Configure Sophos Email anti-spam and outbound threats
An Email Security Policy combines classic spam scoring with country and language detection and protection against new domains and senders. The same policy can add a disclaimer to outbound messages. A safe configuration doesn’t start with Delete, but with a measurable pilot: record policy scope and order, initially tag or quarantine suspicious messages, and enforce more strictly only after evaluating the results.
Recommended quick path: Initially set Confirmed Spam and Bulk to Quarantine, and Suspected Spam to Tag subject line. Then enable country, language, Newly Registered Domain (NRD) Protection, and New Sender controls only where you know the business exceptions. Test each change with legitimate and suspicious messages in Message History and Quarantined Messages. An exception must never disable malware scanning.
Prepare the pilot and policy scope
Under My Products > Email Security > Policies, select the Email Security Policy you want to change. First document:
- direction, affected users, groups and domains, and current policy order;
- existing actions and ownership of administrator and End User Quarantine;
- legitimate newsletters, automated senders, partner countries and languages actually required;
- current SPF, DKIM and DMARC results from representative messages;
- for Gateway domains, the outbound connector, public sending IP and SPF record;
- a window, success criteria and the original policy state for rollback.
Authentication results are control values here, not a blanket allow decision. A message that passes SPF, DKIM or DMARC may still be unwanted, while a failure may result from forwarding or incorrect sender configuration. Review the spam category, sender checks, policy assignment and raw headers together before creating an exception.
If several policies cover different recipients or sender domains, give them unambiguous names and record their order. For example, a limited pilot policy for a support group can be less aggressive than the general policy. After saving, verify that the intended policy is Enforced and that the test message actually falls within its scope.
Grade anti-spam actions
Under Settings > Inbound > Anti-spam, Sophos Email distinguishes three categories:
- Confirmed Spam matches known and verified spam patterns.
- Bulk is solicited mass mail, such as a mailing-list newsletter. Bulk is therefore not automatically malicious.
- Suspected Spam has suspicious attributes but doesn’t meet the threshold for Confirmed Spam.
Choose an action for each category:
- Deliver passes the message to the next anti-spam check. It expressly doesn’t mean the user has received it.
- Delete deletes it immediately, without a normal release path.
- Quarantine holds it for review. Include In End User Quarantine can additionally make it available in the user’s quarantine.
- Tag subject line adds a configurable prefix of up to 30 characters to the subject and delivers the message.
Sophos recommends starting with Quarantine for Confirmed Spam and Bulk, and Tag subject line for Suspected Spam. Messages with excessively large bodies are quarantined for security reasons regardless of these settings.
Increase Suspected Spam detection under control
The slider increases the catch rate one level at a time; a higher level is more aggressive. The detected level appears in Message History, for example as Suspected L3. More detection typically means more false positives. Change only one level, monitor false positives and false negatives for a period representative of your mail flow, and don’t change both scope and action at the same time.
Where spam exposure is high, you can quarantine rather than tag Suspected Spam. Separate policies for sensitive recipients, groups or known sender domains are often easier to understand than a global relaxation. Frequent changes in response to individual spam runs make assessment unreliable because those runs are sporadic.
Filter countries and languages only with a sound business rule
Country of origin
Under Settings > Inbound > Country of origin, select Tag subject line, Quarantine or Delete, followed by the disallowed countries. Keep Check for every message hop selected so that every message hop is evaluated, not only the first visible association with a sender IP.
Country assignment is IP-based and can produce false positives when an address is registered in a different country from the actual sender. Sophos specifically advises against broadly disallowing the US because many sender IP addresses are registered there. Start new country rules with tagging or quarantine and inspect the complete Received chain in the raw headers. Use Delete only after business communication and false positives have been observed over time.
Language
Under Settings > Inbound > Language, select the disallowed languages and Tag subject line, Quarantine or Delete. Optionally, Include In End User Quarantine adds hits to the user’s quarantine.
