Skip to content
Avanet

Sophos Email Monitoring System (EMS): Function and Limitations

The Sophos Email Monitoring System (EMS), also known as Email Sensor, scans and logs copies of emails without changing the original messages or affecting their delivery. It is therefore suitable for organizations that want to continue using Microsoft 365, Google Workspace Security, or another email security solution while also receiving Sophos analytics and context for MDR or XDR.

Direct answer: EMS provides visibility, not email protection. For example, a policy may report a simulated verdict of “quarantine,” but EMS does not hold back the production message as a result. Anyone who needs encryption, enforced policy actions, automated post-delivery remediation, or a Self Service Portal needs Sophos Email instead of EMS.

How Sophos EMS works

Through journaling, the email service creates a copy of every captured inbound and outbound message and sends it to EMS. Sophos scans this copy and records the results in Message History, Quarantined Messages, and other reports. The original message remains on its existing delivery path and reaches the intended recipient unchanged.

This results in two important limitations:

  • If Microsoft 365 or Gmail blocks a message before a journal copy is created, EMS cannot scan it.
  • Internal emails between two domains configured in the same Sophos Fusion account are not scanned. This also applies if the domains belong to different tenants or use different providers.

The displayed policy actions are therefore observational findings: they show what Sophos Email would have done. They do not prove that EMS blocked, encrypted, or quarantined the production message.

EMS and Sophos Email compared directly

FeatureSophos EMSSophos Email
Email protectionmonitoring and visibility onlyfull protection
Message flowscans journal copies; no effect on deliveryscans live traffic via gateway or Microsoft 365 mailflow
Policy actionsreference only in reportsenforced
Content findingsflags sensitive content in reportsenforces the configured action
Encryptionnot supportedsupported
Time of Clickdisplays URL findings but does not rewrite linkssupported
Manual Clawbacksupportedsupported
Auto search and remediatenot supportedsupported
Post-delivery quarantinecontains only manually recalled messagescontains manually and automatically recalled messages
Quarantined Messagesreference for scanned copies; messages are not held backmessages are actually held back
Self Service Portalnot availableavailable
Logging and reportinglogs findings for visibility and MDR/XDRlogs findings, actions, and policy results

EMS and Sophos Email are alternative operating modes and are not used simultaneously in the account described here. Switching is therefore a migration, not an additional checkbox for the same production mailflow.

Prerequisites, license, and roles

EMS is part of Sophos Workspace Protection and is licensed by mailbox. For this bundle, the highest usage of any included product determines the required quantity; the individual product quantities are not added together. How is Sophos Fusion licensed? explains the details and provides examples.

Before deployment, the following points must be clarified:

  • The appropriate Workspace Protection license is active in the Sophos Fusion account.
  • Mailboxes have been added through Directory Service, the user interface, or CSV.
  • The domains to be monitored and the email service in use are known.
  • Journaling can be configured for Microsoft 365 or Google Workspace. If an existing third-party security solution is in place, its type and, where applicable, its delivery IP addresses must also be known.
  • A Super Admin is responsible for domain management. Permissions in the email service remain separate and must be assigned appropriately there.
  • Those responsible for email explicitly accept that EMS performs no delivery action.

After an EMS license is added, the mode is active by default. Nevertheless, a Super Admin checks under Profile icon > Account preferences > Sophos Email Monitoring System (EMS) that Monitor Only mode (EMS) is actually enabled.

Plan deployment with customizable sample values

For a sample environment with the domain example.com, Microsoft 365, existing Microsoft Defender for Microsoft 365, and 120 mailboxes to monitor, the decision process looks like this:

  1. Replace example.com with the production domain and compare the number 120 with the actual mailbox count and the available Workspace Protection quantity.
  2. Under Profile icon > Account preferences > Sophos Email Monitoring System (EMS), check that Monitor Only mode (EMS) is enabled.
  3. Add the domain under My Products > Email Security > Settings > Products and Services > Email > EMS Domains with the actual mail service. If an email security solution is already in place, enter only its actual delivery IP addresses; do not guess IP addresses.
  4. Configure journaling for Microsoft 365 or Google Workspace. EMS needs journal copies from every direction that is to be monitored.
  5. Align the policy actions of the configurable Email Security and Data Control policies with the existing production policy landscape. In EMS, they serve exclusively as reporting verdicts.
  6. Validate the configuration with an actual, limited Quick Test mailbox. Only then expand the test to one captured inbound and one captured outbound message.

The example describes the decisions, not a universal copy-and-paste procedure. The domain, email service, mailbox, delivery IP addresses, and journaling scope must match your own environment. Particularly when an upstream security solution is in place, the actual delivery path determines the configuration.

Validation and expected result

After configuring the domain and journaling, start Quick Test for the affected domain under My Products > Email Security > Settings > Products and Services > Email > EMS Domains. Use an existing mailbox in that domain as the test address.

