The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring riskware email blocking

Prev Next

You can enable or disable blocking emails based on riskware detected by Trellix Riskware rules by using the Email Security - Server appliance Web UI or CLI:

When you enable riskware detection both to generate a riskware alert and to block an email, the Email Security - Server appliance blocks emails that might be suspicious. In this scenario, a malware object event notification is generated if the sample is detected as riskware. You can view the analysis results on the eAlerts > Alerts page in the Web UI.

Note

Blocking emails based on the riskware detection feature is disabled by default.

Prerequisites

  • Administrator or Operator access to the Email Security - Server appliance

  • An established connection to the Internet

  • A connection to the DTI Cloud

  • Download and install the latest security content with new riskware policy rules by using the fenet security-content apply-update command, For details about how to update security content, refer to the System Administration Guide.