Skip to content

Manage quarantined messages

You can release, delete, and block quarantined messages from the message list or from Message Details.

Release or delete messages

You can release or delete messages from the message list or from Message Details.

Quarantined messages are deleted after 30 days. If you have a Sophos Email Plus license, they're deleted after 90 days.

Click the tab that matches the quarantine list you're viewing.

  • Click Release to release messages from quarantine and deliver them to users.
  • Click Release and Allow to release messages and add the sender's email address to the Inbound Allow/Block list.

    Note

    When a message is released from quarantine, Sophos Email rescans it before delivery.

    If the message was clawed back from post-delivery quarantine, any associated internally forwarded or replied messages are also released.

    Release quarantined messages in email security quarantine

    Release quarantined messages in post-delivery quarantine

  • Click Delete to delete quarantined messages.

  • Click Delete and Block to delete messages and add the sender's email address to the Inbound Allow/Block list.

If you've turned on Allow/Block List for your users, you can also add IP addresses and domains to allow or block lists. See User Settings.

  • Click Release to request Microsoft 365 to deliver the message.
  • Click Delete to request Microsoft 365 to delete the message.

Blocking

This feature doesn't apply to the M365 quarantine list.

In Quarantined Messages, click the subject of a message to open Message Details.

Under SMTP From, click Block, then select Block sender or Block sender domain to add the sender's email address or domain to your block list.

You can also click Block IP Address under IP Address to add the IP address to your block list. Alternatively, you can add email addresses and domains from the Inbound Allow/Block list.

Warning

Be careful when you block an IP address. You can accidentally block an entire service. For example, if you block an IP address used by Microsoft 365, you won't receive messages from Microsoft 365 users.

You can add descriptions when blocking a sender's email address, domain, or IP address to specify the reason for each block entry.

Example
Blocked due to spam.

You can view and edit these descriptions later on the Inbound Allow/Block list.

For more information, see Inbound Allow/Block.