Skip to content
Avanet

Sophos Email Security: create and assign policies

An Email Security Policy protects selected mailboxes from spam, malware, phishing and other email threats. What’s important is not just which checks are enabled: the internal and external scope, order and enforcement status determine which messages a custom policy actually applies to.

Quick path: Add an Email Security policy under My Products > Email Security > Policies, give it a unique name, select internal users, groups or domains and, if required, limit the external scope. Check the settings and actions, save the policy, place it at the correct priority and set it to Policy is enforced. Finally, compare controlled messages to a recipient in scope and a control recipient outside it, and document the observable results in Message History.

Record the scope and return path before changing

You need a current list of protected mailboxes and domains as well as known business exceptions. Before making the first change, you record in a change or ticket:

  • Name, purpose and owner of the new policy;
  • internal users, groups and domains that should receive the policy;
  • external addresses or domains to include or exclude;
  • expected direction and intended actions;
  • current order, enforcement status and relevant settings of the affected policies;
  • acceptance criteria, test senders and test recipients;
  • rollback: set the new policy to Policy Bypassed and restore the previous order or settings.

Under Policies there are three families for different tasks. Email Security handles threats, Data Control controls sensitive information, and Secure Message encrypts messages. For the protection against spam, malware, phishing and sender manipulation described here, choose Email Security; a similarly named policy from another family does not replace it.

⚠️ An exception may never disable malware scanning. When a legitimate message is misclassified, first narrow down the affected check, scope, and sequence. A correction that is as narrow as possible is safer than a blanket exception for a sender or a domain.

In the EMS mode you can configure Email Security policies, but their actions are only evaluated for reporting and not applied to messages. The policies should still reflect the current mail environment so that the verdicts displayed are meaningful. A hit in EMS therefore does not constitute a block or quarantine.

This is how Sophos evaluates the policy scope

A custom policy can be assigned to internal users, groups, or domains. An entry in one of these internal lists is sufficient for the internal part of the scope. With External you can add individual external email addresses or entire domains, import them from a file and include or exclude them from the scope. The policy then applies to messages between the internal scope and the defined external scope, inbound or outbound, as long as the respective setting supports this direction.

Sophos evaluates the SMTP-Envelope addresses of the sender and recipient, not just the visible From and To headers. This is particularly important for redirects, aliases or different Return-Path addresses. In the event of an unexpected match, you first check the envelope sender and envelope recipient in the message details or raw headers.

Sophos treats plus addresses like accounts+test1234@example.com like email aliases. This plus addressing protection is only supported for incoming messages.

Handle distribution lists and Shared Mailboxes consciously

By default, custom policies do not apply to Distribution Lists (DLs), Shared Mailboxes and Public Folders. If you want a selected DL or shared mailbox to receive the custom policy, activate Apply custom policy to DL and shared mailbox. If the option is omitted, only the Base Policy applies, even if the object was selected in the custom policy. Public Folders remain outside this switching; you can’t just treat it like a shared mailbox.

The dependent account setting Treat a DL as a mailbox is available only when Apply custom policy to DL and shared mailbox is enabled. When selected, Sophos treats a chosen DL as one mailbox address: the custom policy applies only to the DL address, not to its members. To apply the policy to the DL as a group, clear Treat a DL as a mailbox. DLs still appear on the policy’s Groups tab. The setting does not affect DLs synchronised through AD Sync, which are always treated as groups.

Before activating, compare a representative personal mailbox, a DL and a shared mailbox. This makes it clear whether an apparent assignment problem is actually caused by this tenant-wide handling of user-defined policies.

Create and prioritise an Email Security policy

  1. Open My Products > Email Security > Policies.
  2. Click on Add Policy and select the family Email Security. To adapt an existing policy, open its entry instead.
  3. Give it a unique name, for example ES-Inbound-Finance-Strict. The name describes direction, target group and purpose; New Policy does not help later either in the order or in an incident.
  4. Add the intended users, groups or domains under Internal. When you hover over an internal username, Sophos displays the email address. This lets you verify the correct person before saving when names are identical.
  5. If the policy should only apply to certain communication partners, open External. Add addresses or domains manually or via file and consciously check whether the list is included or excluded.
  6. Check the required protection functions and their actions under Settings. In particular, document the desired direction, the actions for hits, SPF, DKIM and DMARC checks, and the order of sender checks. Most settings apply only to inbound messages. Exceptions include Enhanced content and file property scan, which can also apply inbound and outbound, S/MIME with selectable direction and the outbound disclaimer.
  7. If the New domain/sender check is used, document its configured action and test it with a controlled external domain or sender that is genuinely new to the tenant. Record tenant-level settings separately; they are not part of this recipient policy assignment and must not be inferred from it.
  8. Check the option Apply custom policy to DL and shared mailbox for DLs and Shared Mailboxes and compare the selection with the prepared target list.
  9. Make sure the policy is saved and set to Policy is enforced. If an option is locked, the global default comes from the partner or enterprise administrator; it is not bypassed locally.
  10. Arrange the policy according to the documented goal. Narrow exceptions and specific target groups belong above broader rules; the Base Policy provides the fallback. After each move, check whether another policy now takes effect first for the same scope.
  11. Click on Save and log name, scope, order and enforcement status.

