Please enable JavaScript to view this site.

SecurityGateway for Email Servers v12.5

Navigation: Security > Filtering

Attachment Filtering

Scroll Prev Top Next More

Use the options on this page to designate specific types of files that will cause a message to be either blocked or quarantined when one of those files is attached. Attachments can be matched two ways: by content-based file type detection, which identifies a file's real type regardless of what it's named, and by file extension, which matches the attachment's file name. You can define these filtering restrictions both globally and per domain.

Attachments to Block

The options in this area determine which attachments to block, whether by identifying the file type based on its content or by its file extension.

If you list the same file type in both the Block and Quarantine section, messages containing attachments of that type will be blocked, they will not be quarantined.

Content-Based File Types to Block

This section lets you block attachments by their actual, detected file type, using the same content-detection engine as Attachment Disguise Protection, regardless of what extension the file is named with.

Category list

Select the file type categories you want to block by content. No categories are selected by default (although by default some file extensions are blocked using the "File Extensions to Block" options below). Attachments whose detected content matches a selected category are blocked, regardless of their file name or extension.

The categories are arranged as a two-level tree. Click the arrow to the left of a category name to expand or collapse its sub-categories. Top-level categories (such as Executables or Scripts) group related sub-categories, such as Windows Executables, DOS Executables, PowerShell, or Windows Batch. Checking a top-level category selects all of its sub-categories. Checking only some of its sub-categories changes the parent checkbox to an indeterminate state, to give a visual indicator that not all sub-categories are selected. All file extensions associated with a file type are listed after the file type's name.

Edit extensions (pencil icon)

File type categories and sub-categories that have file extensions associated with them display those extensions next to their name, followed by a pencil icon. Click the extensions text or the pencil icon to open the File Type Extensions dialog, described below, where you can review or customize which file extensions belong to that category.

Select All / Deselect All

Use these buttons to quickly select or clear every category and sub-category in the list.

search for a file type

Type in this box to filter the category list down to categories and sub-categories whose names or extensions match your search text. Click the X icon to clear the search and show the full list again.

File Extensions to Block

Specify file extensions in this section that you wish to block by file name. When a message has an attachment with one of these extensions, it will be refused during the SMTP process.

Add

To add a new file type to the block list, enter it here and click Add.

Remove / Remove All

To remove one or more file types from the block list, select them and click Remove, or click Remove All to clear the entire list at once.

Also block attachments with extensions associated with the content-based file types selected above

When checked, SecurityGateway automatically adds the file extensions typically associated with the categories you selected above (under Content-Based File Types to Block) to this extension block list. For example, selecting the Windows Executables category will also block the ".exe" extension. This option is enabled by default.

Exclusions (Block)

Exclude messages sent to email addresses listed below

Check this box and add any recipient addresses that you wish to exclude from Attachments to Block options. Email address masks are allowed.  Example: *@company.mail, user*@company.mail, admin@*.mail

 

Attachments to Quarantine

The options in this area determine which attachments to quarantine, whether by identifying the file type based on its content or by its file extension.

If you list the same file type in both the Block and Quarantine section, messages containing attachments of that type will be blocked, they will not be quarantined.

Content-Based File Types to Quarantine

This section works the same way as Content-Based File Types to Block, above, except that it lets you quarantine rather than block attachments by their actual, detected file type regardless of what extension the file is named with.

Category list

Select the file type categories you want to quarantine by content. No categories are selected by default. Attachments whose detected content matches a selected category are quarantined, regardless of their file name or extension.

The categories are arranged as a two-level tree. Click the arrow to the left of a category name to expand or collapse its sub-categories. Top-level categories (such as Executables or Scripts) group related sub-categories, such as Windows Executables, DOS Executables, PowerShell, or Windows Batch. Checking a top-level category selects all of its sub-categories. Checking only some of its sub-categories changes the parent checkbox to an indeterminate state, to give a visual indicator that not all sub-categories are selected. All file extensions associated with a file type are listed after the file type's name.

Edit extensions (pencil icon)

File type categories and sub-categories that have file extensions associated with them display those extensions next to their name, followed by a pencil icon. Click the extensions text or the pencil icon to open the File Type Extensions dialog, described below, where you can review or customize which file extensions belong to that category.

Select All / Deselect All

Use these buttons to quickly select or clear every category and sub-category in the list.

search for a file type

Type in this box to filter the category list down to categories and sub-categories whose names or extensions match your search text. Click the X icon to clear the search and show the full list again.

File Extensions to Quarantine

Specify file extensions in this section that you wish to quarantine by file name. When a message has an attachment with one of these extensions, it will be accepted and then quarantined.

Add

To add a new file type to the quarantine list, enter it here and click Add.

Remove / Remove All

To remove one or more file types from the quarantine list, select them and click Remove, or click Remove All to clear the entire list at once.

Also quarantine attachments with extensions associated with the content-based file types selected above

When checked, SecurityGateway automatically adds the file extensions typically associated with the categories you selected above (under "Content-Based File Types to Quarantine") to this extension quarantine list. For example, selecting the Windows Executables category will also quarantine the ".exe" extension. This option is enabled by default.

Exclusions (Quarantine)

Exclude messages sent to email addresses listed below

Check this box and add any recipient addresses that you wish to exclude from Attachments to Quarantine options. Email address masks are allowed.  Example: *@company.mail, user*@company.mail, admin@*.mail

 

File Type Extensions File Type Extensions

Exclusions

Exclude messages from allowlisted senders

Check this box if you wish to exclude messages from the attachment filtering restriction when they are from an address, host, or IP on an Allowlist.

Exclude messages from authenticated sessions

Use this option if you wish to exclude a message from attachment filtering when it is arriving over an authenticated session.

Exclude messages from domain mail servers

Use this option to exclude messages from attachment filtering when they are coming from one of your domain mail servers.

Exceptions - Domains

If you wish to customize this page's settings for specific domains:

1.Select a domain in the "For Domain:" drop-down list at the top of the page.

2.Click Use the custom settings defined below for this domain.

3.Choose the desired settings.

4.Click Save.

When any customized domains exist and "-- Global --" is selected above, the customized domains will be listed here at the bottom of the page. Click the View/Edit link for the corresponding domain to review or edit its settings, or click Reset to reset the domain's settings to the default Global values.

Copy Domain Settings

If you have customized a domain's settings and wish to copy those settings to one or more other domains:

1.Select a domain in the "For Domain:" drop-down list at the top of the page.

2.At the bottom of the page, click "Click here to copy these custom settings to one or more domains."

3.On the Copy Custom Domain Settings page, use the arrows to move any desired domains from Available Domains to Selected Domains.

4.Click Save and Close.