Administer Sophos Email quarantine
The Quarantined Messages page combines messages from all protected mailboxes. Before taking action, identify the list containing the item: ordinary Email Security quarantine holds a message before delivery; post-delivery quarantine claws back a message that was already delivered. That difference changes the effect, validation, and risk of a release.
This workflow is for Sophos Fusion (formerly Sophos Central) administrators. User releases in the Self Service Portal and quarantine summaries are a separate self-service process. Automation through the Email Quarantine API is also outside this GUI runbook.
Prepare access, authorization, and source data
Use a named administrator account in the correct tenant and apply least privilege. The predefined Admin role can release email on Quarantined Messages; view access alone isn’t release permission. Sophos Fusion administrative roles explains role selection and assignment. Before starting, verify that the account actually offers the actions authorized in the request.
Record the ticket or change, time window, expected sender and recipient, subject, message ID, suspected reason, and authorized action. Before a bulk action, separately record the applied filters, result count, and message IDs in the ticket or change record. Open attachments and URLs only in an approved analysis environment; an administrator workstation isn’t a malware laboratory.
Distinguish quarantine type and retention
Open Quarantined Messages and deliberately select the appropriate tab:
- Email security quarantine contains messages held before delivery because standard Email Security policies classified them as spam, malware, or otherwise suspicious.
- Post-delivery quarantine appears only when post-delivery protection is enabled. These messages were delivered, later identified as malicious or risky, and clawed back. Subject and details are available for inbound messages; full details aren’t available for internally forwarded or replied-to Microsoft 365 messages.
- M365 quarantine appears only when M365 Quarantine is enabled and a post-delivery connection is configured. It shows messages quarantined by Microsoft 365. Connection setup, permissions, synchronization, and removal belong in the separate M365 setup process.
The page shows the current day by default. The selectable range is up to 30 days, or up to 90 days with Sophos Email Plus. Email Security quarantine messages are deleted after 30 days, or after 90 days with Email Plus. Unreleased post-delivery messages are deleted after 30 days. Don’t rely on quarantine as permanent evidence storage.
Search and narrow the result set
Open Advanced Search in the correct list. Available criteria are From, To, Subject, Message size, and Attachment. Partial sender, recipient, and subject strings aren’t case-sensitive. Message size uses MIME size and may exceed raw file size. Special and formatting characters in search fields are ignored.
Multiple criteria use logical AND. Start with the date range and recipient, then add sender, subject, or attachment type. Filter further by Direction, Status, or Reason. After changing the date range or filters, select Refresh. A gray cross removes a criterion immediately.
In Email Security lists, sender and recipient refer to SMTP envelope addresses. In M365 quarantine, From and To instead use header addresses. The arrows filter inbound or outbound messages. Post-delivery quarantine and M365 quarantine show no direction because all listed messages are inbound.
Before a bulk action, compare the quarantine list, time, recipient, Reason, message ID, and result count. A matching subject doesn’t prove that two records represent the same message.
Inspect the message safely in preview
Select the subject to open Message Details. Available tabs depend on the quarantine list:
- Details shows general data and identifies a post-delivery clawback.
- Raw Header shows the headers. AI Analysis can summarize SPF, DKIM, and DMARC results and security analysis, but doesn’t replace the raw header or underlying verdict.
- Message shows the body. For M365, you must acknowledge a connection to Microsoft services; retrieval may take longer.
- Attachments shows names and sizes. In Email security quarantine, authorized administrators can download, strip and reattach attachments, and reattach attachments removed by Data Control rules. Post-delivery quarantine permits downloads. M365 quarantine shows names and sizes only.
- URLs shows URLs found in the message. This is investigation data, not an invitation to click them. To save the URL list for this individual message, select Export here, then CSV or PDF. This is not the quarantine report for a date range.
Before exporting URLs, check that the request and your account permissions authorise viewing and saving this data. If the action is missing, check your role and the available message details rather than broadly extending permissions. Check the saved file and compare its URLs with the message under investigation; the export is not evidence of the complete original message content. Before sharing, remove unnecessary personal data and any tokens from a copy, and retain any required original with restricted access.
Downloading, stripping, or reattaching changes the risk. Perform these operations only for the documented case, never store unknown files on normal workstations, and record filename, size, verdict, and action.