If you change the scope, order and many actions at the same time, it is difficult to identify the cause of an unexpected result. In production tenants, you therefore work with a small pilot group, check the effect and only then expand the scope.

Clone a policy securely

Cloning is suitable if an existing configuration is to serve as a tested starting point for a similar target group:

  1. Open My Products > Email Security > Policies and select the source policy.
  2. Click on Clone.
  3. In Clone Policy, adjust the name and click on Continue.
  4. Once the Base Policy has been cloned, add users, groups or domains; A clone of the Base Policy initially does not contain such a scope.
  5. Click on Save and compare settings, actions, scope and direction with the change.
  6. The clone is initially set to Policy Bypassed. Only after checking do you arm it using Policy Bypassed > Policy is enforced.
  7. By default, a clone is given a higher priority than the original policy. Therefore, check and correct the order before the pilot begins.

The safe way back is therefore simple: If the original remains unchanged, if an unexpected effect occurs, set the clone back to Policy Bypassed and restore the previous order. You do not delete the clone until Message History and the change log are evaluated.

Check effect with Message History

For acceptance, use a dedicated recipient inside the new policy’s scope and a comparable control recipient outside it. Send the same controlled messages to both recipients, without changing any other policy or tenant setting during the test. Include at least:

  • a normal expectedly permissible message;
  • an authorised, harmless test message that specifically triggers a configured threat category or action;
  • a message with a known SPF, DKIM or DMARC test result;
  • with an external scope, one suitable and one unsuitable communication partner;
  • if required, one message each to a personal mailbox and a shared mailbox;
  • when a DL is in policy scope, separate messages to the DL address and at least one member recipient, demonstrating the intended mailbox or group scope.

In Message History search by time, envelope sender and envelope recipient. For every in-scope and control message, record the message ID, timestamp, envelope addresses, category or authentication result, and action. With EMS, expect only the reported result; with an enforced policy, also record the action that was carried out.

A category, authentication result, or action shows how Sophos processed that message; it does not identify or prove which policy was effective. Accept the assignment only when the documented scope, order and enforcement status, together with the recipient-specific comparison and its recorded observable results, match the test plan. A delivered or quarantined message on its own is not sufficient evidence.

Systematically limit errors

The new policy does not apply

Check Policy is enforced, internal scope, external include/exclude scope and order one after the other. For a DL or shared mailbox you also check Apply custom policy to DL and shared mailbox. A Base-Policy clone may be completely missing the assignment. In EMS, actions not performed are expected behavior.

The wrong policy or action takes effect

Compare the scopes of overlapping policies and their order. Then check the SMTP-Envelope addresses in the details instead of just From and To. Only when the policy match is correct do you examine the configured action and the sequence of SPF, DKIM, DMARC and other sender checks.

A legitimate message is blocked or quarantined

Record message ID, time, envelope addresses, category, action and sender check details. Analyze the raw headers for redirection, different envelope sender, and actual authentication results. First correct the order, scope or the specific false positive test. Don’t disable malware scanning or create a broad allow exception just to quickly deliver the individual message.

New senders behave unexpectedly

Check the action configured under New domain/sender and whether the test domain or sender was genuinely new to the tenant. Repeat the recipient-specific test with a controlled new external domain or sender and record the observable results in Message History. Review tenant-level settings separately rather than attributing their effect to the assigned policy.

If the cause remains open after these steps, leave the new policy at Policy Bypassed or restore the previous enforcement status and order. For escalation, you collect policy names, scope, sequence, message IDs, timestamps, raw headers and screenshots of the sender check details. This allows Sophos or the supporting partner to trace the matching and inspection path without making further risky exceptions in the tenant.