Title
Page icon
Create new category
Edit page index title
Edit category
Edit link
Quarantine
The Quarantine page provides information of blocked and modified emails, including some basic metadata. Each entry is linked to an Event (See Events).
Search and Filtering Options
Search Bar: Allows users to search for specific quarantine based on keywords.
Time Range: Narrows down entries by time range.
Filters: Use the panel to narrow the list of entries using one or more search criteria. It includes:
Status: Filters entries by their current processing status (for example, Quarantined).
Verdict: Filters events by the final processing verdict.
Message ID: Searches for a specific email message using its unique Message ID.
Quarantine ID: Filters entries by its unique Quarantine ID.
Subject: Filters entries by the email subject.
SMTP Sender: Filters entries by the SMTP envelope sender address.
From Address: Filters entries by the email sender shown in the From header.
Recipient: Filters entries by the recipient email address.
Policy Name: Filters entries processed by a specific policy.
Attachment Name: Filters entries containing attachments with a specified file name.
Column visibility: Configure columns to display in list. Available are:
Select (Fixed Column): Allows for batch operations.
Quarantine ID (Fixed Column): Unique ID automatically assigned to each entry.
Actions (Fixed Column): Provides quarantine actions, like Release or Delete.
Policy: Shows the policy that was applied during email processing.
Verdict: Displays the final security verdict assigned to the event.
Status: Shows the current processing status of the event (for example, Delivered or Quarantined).
Time of Event: Displays the date and time the event occurred. This column is fixed and cannot be hidden.
Quarantine List (Blocked & Sanitized Originals)
Each row in the list represents an event with the following details:
Time of Event: Timestamp indicating when the event occurred.
Quarantine ID: Unique identifier assigned to each security event.
Status: The current status of the event, for example, Quarantined.
Policy: Indicates the Policy that applied for the the content.
Verdict: See Verdicts.
Viewing Details
Clicking the arrow next to a Quarantine ID expands detailed metadata about the quarantined email, including:
Item type: Type of content.
- View headers: View the email header for analysis.
Affected User: The user(s) affected by the event.
Sent at: Timestamp of when the email was sent.
Received at: Timestamp of when the email was received.
Message ID: Unique email message identifier.
Subject: The subject of the email.
Sender & Recipients: Sender's email address and SMTP server details.
From, To & Cc: Identify the sender and recipients listed in the email header.
Received from: Endpoint from where email was received.
Size: Email content size.
Actions
To the right of each quarantined email are action icons:
View Event: Opens the associated event for detailed threat analysis. See Viewing Event details.
Delete: Permanently removes the email from the system
Release: Delivers the email to the intended recipient if deemed safe
These actions can help administrators quickly manage threat resolution or allow legitimate emails that were flagged in error.