The Attachment restrictions page allows you to configure which email attachments to allow and which to block.
In the Domain Level Control Panel, select Incoming - Protection Settings > Attachment restrictions the Attachment restrictions page is displayed:
The following restrictions can be configured:
Restriction | Description |
---|---|
Blocked Extensions |
Messages that have an attachment with any of the selected extensions will be rejected. You can add new extensions to those listed using the Add new extension feature. |
Disallowed release extensions |
Email users will not be allowed to release messages that contain attachments with the selected extensions. You can add extensions to this list using the Add new extension feature. |
Restriction options |
|
Additional restrictions |
Message link size limit (in bytes) - This option restricts the amount of data that is downloaded per message. Links in messages to executable files that would be blocked as attachments are followed and the content is checked against an anti-virus database. Maximum MIME defects - Messages that are sent with standard email clients have no defects, whereas spam messages are often generated with poorly developed software and have many defects. Normally we reject messages with defects but if you have a need to receive defective messages, you may set a limit or disable this check. If the defective messages come from a single sender, it would generally be better to either convince the sender to fix their software or allow that sender using Manage Incoming Sender Allow list. |
Scanned link extensions |
If the Message link size limit is set (above), then links in messages to files with the selected extensions will be scanned for viruses and other malware. You can add extensions to this list using the Add new extension feature. |
Default (inherited) Blocked Extensions | Default (inherited) Scanned Link Extensions |
---|---|
.ade |
.bat |
.adp | .btm |
.bat | .cmd |
.btm | .cpl |
.chm |
.dll |
.cmd | .exe |
.com | .lnk |
.cpl | .msi |
.dll | .pif |
.docm | .prf |
.exe | .reg |
.hta | .scr |
.ins | .url |
.isp | .vbs |
.jar | |
.js | |
.jse | |
.lib | |
.lnk | |
.mde | |
.msc | |
.msi | |
.msp | |
.mst | |
.nsh | |
.pif | |
.prf | |
.reg | |
.scr | |
.sct | |
.shb | |
.url | |
.vb | |
.vbe | |
.vbs | |
.vxd | |
.wsc | |
.wsf | |
.wsh |
You can also block messages based on their attachment type. You can add more attachment types to the list of default ones already set up in the system.
Spammers often use the trick of sending password encrypted archives in the hope to bypass some filters, and saying the “password” in the body of the spam message. These messages can be blocked by enabling the “Block Password Protected Attachments” feature.
To block dangerous attachments for a specific domain only:
This option (which is disabled by default) allows you to reject all incoming emails received with document based attachments (.doc, .xls, .ppt etc) containing macros. This can be enabled per domain by:
This option (which is disabled by default) allows you to configure your domain(s) to allow the download of files of a specific extension type from links within an email. The system scans the files for any viruses or malware.