Sophos Email: configure malware, attachment, and URL protection
Malware, attachment, and URL protection shouldn’t be treated as isolated switches. What matters is which policy applies to which direction and recipients, what action a detection triggers, and whether Message History confirms the outcome. This workflow covers Sophos Email in Sophos Fusion (formerly Sophos Central), not Mail Protection on a Sophos Firewall.
Safe starting point: initially quarantine known malware and unscannable inbound messages, keep enhanced content and file-property scanning on, and use the recommended extraction and scanning of URLs from QR codes. Use deletion only after the team can reliably investigate false classifications. An exception must never turn off malware scanning.
Record the policy and starting state
Before changing anything, open the relevant Email Security Policy and record:
- direction: inbound or outbound;
- assigned users, groups, and domains;
- the rule position and rules above it;
- current actions for malware, unscannable messages, Intelix, and URL or QR code detections;
- known, business-approved exceptions;
- one controlled sender, recipient, and message combination for acceptance testing.
Scope matters. Enhanced content and file property scan applies to inbound and outbound messages, whereas the unscannable-email action applies only inbound. A correctly configured rule that doesn’t match the intended mail flow provides no protection there. Check assignment and order before editing its controls.
For later diagnosis, also record current SPF, DKIM, and DMARC status, the visible sender-check sequence, and the new-sender learning period. That period can be 0 to 90 days, is 14 days by default, begins with the sender’s first inbound message, and changes affect newly observed senders. These sender signals can explain an additional classification, but don’t replace malware or URL scanning.
Configure malware and unscannable attachments
Known malware
Under Anti-malware scan, the actions for a message containing known malware are Delete and Quarantine. Quarantine is safer during rollout because an administrator can investigate the detection. Delete removes the message immediately and should be used only with an approved operating procedure.
If a message quarantined as Malware/Virus is released, the user receives a new email containing the original malicious message as a password-protected ZIP file. The password is in the new email. Release is therefore not normal delivery; keep it a deliberate, recorded decision.
Enhanced content and file-property scanning
Enhanced content and file property scan uses message and attachment metadata in heuristic rules. It applies inbound and outbound and is on by default. Keep it on unless Sophos Support advises otherwise for a specific investigated case. For a false detection, narrow down the rule, direction, file, and verdict before considering any change.
Unscannable inbound messages
A message can be unscannable because a file is corrupt or inaccessible, content is unexpected, the scanner times out, or a compressed attachment is too large or too deeply nested. The documented actions are Quarantine, Delete, Tag subject line, and Add banner.
Use quarantine for rollout. A subject tag or banner doesn’t make unchecked content safe. If a smart banner is used, it appears at the top of inbound HTML messages; in plain text, the same content appears at the start of the body. User actions such as Allow sender, Block sender, and Report messages to Sophos must fit the organization’s self-service process. In particular, Allow sender isn’t a remedy for a scan failure. Sophos-encrypted email and messages from addresses or domains on the Inbound Allow/Block list still undergo malware scanning.
Receive copies of reported messages safely
Go to Global Settings > Products and Services > Email > User Settings, turn on Copy of reported messages, and select one or more recipient mailboxes and/or distribution lists. Every configured recipient receives a copy of every message reported to SophosLabs: reports submitted as threats and as clean, whether submitted by a user or an administrator.
The notification attaches the original message and includes the reason, reporter, notification recipients, original-message recipients, subject, and timestamps. It also includes exactly these headers for automation:
X-Sophos-EmailReported-ReportedAsX-Sophos-EmailReported-CategoryX-Sophos-EmailReported-SubCategoryX-Sophos-EmailReported-ReportedDate
Because the attachment can contain malicious or sensitive content, restrict access to the selected mailboxes and distribution lists to the responsible investigation team and treat the attachment as untrusted evidence. Don’t open it directly on a normal workstation; inspect it only through the approved isolated analysis process.
Sophos Fusion raises an alert when a configured mailbox or distribution list becomes unavailable. Monitor that alert, repair or replace the affected recipient object, and then confirm that a copied report is received again.
Set Intelix Threat Analysis actions
Intelix examines potentially active malicious content in an isolated environment with static and dynamic analysis. Set actions separately by verdict:
- Intelix Malicious: Quarantine or Delete;
- Intelix Suspicious: Quarantine, Deliver, Delete, or Tag subject line;
- Intelix Unscannable: Sophos quarantines the message when Intelix can’t scan it.
For a pilot, quarantine both Malicious and Suspicious. Delivering suspicious messages directly requires a documented risk decision. If the Intelix service-location selector is available, Let Sophos decide (recommended) is the documented option for automatic performance-based routing.
Configure URL and QR code protection
When QR Code Scanning is enabled, the modes have different meanings:
- Extract URLs and scan for potential threats (Recommended): extracts URLs from QR codes in images and attachments and checks them like ordinary URLs.