Scan attachments with Intelix
The GUI-supported rescan applies only to messages with attachments in Email security quarantine. In Message Details, select Scan with Intelix. Analysis runs in the background and appears in Intelix Threat Summary. For a clean or likely clean verdict, you remain on the details page and can open View Intelix Report. A malicious or suspicious verdict redirects you to the report.
You can also select Intelix scanning before Release or Release and Allow. A clean or likely clean verdict releases the message; a malicious or suspicious verdict leaves it quarantined. With Release and Allow, the sender is allowed only after a clean or likely clean verdict. For messages already quarantined by Intelix, View Report opens the existing report.
Intelix reduces uncertainty but doesn’t authorize a business decision. If sender identity, authentication, or business context is inconsistent, keep the message quarantined even if its attachment appears clean.
Release, allow, delete, or block
Immediately before acting, recheck the tenant, tab, recipient, message ID, reason, and selection count.
- Release delivers an eligible message to the user. Sophos Email rescans it before delivery. Releasing a clawed-back post-delivery message also releases associated internally forwarded or replied-to messages.
- Release and Allow delivers the message and adds the sender address to Inbound Allow/Block. Enable Enforce Message Authentication so the allowed sender must pass at least one check such as DMARC, SPF, or DKIM. Use this only for a persistently verified sender, never to bypass malware, URL, or policy verdicts.
- Delete deletes the selected quarantine items. It isn’t a temporary hide operation; preserve evidence and verify selection and count first.
- Delete and Block deletes and adds the sender address to Inbound Allow/Block. Use the combined action only when both the current message and future sender traffic must be blocked.
For a targeted block, open Message Details. Under SMTP From, select Block, then Block sender or Block sender domain; Block IP Address is available under the IP address. Record a reason. Never block a shared provider IP without impact analysis: a Microsoft 365 IP can affect many unrelated senders.
In M365 quarantine, Release and Delete only send a request to Microsoft 365. Then use Refresh to reload data from Microsoft; selecting the button isn’t proof of successful processing, and changes may appear after a delay. The Sophos blocking actions described above don’t apply to this list.
Preserve reports and audit evidence
Use Export to download a quarantine report in CSV or PDF for the selected range or the last 90 days. Reports for selected administrators can be scheduled separately. Maintain the change or incident log separately from these reports.
For every handled case, record at least the tenant, administrator, timestamp, quarantine type, sender, recipient, message ID, Reason, relevant header and Intelix verdicts, selected action, item count, and ticket reference. Store attachments or full message content only when retention and privacy rules permit it.
Validate the result
Select Refresh and repeat the same search. Then confirm:
- Sophos Fusion accepted the selected action without an error. For Delete, record that response; a subsequently missing row alone isn’t proof of deletion.
- For Release, delivery to the correct recipient is confirmed. Use Message History to check whether processing continued or the message was quarantined again.
- For post-delivery, you know whether linked forwards or replies were released as well.
- After allow or block actions, Inbound Allow/Block contains exactly the intended address, domain, or IP and a meaningful reason.
- The message ID and time in Message History match the case; keep the administrator action itself recorded separately in the ticket.
- For M365 requests, the list reloaded from Microsoft shows the new state. If it remains unchanged, allow for synchronization instead of assuming that processing succeeded.
A missing row alone isn’t proof of success: the date range, filters, or retention expiry can produce the same effect.
Troubleshoot and escalate
- No result: check the tab, date range, and tenant; remove criteria one at a time and select Refresh. Compare envelope and header addresses. Missing direction in post-delivery is expected.
- Details missing: check the quarantine type. Full details aren’t available for internally forwarded post-delivery messages; for M365, the Microsoft connection may be unacknowledged or delayed.
- Release unavailable: check role, reason, policy, and quarantine type. Don’t elevate access or add an allow entry merely to bypass an unavailable action.
- Released message not received: check the rescan, Message History, recipient state, and possible requarantine. For M365, inspect the Microsoft request state.
- Message is quarantined again: compare Reason, direction, recipient assignment, and the effective Email Security policy. Correct the cause instead of repeatedly releasing or broadly allowing.
- Intelix remains risky or inconclusive: don’t release. Preserve the report, message ID, and affected attachment for Security Operations.
For escalation, collect tenant ID, timestamp with time zone, quarantine list, message ID, sender and recipient, Reason and Status, raw headers, policy name, attempted action, Intelix report, and screenshots without unnecessary personal data. For post-delivery, add clawback time and affected forwards; for M365, add connection and request status. Keep protection active and the message quarantined until the case is resolved.