The expected results are:

  1. Quick Test completes successfully.
  2. The journal mailbox and specified mailbox receive the test copies according to the journaling configuration.
  3. Limited inbound and outbound test messages appear under My Products > Email Security > Reports > Message History.
  4. The production messages continue to be delivered unchanged; configured EMS actions appear only as findings.

If Quick Test does not complete within the expected time, wait a few minutes and repeat it once. If results are still missing, do not continue configuring additional domains or rules on a trial-and-error basis.

Troubleshooting by symptom

Quick Test times out or no test email arrives

First, check whether the test mailbox actually exists in Sophos Email Security. Then compare the configured journal rule and, for a third-party solution, the Sophos Delivery IPs with the actual delivery path. If the journal rule is inactive or scoped incorrectly, correct it in the email service and run Quick Test again. If the error persists after these checks, document the domain, email service, test mailbox, time, and observed result for Sophos Support.

Message History remains empty

Under My Products > Email Security > Reports > Message History, first check the time range and the tested sender/recipient direction. Then ensure that the mailbox has been added and that the journal rule covers exactly this direction and this domain. Successful production delivery alone does not prove that a journal copy was sent to EMS.

External messages appear, but internal messages are missing

This may be the documented product limitation: messages between domains in the same Sophos Fusion account are not scanned. Therefore, use external test senders or recipients for validation. An additional journal rule does not remove this EMS limitation.

The report shows quarantine, but the message is in the mailbox

With EMS, Quarantined Messages initially serves as a reference for journal copies. The finding does not mean that Sophos held back the original message. In EMS, messages are actually quarantined after delivery only when an administrator manually recalls them from Microsoft 365 using Clawback.

Correctly understand MDR, XDR, and manual Clawback

EMS feeds email data into the Sophos Data Lake and can therefore provide additional indicators for detection and investigation. However, this does not make EMS itself either MDR or XDR:

  • Sophos MDR is a separate, 24/7 managed service. Onboarding, integrations, and active incidents are managed under My Products > MDR.
  • Sophos XDR is licensed separately. Your own investigations using Data Lake, Live Discover, detections, and cases take place in the Threat Analysis Center.
  • An EMS reporting verdict is not automatically a detection or a case.

For Microsoft 365, the API integration supports manual clawback. This is a targeted administrator action for messages that have already been delivered. EMS does not support Auto search and remediate; only on-demand Clawback is available.

Safe migration and offboarding

Migrate from Sophos Email to EMS

Document existing gateway or mailflow dependencies before switching. Then:

  1. Remove the domains from the existing gateway or mailflow configuration.
  2. Depending on the mode previously used, revert the MX configuration or mailflow settings.
  3. Enable the mode under Profile icon > Account preferences > Sophos Email Monitoring System (EMS).
  4. Add the domains again and fully complete EMS onboarding, including journaling and validation.

With release 2026.38, Sophos introduced automatic Microsoft 365 journaling configuration for EMS onboarding. Sophos creates it after the required permissions have been authorized. Plan the migration path back in advance nevertheless, because EMS and Sophos Email cannot run in parallel in this account mode.

Migrate from EMS to Sophos Email

  1. Remove the affected EMS domains. This immediately stops scanning and logging for that domain.
  2. Remove the remaining journaling configuration. For automatically configured Microsoft 365 domains, Sophos removes the journal rule and associated configuration when the last domain is deleted; background cleanup may take a few minutes.
  3. Disable Monitor Only mode (EMS). This automatically disconnects any EMS domains that are still connected.
  4. Add the domains again, then fully configure and test the gateway or mailflow.

Manually created journal rules and dependent configurations must also be removed manually. Do not start any additional EMS domain operations while automatic Microsoft 365 cleanup is in progress. The migration is complete only after the target mode has been verified.

Operations, review, and lifecycle

During operation, regularly check the license quantity, mailbox count, domains, journal rules, delivery IP addresses, Quick Test, and current entries in Message History. Changes to the email service, domains, or an upstream security solution trigger a new limited test for each monitored direction.

Sophos publishes product changes in the shared release notes stream for Sophos Email Security. Specifically check EMS entries and their release date and feature or behavior change; general Sophos Email changes do not automatically apply to EMS. Before major changes or a renewal, compare the documented behavior with the current EMS product and licensing documentation.

Sophos has not currently published a separate end-of-life or retirement date for EMS. This does not constitute a commitment to unlimited support.

As a next step, select the appropriate detailed guide: Set up and test Sophos Email Monitoring System, Sophos EMS: Configure policies and interpret findings, or Analyze Sophos EMS telemetry and recall emails using Clawback. For license quantities, bundle composition, and terms, see How is Sophos Fusion licensed?.