Detection evaluates only the meaning of the message body. It ignores subjects, attachments, numbers, special characters, symbols and URLs. Short or cryptic text, similar languages, multilingual content and machine-generated templates can therefore be misclassified. Attachments in another language aren’t detected by this setting. Language rules are an additional signal, not a replacement for malware scanning or Data Control.
Detect new domains and senders
Both controls are under Settings > Inbound > New domain/sender, but answer different questions: NRD evaluates a domain’s registration age, while New Sender evaluates the previous relationship between a sender and the individual mailbox.
Newly Registered Domain Protection
- Turn on Newly Registered Domain (NRD) Protection.
- Under Domain age threshold, select the period within which a domain is considered new.
- If required, select Include “Envelope from” domain. This evaluates both the visible Header from and technical Envelope from domains.
- Select Quarantine, Deliver, Tag or Banner. When selecting Quarantine, optionally select Include In End User Quarantine to include NRD hits in the user’s quarantine. An NRD tag can contain up to 65 characters; the default is
[Newly registered domain]. - With Banner, you can offer Report spam. Save the policy.
A new domain is a risk signal, not proof of an attack. Banner, Tag or Quarantine are therefore safer pilot actions than automatic deletion. In Message History and Quarantined Messages, verify which domain triggered the result and whether Header from and Envelope from match the selected option.
New Sender Protection and learning period
- Turn on New Sender and use the Edit icon to customize the alert text.
- Select the required banner actions: Allow sender, Block sender and/or Report spam. Allow and Block only appear if they are also enabled in User Settings.
- Optionally enable Include persistent unanswered senders. The alert then remains on repeated messages until the recipient replies or the learning period ends.
- Save the policy.
The feature evaluates each sender-mailbox combination separately and uses the preceding six months of sender history. With multiple recipients, the same sender may therefore appear new to only some mailboxes. An alias uses the history and policy of its primary mailbox. Sophos removes the alert from message content when a message is forwarded or replied to.
An allow-list entry for the sender address, domain or IP suppresses the New Sender alert. An administrator’s allow entry applies to all account mailboxes; a user’s entry applies only to that user’s mailbox. If a message is released from quarantine and the sender is allowed during release, the delivered message may still carry the banner; subsequent messages use the new allow entry.
New accounts and users first have a learning period. Set it via the Global Settings > Products and Services > Email > New Sender Settings icon under Number of days to 0, 7, 14, 30, 45, 60 or 90 days; the default is 14 days. It starts with the first inbound message, not when the mailbox is added. Sophos collects data during this period but doesn’t show New Sender alerts. A change applies only to new accounts or senders first observed after the change and doesn’t reset existing sender data.
Include persistent unanswered senders also requires outbound mail to pass through Sophos Email so replies can be observed. For an inbound-only domain, the alert appears only on the first message regardless of this option. If other Sophos banners are active, Sophos can combine the messages; an action appears when at least one applicable policy allows it. Review every offered banner action, not only its text.
Add an outbound disclaimer
Under Settings > Outbound > Outbound Disclaimer, turn on Add disclaimer to plain text messages, Add disclaimer to HTML messages, or both. Each entry can contain up to 5,000 characters. After Save, verify again that the policy is Enforced. The text is appended to every outbound message matching the policy.
For acceptance testing, send one plain-text and one HTML message to a controlled external mailbox. Check the visible footer and, for HTML, that the layout remains readable. A disclaimer doesn’t prove encryption, authenticity or legal effect; it only appends the configured text.
Validate changes conclusively
After each individual change, use a small test matrix:
- a normal business message and a legitimate newsletter;
- a previously known, safely handled spam or quarantine case rather than a self-made malicious message;
- a controlled new sender and, if available, a controlled newly registered test domain;
- a plain-text and an HTML message for the outbound disclaimer;
- one message for each expected SPF, DKIM and DMARC result.
