Quarantine digest settings

You can specify settings for the quarantine digest, an email sent to users that lists their quarantined emails. You can also release emails from quarantine digest.


Quarantine digest lists all emails that are identified as spam and quarantined by the XG Firewall anti-spam engine. XG Firewall emails the quarantine digest to all users as per the configured frequency (hourly, daily, or weekly). From the digest, users can sort through the quarantined emails and, if necessary, release them to their inboxes.

The quarantine digest contains the date and time of email receipt, sender and recipient email addresses, the subject, and release links.

Note The quarantine digest is available only in Sophos Firewall XG 105, Cyberoam CR25iNG, Sophos UTM SG105, and higher models.
Note The quarantine digest doesn't apply to XG Firewall appliances with built-in Wi-Fi.

How to configure quarantine digest

Note Follow these steps for MTA and legacy mode. In legacy mode, the following options are not available: Quarantine area and Skip quarantine reports.

To configure quarantine digest, do as follows:

  1. Go to Administration > Notification settings
  2. Select the email server type. In this example, you select Built-in email server.
  3. Specify the following details: From email address and Send notifications to email address.

    The following image shows example notification settings:

    Image showing notification settings.
  4. Go to Email > Quarantine settings.
  5. Specify quarantine settings as follows:

    Enable quarantine digest

    Select to create a quarantine digest for users.

    Email frequency

    Frequency, time, and day when the digest is emailed.

    From email address

    Address from which to send the email.

    Display name

    Sender's name for the digest.

    Release link settings

    Select the IP address or hostname to use in the release links sent in the quarantine digest email. Users can select the links to release individual emails.

    Alternatively, they can select My account in their digest to manage their quarantined emails.

    Reference user portal IP: The IP address of the selected port is used in the release links. Users who belong to the port's network can use these links.

    Other users can access the user portal, using https://<IP address of XG Firewall> and manage their quarantined emails.

    User interaction setting: The option selected in Administration > Admin settings > Admin console and end-user interaction is used in the release links.

    You can select the firewall hostname, the IP address of the first internal interface that you specify, or a custom hostname.

    You must specify the user portal port after the IP address.


    IP address of the port or first internal interface:

    User portal port: 3311

    Release link:

    Firewall or custom hostname: myfirewall

    Release link: https://myfirewall:3311/webconsole/Controller?mode=458

    Send test email

    Test email to verify the quarantine digest report.

    The following image shows the default quarantine settings:

    Image showing quarantine settings.
  6. Quarantine area: Specify the size of the quarantine area. Select a Disk size. A disk usage check runs every five minutes and deletes older emails, lowering usage from 90 percent and above to 60 percent of the specified size.
  7. Skip quarantine reports: Under Skip address patterns, add email addresses whose quarantined emails you want to exclude from the quarantine digest. For example, you can add the alias email address sales@organization.com to exclude its quarantined emails from the quarantine digest sent to users who are part of the alias.
  8. Change user's quarantine digest settings: Select to apply the digest settings to specific users and groups. Select the users and select Apply. To apply the settings to a group, filter by group.

How to release emails

You can only release emails from quarantine digest directly from the user portal.

For instructions on how to release emails from quarantine digest, see the Quarantine section of the Sophos user portal documentation.