Set up and test Sophos Email Monitoring System
Purpose and quick answer
Set up Sophos Email Monitoring System (EMS) in five steps: check EMS mode, provision mailboxes, add the domain, configure journaling and policies, and test mail flow. Through journaling, EMS receives a copy of inbound and outbound emails, scans and logs them, and then discards the scanned copy. The original message is delivered unchanged.
EMS is therefore a monitoring system, not a second mail gateway: displayed policy actions are observational results. EMS does not block, encrypt, or quarantine the original message. Everyone involved should understand this boundary before onboarding so that a successful EMS result is not mistaken for actively enforced email protection.
Prerequisites, licensing, and roles
Check the following before starting:
- The Sophos EMS license has been added to the Sophos Fusion account. This enables EMS mode by default.
- EMS and Sophos Email are alternatives and cannot be used in the same account at the same time. Switching modes requires a new domain configuration.
- A Super Admin is available to manage EMS domains.
- The responsible administrator knows which mail service is in use and can configure its journaling. Microsoft 365 and Google Workspace have different provider-specific procedures.
- The user mailboxes, distribution lists, public folders, and aliases to be monitored have been inventoried. At least one limited-scope test mailbox in the domain is available.
- If an upstream email security service is in use, its actual delivery IP addresses are known. Do not copy these values from a sample environment.
Mailboxes can be added manually, by CSV, or via AD Sync or Microsoft Entra ID Sync. If you use synchronized objects, first clarify the prerequisites and ownership boundaries for Directory Sync. A synchronized mailbox is subsequently deleted in Microsoft AD or Microsoft Entra ID, not directly in Sophos Fusion.
Before changing the mode or production domains, record the initial state: active email mode, existing EMS domains, mail service, journaling rules, delivery IP addresses, test mailbox, and responsible administrators. This brief inventory provides a baseline for troubleshooting and rollback.
Configuration with adaptable example values
1. Check EMS mode
The full path is Profile icon > Account preferences > Sophos Email Monitoring System (EMS).
- In Sophos Fusion, click Profile icon.
- Open Account preferences.
- Under Sophos Email Monitoring System (EMS), check whether Monitor Only mode (EMS) is enabled.
- If necessary, enable the mode and select Save.
After saving, EMS is active for the account. A banner on affected pages indicates that emails are only monitored and no actions are applied.
2. Provision and check mailboxes
Under My Products > Email Security > Mailboxes, you manage the object types user mailbox, distribution list, and public folder. Before onboarding the domain, check that the expected recipients are present. You can check aliases and assigned policies in a mailbox’s details.
There are three approaches, depending on the ownership model:
- Import mailboxes automatically via AD Sync or Microsoft Entra ID Sync;
- Add mailboxes manually in the interface;
- Import mailboxes and aliases from a CSV file.
For a test mailbox, also check the primary user, aliases, and assigned policies. If a synchronized mailbox is missing, check the source directory first. Changes or deletions directly in Sophos Fusion would bypass the ownership model and are not intended for synchronized mailboxes.
3. Add an EMS domain
- Open My Products > Email Security > Settings.
- Select Products and Services > Email > EMS Domains in the left navigation.
- Click Add Domain. If no domain has been added yet, the button may be called Setup domains for EMS.
- Enter your email domain and select the actual mail service.
- If another email security service is upstream, enter its delivery IP addresses.
- Depending on the selected mail service, follow the instructions for Microsoft 365 or Google Workspace. Microsoft 365 uses the automatic EMS procedure; Google Workspace requires manual configuration.
- Return to EMS Domains and check the domain status.
The domain and test mailbox are environment-specific values. For a limited pilot, use a real, low-criticality domain and a designated mailbox such as ems-test@beispiel.ch; replace the placeholder with an address that actually exists in the configured domain. The delivery IP addresses must match the actual mail path; otherwise, EMS cannot correctly associate the journal messages.
4. Align policies with the existing environment
Under My Products > Email Security > Policies, Email Security and Data Control policies are available in EMS mode. Their actions are logged only as expected outcomes and are not enforced on the original messages. Configure them to reflect the existing email environment as closely as possible.
Some features cannot be configured in EMS mode. These include SMTP Routing, Time of Click, Self Service Portal, and Secure Message policies; encryption of a journal copy is also unsupported. Missing controls should therefore not be “fixed” by changing mail flow.
For post-delivery message actions, EMS supports only on-demand clawback. Automatic search and remediation (automatic search and remediate) are unavailable in EMS mode. Setting up and evaluating such actions is outside the scope of domain configuration.
Global email settings are available via the Global Settings icon under Products and Services > Email. Before a broad rollout, check a small, documented group of recipients first. This makes it possible to explain observational results without changing the production mail path at the same time.
Validation and expected result
Quick Test for a domain
- Open My Products > Email Security > Settings > Products and Services > Email > EMS Domains.
