on reports" and click Save.
  • Wait approximately 20-30minutes for propagation.
  • Then run the report and the column "Matched Content" will show what in the email triggered the policy.