In Message History, compare timestamp, sender, recipient, direction, applied policy, category or detection detail, and action. Then inspect Quarantined Messages, actual mailbox delivery, banner or subject tag, and raw headers. Success is not merely “mail arrived,” but evidence that the intended policy and action were applied.
For administrator-side diagnostics, review the evidence in this order: 1. policy scope, direction and order; 2. spam category and configured action; 3. applicable sender controls; 4. SPF, DKIM and DMARC results; 5. raw message headers. This is a repeatable diagnostic sequence, not a claim about Sophos’s internal processing order.
Keep the original state until the pilot ends. If false positives rise, first restore the most recently changed slider, action, country/language selection, domain-age threshold or banner option to its documented value. Don’t change multiple signals simultaneously or create a broad allow exception as a quick rollback.
Understand the delay queue
Suspicious messages can remain in the delay queue for 5 to 60 minutes. Sophos Email builds a history of sending IP addresses and uses heuristics against snowshoe spam, where a campaign is spread across many domains and IP addresses. It rescans the message after the delay so that detections made available in the meantime can take effect.
Release within 60 minutes is therefore expected behavior, not a delivery failure. Support also can’t manually release a message early while it awaits rescanning. If the state lasts longer, record Message-ID, sender, recipient and timestamp, inspect Message History, and escalate the specific case rather than disabling spam or malware protection.
Handle false positives safely
For Suspected Spam, first compare policy, level, category, headers and action. You can then lower the level by one step, tag rather than quarantine for a limited scope, or allow a narrowly defined legitimate sender address or domain. An allow rule isn’t an appropriate answer to an unexplained country, routing or authentication discrepancy. In particular, it must never be broad enough to bypass malware scanning.
When legitimate outbound messages are deleted as spam
This emergency procedure applies specifically to a Gateway domain when Sophos incorrectly identifies and deletes legitimate outbound messages as spam:
- Send the affected original message as a sample to
not-spam@labs.sophos.com. - Open a support case with the address used to send the sample, date and time, and subject.
- Before the workaround, preserve the current domain mode, send connector, route, public sending IP and SPF content. Direct internet delivery must already be planned, authorized and tested.
- In Gateway Domain settings/status, change the direction to Inbound Only and select Save.
- Configure the mail server’s send connector to deliver directly to the internet instead of through Sophos Email. If SPF is used, its record must authorize the public IP used for this path.
- Use a controlled external message to verify direct delivery, raw headers and the SPF result. Keep monitoring enabled for the now-unscanned outbound path.
This workaround temporarily removes Sophos outbound scanning and isn’t a general anti-spam exception. Use it only with change approval and a named owner. If direct delivery or the SPF adjustment isn’t safely prepared, stop before cutover and escalate.
Sophos Support will advise when the detection has been corrected. To roll back in a maintenance window, restore the documented route through Sophos and the previous domain direction, undo only temporary direct-delivery and SPF changes, and retest outbound delivery in Message History and the external mailbox. If results are unexpected, return to the last proven, documented route and update the support case.
Typical failures
- The test message receives a different action: Check policy scope, direction, order and Enforced status; then compare the category and other sender checks in Message History.
- Too many legitimate newsletters are quarantined: Don’t equate Bulk with Confirmed Spam. Test a limited policy or tagging before allowing globally.
- The country filter blocks a known partner: Investigate every
Receivedhop and its IP assignment. Don’t assess only the visible From domain. - Language detection appears wrong: Evaluate only the body. Account for short, multilingual or automated text and ignored attachments, subjects and URLs.
- The New Sender banner is missing: Check learning period, allow list, six-month mailbox history, policy assignment and an alias’s primary mailbox.
- The persistent-unanswered alert disappears: Verify outbound replies also pass through Sophos Email. The feature isn’t available with Inbound Only.
- The disclaimer is missing: Check direction, policy scope, Enforced status and the separate plain-text and HTML options.