- Click Quick Test icon for the configured domain.
- Enter an existing mailbox in that domain as the Quick Test mailbox.
- Start the test.
The Quick Test sends a sample message and checks the journaling rule. On success, the specified mailbox and journal destination each receive a copy of the test message according to the journaling configuration. If the test does not complete within the expected time, wait a few minutes and retry it once.
Confirm inbound and outbound mail flow
After a successful Quick Test, send one inbound and one outbound test message for a recipient covered by the journaling rule. Then open My Products > Email Security > Reports > Message History.
The test succeeds when matching entries appear there. At the same time, the original message must be delivered unchanged through the existing mail service. A logged EMS verdict shows what Sophos Email would have done; it does not prove that the original message was blocked or quarantined.
Troubleshooting by symptom
Quick Test times out
Wait a few minutes and retry the test once. If it still produces no result, check the delivery IP addresses, test mailbox, and active journaling rule, in that order. Avoid changing the domain, rule, and delivery IPs simultaneously, as this makes the cause harder to isolate.
The test mailbox receives no message
Under My Products > Email Security > Mailboxes, verify that the entered mailbox actually exists and belongs to the configured domain. For a synchronized mailbox, then check the email attribute, filter, and status in the source directory. Next, ensure the journaling rule is active and correctly configured.
Message History remains empty
First confirm that the Quick Test succeeded. Then send an inbound and an outbound message to a user covered by the rule and reopen My Products > Email Security > Reports > Message History. If no entries appear, check the delivery IP addresses, mailbox inventory, and journaling rule. If these three checks reveal no error, escalate the case to Sophos Support with the domain, time, test sender, test recipient, and visible domain status.
Delivery IP addresses are incorrect
Compare the addresses entered in EMS with the actual final delivery path of the journal messages. If an upstream security service is in use, its actual outbound IP addresses are authoritative, not generic provider or example values. After correcting them, repeat the Quick Test first, followed by one inbound and one outbound mail test.
Policy actions are not executed
This is expected behavior in EMS mode. Email Security and Data Control actions produce reporting verdicts only. If messages need active protection or modification, reassess the deployed protection solution and mail-flow configuration; an action must not be considered executed solely because of an EMS verdict.
Sophos Support needs access
Enable Remote Assistance only upon a specific request and after internal approval. The path is Profile icon > Account Details > Sophos Support; there, Remote Assistance can be enabled for a limited time. After the case is closed, check the remaining access period.
Safe rollback or offboarding
Remove an individual domain
Deleting a domain immediately stops its EMS scanning and logging. Document the domain status, journaling rule, delivery IP addresses, and provider-specific resources beforehand.
- Open My Products > Email Security > Settings > Products and Services > Email > EMS Domains.
- Select Delete icon for the desired domain.
- Click Delete in the confirmation dialog.
- Confirm that the domain is no longer monitored.
- Carefully remove manually configured journaling rules and dependent configurations at the mail provider, and reset the associated domain or email settings.
For automatically configured domains, Sophos removes the association between journal rules and the deleted domain. If this was the last domain in a Microsoft 365 tenant, the journal rules and Microsoft 365 application created by Sophos are removed. Background cleanup may take a few minutes; do not start further EMS domain actions during that time. Sophos cannot reset the NDR fallback mailbox; adjust it manually in Microsoft Purview if necessary.
Disable EMS mode or switch to Sophos Email
Before disabling the mode, understand that all remaining EMS domains will be disconnected. First record the domain list and provider-specific configurations, then disable the mode under Profile icon > Account preferences > Sophos Email Monitoring System (EMS). Afterwards, confirm that the domains are disconnected and clean up any remaining manual journaling configurations at the provider.
The policies remain in place, but domain configurations for EMS, Sophos Gateway, and Sophos Mailflow differ. Recreate them for the new mode; simply switching modes is not an established automatic, lossless rollback path. If ownership or removal of a resource at the mail provider is unclear, stop before deleting it and clarify its status with the responsible provider administrator or Sophos Support.
Operations, review, and lifecycle
For ongoing operations, document the domain, mail service, delivery IP addresses, journaling owner, test mailbox, and last successful Quick Test. After changes to mail routing, journaling rules, mailbox synchronization, or provider configuration, repeat Quick Test and an inbound and outbound test, then check the entries in Message History.
Also regularly check whether the policies still match the production email environment. This matters because EMS provides observational results only: an outdated EMS policy can produce a plausible-looking verdict that says little about the actual environment.
The current product interface and help are authoritative for current functionality. Do not infer a shutdown, migration, or end-of-life date from older announcements.
Related existing guides
- Prepare Directory Sync for Sophos Email: authoritative directory, preview, validation, and deletion boundaries for synchronized mailboxes.
- Set up EMS journaling for Microsoft 365: automatic provider procedure and its rollback.
- Set up EMS journaling for Google Workspace: manual routing and journaling configuration.