Set up and test the Sophos Firewall quarantine digest
The quarantine digest emails users a list of spam messages held by Sophos Firewall. It isn’t just another system notification: the delivery path, user assignment, release link, and user portal must all work together.
The most important acceptance criterion is therefore the complete user journey. A successful test email doesn’t confirm that a real user receives the digest, can sign in to the correct portal, and can release an eligible message.
⚠️ The release link doesn’t release a message directly. It opens the user portal, where the user must sign in and select the message. The portal address must therefore neither point to an internal-only name nor expose a management interface broadly without control.
Set up the quarantine digest in seven steps
- Configure mail delivery under Administration > Notification settings and verify it with a test email.
- Define the portal FQDN, DNS, certificate, and allowed source networks for the intended users.
- Turn on the digest under Email > Quarantine settings and set the delivery time, sender, and display name.
- Select the correct user portal address under Release link settings.
- Define the quarantine area and any address patterns that should deliberately be excluded.
- Assign the digest to the intended accounts under Authentication > Groups or Authentication > Users.
- Use a real quarantined spam test message to verify the digest, portal sign-in, and release end to end.
What the digest does and doesn’t do
The digest lists quarantined spam messages with their receipt time, sender, recipient, and subject. It provides a convenient user view, but it doesn’t replace the administrative quarantine under Email > SMTP quarantine or technical analysis of the policy, mail logs, and MTA logs.
Only users who have authenticated with the firewall at least once receive a quarantine digest. This is easy to miss when accounts have been imported from Active Directory but have never signed in to the user portal, captive portal, or another applicable service.
According to the current SFOS 22 help, the quarantine digest isn’t available on XGS 87 and XGS 87w. This model restriction applies to the digest and must not be confused with the separate MTA mode restriction. Set up Mail Protection in MTA mode explains the mail flow, SMTP policy, and administrative quarantine.
Prepare mail delivery and the portal address
Delivery uses Administration > Notification settings. The mail server, sender, recipient, DNS, route, authentication, and TLS must work there first. The complete transport test is described in Set up Sophos Firewall email notifications.
There are two options for the release link:
- Reference user portal IP: SFOS uses the address of the selected interface together with the user portal port.
- IP address or hostname: SFOS uses the address configured under Administration > Admin and user settings > Admin console and end-user interaction.
An FQDN is usually easier to understand and can be secured cleanly with a matching certificate. It must resolve to the correct firewall address and be reachable from the recipients’ networks. A private interface IP in the digest is normally unusable for external or mobile users. Conversely, a public address isn’t a reason to enable the user portal for every WAN network. Sophos Firewall portals overview explains portal purpose and Device Access separately.
Configure the digest
Turn on Enable quarantine digest under Email > Quarantine settings. Then set the required delivery frequency, time, and, where applicable, day of the week. From email address must contain a valid sender address; Display name should clearly identify the firewall quarantine to users.
Next, select the prepared portal address under Release link settings. Send test email verifies whether SFOS can send a digest email through the configured mail path. However, the test doesn’t contain a real quarantined user message and proves neither subsequent user assignment nor portal sign-in or release.
Quarantine area and automatic cleanup
In MTA mode, select the size of the local quarantine area under Quarantine area. SFOS checks usage every five minutes. When it reaches at least 90 percent of the selected size, older messages are deleted until usage falls to 60 percent.
This automatic cleanup isn’t an archive. An area that’s too small can shorten the time available for review and release; a large area consumes local storage. Monitor its usage and free space together with the remaining /var consumption. Check Sophos Firewall storage and reports describes the safe diagnostic path.
Understand Skip address patterns
Addresses under Skip address patterns are excluded from quarantine reports. This can be useful for shared aliases whose spam shouldn’t be distributed to many users. The setting doesn’t delete messages and isn’t an exception from spam, malware, or data protection checks.
Assign users and groups
The global digest configuration alone doesn’t enable delivery for every user. Set Quarantine digest to Enable for the intended accounts under Authentication > Groups or Authentication > Users. Alternatively, assign it directly under Email > Quarantine settings > Change user’s quarantine digest settings.
There are two important limitations for alias addresses. By default, SFOS doesn’t automatically apply digest settings to aliases; they must be stored with the user’s primary email address or assigned deliberately. The digest can then list spam for primary and alias addresses. However, Sophos states that quarantined messages sent to aliases don’t appear in the user portal. These addresses therefore need a clear administrative release process under Email > SMTP quarantine.
Control user sender exceptions
Under Exception in the user portal, an authorized user can allow or block individual sender addresses or wildcards such as *@example.com. Allowed senders aren’t marked as spam or moved to spam quarantine, but antivirus scanning remains active. If the same address appears in both lists, the block list takes precedence and the message is quarantined. Include these user-specific exceptions in pilot and support tests, and don’t confuse them with the digest’s global Skip address patterns.
Test the complete release path
Use a pilot user who has already authenticated with the firewall at least once. A controlled message must be quarantined as spam by the expected SMTP policy. Then verify the following states:
- The message appears under Email > SMTP quarantine with the expected recipient, subject, and reason.
- The pilot user receives the digest at the configured time.
- Sender, display name, subject, and metadata meet the privacy and operating requirements.
- The release link opens the intended user portal FQDN with a valid certificate chain.
- Sign-in succeeds from an allowed network and fails from a network that isn’t intended.
- The eligible test message can be released after sign-in and is actually delivered.
- A user without digest assignment receives no report.
Virus-infected messages and emails that Zero-day protection identifies as malicious can’t be released. This negative test prevents a successful spam release from being misunderstood as a general release option.
Troubleshoot systematically
The test email doesn’t arrive
Check Administration > Notification settings first. Send test email fails before the actual quarantine function when DNS, route, mail server, authentication, TLS, sender, or recipient is incorrect. Don’t change user assignments or quarantine size while the mail transport itself is failing.
The test email arrives, but no user digest does
Check that Enable quarantine digest is on, the schedule and time zone are correct, and the affected account is enabled under Groups, Users, or Change user’s quarantine digest settings. The user must have authenticated with the firewall at least once. There must also be a matching quarantined spam message for this recipient in the selected period.
The release link points to the wrong address
Compare Release link settings, the selected interface, the user portal port, and Admin console and end-user interaction. Then test DNS resolution, certificate name, and reachability from the real user network. Repeatedly sending the test email won’t correct the address; fix the underlying portal reference first.
Alias messages are missing from the portal
This isn’t automatically a digest failure. Sophos explicitly documents that quarantined messages sent to aliases don’t appear in the user portal. Check the primary address, alias assignment, digest contents, and administrative SMTP quarantine separately.
Operations and rollback
Digest emails contain communication metadata and may persist outside the firewall in mailboxes, archives, or tickets. Keep the recipient group small, align mailbox retention with the protection requirement, and include shared aliases in reports only deliberately.
For rollback, first turn off Enable quarantine digest or remove the assignment from the pilot users. Then generate a new quarantined message and verify that no further digest is delivered. Roll back portal or notification settings only if no other service uses them. The quarantine remains independent of the digest and isn’t deleted as part of the rollback.