Device Configuration : Protect : Email : Email Policies : Add POP - IMAP Scanning Policy
Add POP - IMAP Scanning Policy
This feature requires a subscription in Sophos XG Firewall. It can be configured but cannot be enforced without a valid Email Protection subscription.
The POP - IMAP Scanning Policy page allows you to configure scanning policy to detect incoming and outgoing Spam in Email traffic and take appropriate action.
1. Go to Device Configuration > Protect > Email > Email Scanning Policy .
2. Click Add POP-IMAP Rule under Email Scanning Policy section.
3. Enter Email Address/Domain Group details.
Sender
Specify Email Address(es) of the Sender(s). You can select from the variants:
Contains: Specify keywords to be matched with Sender Email Addresses. Rule applies to Address(es) containing those keywords. For example, if keyword "mail" is specified, rule will apply to Sender Email Addresses john@hotmail.com, sophosmail@sophos.com, etc.
Equals: Specify the exact Email Address(es) of the Sender(s).
You can also add RBLs, list of Email Addresses or keywords using Create New link.
Recipient
Specify Email Address(es) of the Recipient(s). You can select from the variants:
Contains: Specify keywords to be matched with Recipient Email Addresses. Rule applies to Address(es) containing those keywords. For example, if keyword "mail" is specified, rule will apply to Recipient Email Addresses john@hotmail.com, sophosmail@sophos.com, etc.
Equals: Specify the exact Email Address(es) of the Recipient(s).
You can also add RBLs, list of Email Addresses or keywords using Create New link.
4. Select the Filter Criteria.
Inbound Email is
All the Emails that are received by the users in their inbox are referred as Inbound.
On configuring Inbound Spam, all the Emails received by the users are scanned for spam and viruses by the Device.
Specified action will be taken if the Device has identified the Inbound Email to be one of the following:
Spam
Probable Spam
Virus Outbreak
Probable Virus Outbreak
Source IP/Network Address
Specify IP/Network Address, action will be taken when the Email sender IP Address matches the specified IP/Network Address.
Message Size
Specify Message Size, action will be taken when the Email size matches the specified size.
Message Header
Specified action will be taken if the message header equals or contains the specified text.
Contains: Specify keywords to be matched with Message Header. Rule applies to Header(s) containing those keywords.
Equals: Specify the exact Header(s) to be scanned.
You can scan message header for Spam in:
Subject: Specified action will be taken if the header contains the matching subject.
From: Specified action will be taken if the header contains the matching text in the From address.
To: Specified action will be taken if the header contains the matching text in the To address.
Other: Specified action will be taken if the matching text is found in the headers.
None
Select to create a rule between specific sender and recipient without any conditions. You can set actions for POP/S-IMAP/S mails only on the basis of sender and recipient.
5. Select the action.
Accept: Email is accepted and delivered to the intended recipient.
Prefix Subject: Email is accepted and delivered to the intended recipient but after tagging the subject line.Tagging content is specified in spam policy.You can customize subject tagging in such a way that the recipient knows that the Email is a spam Email. For Example Contents to be prefixed to the original subject: ‘Spam notification from the Device – ‘Original subject: ‘This is a test’ Recipient will receive Email with subject line as: ‘Spam notification from the Device - This is a test’.
6. Click Save.