- Detect all emails with QR Codes: applies the configured action to every message containing a QR code; it does not analyze the code’s content.
The second mode is a blanket QR-code control, not a deeper URL analysis. Use extraction and scanning for normal protection. For detected malicious URLs or QR codes, choose Quarantine (Recommended) or Delete. Quarantine is the safe starting point. Releasing a message quarantined for URL/QR Code sends the original message inside a password-protected ZIP in a new email.
Two protection outcomes override normal exceptions:
- If a message contains an entry on the Internet Watch Foundation criminal URL list, Sophos deletes it regardless of the Email Security policy. The URL also can’t be shown in Sophos Fusion or Message History.
- Sophos stops URL scanning when a message contains a very large number of URLs. The threshold isn’t published for security reasons. The message is quarantined as Unscannable - Excessive URLs. Neither the unscannable-email setting nor an allowed sender prevents this protection.
For inbound messages, Time of Click URL Protection can rewrite ordinary URLs so Sophos performs an SXL lookup at click time. High-risk sites can’t be allowed; the documented options for Medium Risk and Unverified are Block, Warn, and Allow. URLs in QR codes aren’t rewritten. Review plain-text and S/MIME- or PGP-signed mail before changing rewrite behavior: rewriting protects the link but can change presentation, while not rewriting preserves the signature but leaves the link unprotected. This control doesn’t apply to DKIM-signed messages because DKIM is checked before message modifications.
Test safely and inspect Message History
Start with a small, unambiguous group. Never email live malware or unknown samples. Use only an internally approved controlled test object and isolated recipient for a negative test. If no such process exists, inspect an existing quarantined detection rather than creating malware.
Acceptance testing includes:
- a normal inbound and outbound message with a clean, representative business attachment;
- a controlled message that triggers the approved malware or attachment check;
- a clean URL and a controlled URL or QR-code test for the intended action;
- a legitimate message with known SPF, DKIM, and DMARC results, so sender authentication isn’t confused with a malware verdict;
- a signed or plain-text message if its URL-rewrite handling changed.
Record time, direction, sender, recipient, and Message-ID. In Message History, open Message Details and compare the category, verdict, and action with the policy. The URL tab shows URLs extracted from text or QR codes. An IWF URL being absent is expected, not a logging defect. For excessive URLs, look for Unscannable - Excessive URLs.
The test passes only when normal mail follows the intended path, the controlled detection triggers the expected action, and Message History confirms the same direction and recipient combination. Delivery alone doesn’t prove that the intended rule matched.
Troubleshoot false classifications methodically
A legitimate Office file is blocked as CXmail/OleDl
Sophos Email detects Office attachments whose macros download additional files or malware as CXmail/OleDl; related endpoint detections can be named Troj/DocDl. Aggressive detection can affect legitimate files. Confirm the Message-ID, filename, actual business source, and verdict first. For that specific exchange, Sophos recommends putting the Word or Excel document in a password-protected ZIP. Automatic macro execution in Microsoft Office should also be disabled. This is a narrow delivery alternative, not a global sender allowance or a reason to disable malware scanning. See the Sophos recommendations for Troj/DocDl detections.
The expected action doesn’t occur
Check in this order:
- Does the direction match, and is the sender or recipient actually in the policy’s user, group, or domain scope?
- Did a higher-priority rule match first?
- Is the verdict known malware, Intelix Suspicious/Malicious, unscannable content, or a URL/QR-code category? They use different actions.
- Was the message inbound? The unscannable-message action doesn’t apply outbound.
- Does Message History contain the expected record and extracted URL on the URL tab?
It may be a sender issue, not a content issue
If history also shows a sender or authentication failure, inspect sender-check details and raw headers. Evaluate SPF, DKIM, and DMARC separately; record which check failed first and which policy actually caused the action. Compare the new-sender learning period with the first inbound message date. Decide on a narrowly scoped correction only after cause and order are clear. Never use a sender allowance to bypass malware, URL, or scanning failures.
A URL or QR code behaves differently than expected
For QR codes, first establish whether extraction and scanning or blanket detection of all QR-code messages is selected. For Time of Click, check that the message was inbound, whether it was plain text or securely signed, and whether another service had already rewritten the link. Sophos can’t re-evaluate a URL after another product has rewritten it. Releasing a message from quarantine also doesn’t rewrite its URLs.
Roll back without opening a protection gap
Before the change, store the original scope, order, and actions in the change record. If the pilot fails, restore exactly those values, then use normal inbound and outbound messages to confirm that the previous rule matches again. Remove any newly created broad exceptions.
Rollback must not disable malware scanning or broadly deliver malicious or unscannable messages. If a legitimate message can’t be classified safely in time, retain it in quarantine and use a controlled alternate exchange method. Collect the Message-ID, raw headers, category, verdict, policy scope, rule position, and affected file or URL for escalation. This keeps protection active while the cause is investigated.