The Non-Delivery Report action causes a forced delivery failure of the email messages. The
non-deliver action generates a new message to the sender of the original message, stating that their message has not reached one or more of the specified recipients. The message to the sender includes the first 1024 characters of the original message.
An example of its use would be where messages arrive in your system for a recipient who is not on your address list, such as someone who has left the company.
Non-Delivery Report could then be used to return the email message to the sender.
Properties
The properties of the Non-Delivery Report action are briefly described in the following sections. For full details on configuring the action, see the MIMEsweeper Policy Editor help.
Message
The text to appear in the subject of the report. The text can include MIMEsweeper tokens.
Tokens available here are
:
For further information about these tokens, see Appendix I.
An optional message can be entered which will be returned to the sender along with the original message to explain why the message was not delivered.
Special features and restrictions
None.
• %SENDER% • %SUBJECT%
Park
The Park action places email messages in a parking area for later delivery.
An example of the use of this action is to defer the delivery of large email messages until outside of normal working hours.
Properties
The properties of the Park action are briefly described in the following sections. For full details on configuring the action, see the MIMEsweeper Policy Editor help.
Message Area
The parking area in which email messages are to be placed.
Options
The form in which to park the email message: either in its original form or as modified by MIMEsweeper. For example, MIMEsweeper may have added an annotation or removed an attachment.
If you choose to attach a message in its original form, rather than as modified by MIMEsweeper, be aware that an email message that poses a threat could enter your organization's email system.
Special features and restrictions
Users who have access permissions to the parking area can use the MIMEsweeper Manager to force the immediate delivery of email messages held in the parking area outside of the scheduled release time.
Quarantine
The Quarantine action places email messages that are inappropriate for delivery in a quarantine area.
An example of the use of this action is to place messages that have triggered a content check performed by a scenario (such as messages containing viruses or prohibited data) in a secure area where a MIMEsweeper system administrator can examine the messages before deciding whether to process or delete them.
Properties
The properties of the Quarantine action are briefly described in the following sections. For full details on configuring the action, see the MIMEsweeper Policy Editor help.
Message Area
The quarantine area in which email messages are to be placed.
Options
The form in which to quarantine the email message: either in its original form or as modified by MIMEsweeper. For example, MIMEsweeper may have added an annotation or removed an attachment.
Special features and restrictions
Users who have access permissions to the quarantine area can use the MIMEsweeper Manager to view messages held in the quarantine area and process or delete them. You can configure quarantine areas to automatically delete quarantined email messages after a specified time.
Relay To
The Relay To action uses SMTP to relay a copy of a message to a specified host on a specified port.
You can use this action, for example, to archive messages on another server, or to relay S/MIME encrypted messages to a separate server for decryption by a third-party tool.
Properties
The properties of the Relay To action are briefly described in the following sections. For full details on configuring the action, see the MIMEsweeper Policy Editor help.
Server
Information about the SMTP server to which messages will be relayed, including the server name and the port assigned to the server. By default, port 25 is assigned.
Special features and restrictions
None.
Reply
The Reply action sends an automatic reply to the sender of a message to inform them of actions taken during MIMEsweeper message processing.
An example of the use of this action is to inform the message sender that MIMEsweeper identified a threat, such as a virus, in the email message that was sent.
Properties
The properties of the Reply action are briefly described in the following sections. For full details on configuring the action, see the MIMEsweeper Policy Editor help.
Sender
The email account from which MIMEsweeper is to send messages. This can be the MIMEsweeper administrator email account, the MIMEsweeper Service email account, or any other email account in your organization's domain.
The email addresses for the MIMEsweeper administrator and the MIMEsweeper service accounts are specified in the Addresses tab of the MIMEsweeper for SMTP Properties page.
Subject and Body
The content of the message MIMEsweeper is to send, including the text to appear in the Subject line of the email message and the text to appear in the body of the email message. The text can include MIMEsweeper tokens. For example, you can use the %SUBJECT% token to include the subject of the original email.
Tokens available for the message Subject are:
• %ADMIN% • %POLICY%
• %UNIQUEID% • %SENDER%
• %AREANAME% • %SERVER%
• %DATE% • %SUBJECT%
• %REMOVEDNAMES%
Tokens available for the message Body are:
You can also specify an alternative character set for MIMEsweeper to use for generating forward messages if your specified subject or body text contains characters that cannot be displayed by the US-ASCII character set. To access this feature, click the Advanced button.
Options
The form in which to send the email message: either in its original form or as modified by MIMEsweeper. For example, MIMEsweeper may have added an annotation or removed an
attachment. You can also specify whether to include the results from any specified text analysis as an HTML attachment to the archived message.
If you choose to attach a message in its original form, rather than as modified by MIMEsweeper, be aware that an email message that poses a threat could enter your organization's email system.
Special features and restrictions
None.
• %ADMIN% • %RECOGNISED%
• %DETECTED% • %REMOVEDNAMES%
• %UNIQUEID% • %RESPONSES%
• %AREANAME% • %POLICY%
• %DATE% • %SENDER%
• %MODIFIED% • %SERVER%
• %RCPTS% • %SUBJECT%
Save
The Save action places email messages in a specified folder on your computer.
An example of the use of this action is to save email messages to a location where they can be accessed by an SMTP email system other than MIMEsweeper.
Properties
The properties of the Save action are briefly described in the following sections. For full details on configuring the action, see the MIMEsweeper Policy Editor help.
Folder
The relative path to the folder to be used to save messages. The base folder for this operation is set in the Base Folders tab of the server’s Properties page. For further details see Chapter 6.
Options
The form in which to send the email message: either in its original form or as modified by MIMEsweeper. For example, MIMEsweeper may have added an annotation or removed an
attachment. You can also specify whether to include the results from any specified text analysis as an HTML attachment to the archived message.
Special features and restrictions
MIMEsweeper saves email messages in SMTP format as.rcpand.msgfiles. For further details on the use of these files in MIMEsweeper message processing, see Appendix F.
Users who have access to the folder where email messages are saved can open the messages in an email system other than MIMEsweeper for SMTP. This is not desirable if the messages contain security threats or offensive material.
MIMEsweeper does not automatically delete copies of messages in the Save folder.
5:
References
This chapter provides more detailed information on References, describing the types of References you can associate with specific scenarios in MIMEsweeper for SMTP. This chapter supplements the information on References in Chapter 2.
Script list. . . .5-24 Script list properties . . . .5-24 General - managed script lists only . . . .5-25 Management - managed script lists only . . . .5-25 Primary expressions. . . .5-25 Secondary expressions . . . .5-26 Usage . . . .5-26 Importing references . . . .5-27 Exporting lists . . . .5-27
Overview
A MIMEsweeper for SMTP Reference is a configuration item containing a list of expressions, checksums or script details that are used during text and content analysis. These lists, or References, are used by scenarios to detect certain types of message content, for example, profanity. References provide a resource for use by scenarios.