Malware quarantined email release procedure in Email Security.cloud
search cancel

Malware quarantined email release procedure in Email Security.cloud

book

Article ID: 451793

calendar_today

Updated On:

Products

Email Security.cloud

Issue/Introduction

Using Administrator Quarantine in Email Security.cloud, you can release messages that have been quarantined in the last 30 days. Messages are sent to Administrator Quarantine because they contain malware detected by a Scan-time Protection Policy or by the Anti-Malware service.

Troubleshooting missing quarantined emails

If users report they are not receiving emails and have received a "messagelabs blocked E-mail" notification, but cannot find the message in the standard user quarantine portal, the message may be in the Administrator Quarantine. This tool allows you to search for and release those missing messages.

Administrator Quarantine displays messages in a table format, with search criteria in the left panel. The default on first use is to display no quarantined emails. You can search quarantined emails from the past 30 days and display those that fit your criteria.

Environment

Email Security .Cloud

Resolution

After you select the emails that you want to release, you can specify whether to release them to the message’s original recipient, or to an alternate email address that you specify. If your criteria match a larger number of messages than can be displayed on a single screen, you can choose to release all of the messages at once rather than scrolling through each screen to select and release the emails.

  • Navigate to Tools >Email Quarantine for Administrators. If you can't view this page, ensure that you have the proper permissions. To view quarantined messages, you must have View Configuration and View Statistics permissions for the Administrator Quarantine service. To release or rescan quarantined messages, you must have Edit Configuration permission for the Administrator Quarantine service.

  • Use the left panel to select search criteria for the emails that you want to release (Time Range, Direction, Domain, and so on), and click Search. Messages that match your search criteria appear.

  • Select the messages to release using the check boxes to the left of each quarantined message.

  • Click the Release icon that is located at the top right of the screen. The Release Emails dialog appears.

  • Specify whether you want to release emails to their original recipient, or to an administrator. If you  select Administrator, a text field appears. Enter an administrator email address.

Note : The administrator email address must belong to a domain that your organization owns.

  • The Release Emails dialog displays the total number of emails you have selected for release. It also provides information about probable malware infection, legal liability, and how emails are formatted after release.

  • Review this information and then click the Release button. The messages are released from Administrator Quarantine.

Additional Information

When you release a quarantined email, it is released directly to the recipient in the form of a zipped attachment, rather than from a mail tower in the ESS infrastructure. For this reason, you cannot use the Track and Trace tool to monitor messages that are released from quarantine. Instead, use the Email Detailed Report. In the portal, on the Reports Wizard's Select Data screen, navigate to

  • Email Data
    • Email Detailed Report (CSV)
      • Anti-Malware