The following tables describe the actions Deep Discovery Email Inspector performs for the selected actions in a matched policy rule in each operating mode.
Action |
Operation Mode |
||
---|---|---|---|
MTA Mode |
SPAN/TAP Mode |
BCC Mode |
|
Delete message |
|
|
|
Block and quarantine |
|
|
|
Strip all attachments |
Note:
Attachments and extracted URLs from attachments in detected email messages are not sent to Virtual Analyzer for analysis. Only extracted URLs from the message body and subject are sent to Virtual Analyzer for analysis. |
|
|
Pass and tag |
|
|
|
Deliver directly |
|
|
|
Encrypt message |
|
|
|
Sanitize file |
|
|
|
Send notification |
|
|
|
Action |
Operation Mode |
||
---|---|---|---|
MTA Mode |
SPAN/TAP Mode |
BCC Mode |
|
Delete message |
|
|
|
Block and quarantine |
|
|
|
Strip all attachments |
Note:
Attachments and extracted URLs from attachments in detected email messages are not sent to Virtual Analyzer for analysis. Only extracted URLs from the message body and subject are sent to Virtual Analyzer for analysis. |
|
|
Pass and tag |
|
|
|
Deliver directly |
|
|
|
Encrypt message |
|
|
|
Send notification |
|
|
|
Action |
Operation Mode |
||
---|---|---|---|
MTA Mode |
SPAN/TAP Mode |
BCC Mode |
|
Delete message |
|
|
|
Block and quarantine |
|
|
|
Pass and tag |
|
|
|
Deliver directly |
|
|
|
Send notification |
|
|
|
Action |
Operation Mode |
||
---|---|---|---|
MTA Mode |
SPAN/TAP Mode |
BCC Mode |
|
Delete message |
|
|
|
Block and quarantine |
|
|
|
Strip attachments, redirect links to blocking page, and tag |
|
|
|
Strip attachments, redirect links to warning page, and tag |
|
|
|
Pass and tag |
|
|
|
Deliver directly |
|
|
|
Quarantine the original message when attachments cannot be stripped |
|
|
|
Quarantine a copy of the original message when stripping attachments or redirecting links |
|
|
|
Attempt to clean before stripping attachments |
|
|
|
Send notification |
|
|
|
-
In policies, the terminal actions are Delete message, Block and quarantine, and Deliver directly. For policies with multiple rules, Deep Discovery Email Inspector applies only one terminal action on detected messages. After applying a terminal action on a message for a matched rule, Deep Discovery Email Inspector does not match the message against subsequent rules in the policy.
For example, if a policy contains one content filtering rule, one antispam protection rule, and one threat protection rule, and Deep Discovery Email Inspector applies the Delete message action on a message based on the content filtering rule matched, Deep Discovery Email Inspector does not apply the antispam and threat protection rules on the message.
-
For policies with multiple rules, Deep Discovery Email Inspector applies all non-terminal actions on messages for matched rules before delivery or until a terminal action is applied.
As an example, you configure a policy containing one or more content filtering rules, one or more data loss prevention (DLP) rules, one or more antispam rules, and one threat protection rule. If Deep Discovery Email Inspector applies the Strip all attachments action on a message based on the content filtering rule or DLP rule that is first matched, Deep Discovery Email Inspector will continue to scan the messages until a terminal action or all subsequent rules are applied (except Virtual Analyzer submission for attachments).
If Deep Discovery Email Inspector does not apply a strip attachment action on a message based on one or more preceding rules matched, Deep Discovery Email Inspector will continue to scan the messages until a terminal action or all subsequent rules are applied (including Virtual Analyzer submission for attachments).
-
When applying multiple actions on a message, Deep Discovery Email Inspector applies the Encrypt message action as the last non-terminal action.