The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Rescan quarantined email request

Prev Next

Rescans the emails present in the quarantine for the given Email Security — Cloud message IDs.

Rescan with password: Rescans emails from the past 7 days or older that contain password-protected attachments and quarantined under riskware rule ID 65066. You need to provide candidate passwords to enable Email Security — Cloud to decrypt and analyze the attachment during the rescan. You can submit multiple passwords per request.

Endpoint (same for both requests):

POST https://<APIURI>/quarantine/rescan

Required headers:

x-fireeye-api-key: <key>—Specifies your personal API key.

Content-Type: “application/json”— Content-type of the request body.

Request body for rescan:

{
  "message_ids":["MSG-ID1", "MSG-ID2"]
}  

Request body for rescan with a single password:

{
  "message_ids":["MSG-ID1", "MSG-ID2"],"encoded_passwords": "base64 encode(PWD)"
}  

Request body for rescan with multiple passwords:

{
  "message_ids":["MSG-ID1", "MSG-ID2"],"encoded_passwords": "base64 encode(PWD1\r\nPWD2\r\nPWD3)"
}  

Options

message_ids—(string) The message ID logged when an email is delivered from the Email Cloud stack.

encoded_passwords-(string) Passwords that can decrypt email attachments.

Note

The encoded_passwords parameter accepts only one string.

To send multiple passwords using the encoded password parameter, combine them into a single Base64-encoded string, rather than passing them as a list of individual encoded values.

The following steps define the process:

  • Combine passwords: Concatenate the individual passwords (e.g., test and pass) into a single string.

  • Use separator: Separate each password within the combined string using the newline sequence \r\n. For example, the combined string would be test\r\npass.

  • Encode entire string: Convert the entire resulting string to Base64 encoding.

  • Pass as single string: Submit the final Base64 string in the request body.

Example request for rescan

{
    "messsage_ids": [
                  "3yOTdNn-1125811-41000653324B5AC360d9dec77"
                  "3yOX7Fh-1125913-d1EEA7213302EFD9E360d9dec77"]
}'

Example request for rescan with password

{
    "messsage_ids": [
                  "3yOTdNn-1125811-41000653324B5AC360d9dec77"
                  "3yOX7Fh-1125913-d1EEA7213302EFD9E360d9dec77"],
    "encoded_passwords": [
                    "OFkyVlRZQWVBSDgyTA0KcGg0cWh2MUxLRGUNCjRrMm5NcWhEVVNNDQpPb0treTVhaW1aQzcNCkU
                     1YXVCa3loS0FZbjUyZjMNCllOMmpYRnFMcnlEd0hnNA0KWHN0S091a0R4DQp3THg4bERLcA0Kb0
                     0xN1Q4eklCelJEdWVtDQozTVpzWm5EVXB2Y1NoDQpuUzg2anVaTUcNCjhnVWpvV1hBMFpqZ1pNQX
                     QNCmNOeU5MRGd5R0dtQVlpVngNCnU2NnN1RkR1ZU55alJBdw0KTmNwbzN3Z0lQDQpaQXRxak8xalh6UXRiYQ==" ]
    
}'

Example response

Success:

{
    "data": {
        "type": "quarantine",
        "operation": "rescan",
        "successful_message_ids": [
                 "3yOTdNn-1125811-41000653324B5AC360d9dec77"
                 "3yOX7Fh-1125913-d1EEA7213302EFD9E360d9dec77"
        ] 
    },
    "meta": {
          "copyright": "Copyright 2023 FireEye Security Holdings US LLC"
    }
}    

Error:

{
    "data": {
        "type": "quarantine",
        "operation": "rescan",
        "successful_message_ids": [
            "3yOTdNn-1125811-41000653324B5AC360d9dec77"
        ],
        "failed_message_ids": [
            "3yOX7Fh-1125913-d1EEA7213302EFD9E360d9dec77"
        ] 
    },
    "meta": {
          "copyright": "Copyright 2023 FireEye Security Holdings US LLC"
    }
}   

cURL code example: rescan and rescan with password quarantined email

curl -XPOST -kL https://<APIURI>/quarantine/rescan -H 'Content-Type: application/json' -H 'x-fireeye-api-key: ' --data-raw
{
    "messsage_ids": [
                  "3yOTdNn-1125811-41000653324B5AC360d9dec77"
                  "3yOX7Fh-1125913-d1EEA7213302EFD9E360d9dec77"],
    "encoded_passwords": [
                    "OFkyVlRZQWVBSDgyTA0KcGg0cWh2MUxLRGUNCjRrMm5NcWhEVVNNDQpPb0treTVhaW1aQzcNCkU
                     1YXVCa3loS0FZbjUyZjMNCllOMmpYRnFMcnlEd0hnNA0KWHN0S091a0R4DQp3THg4bERLcA0Kb0
                     0xN1Q4eklCelJEdWVtDQozTVpzWm5EVXB2Y1NoDQpuUzg2anVaTUcNCjhnVWpvV1hBMFpqZ1pNQX
                     QNCmNOeU5MRGd5R0dtQVlpVngNCnU2NnN1RkR1ZU55alJBdw0KTmNwbzN3Z0lQDQpaQXRxak8xalh6UXRiYQ==" ]
    
}'

This cURL sample includes the following options:

  • -X POST —This option changes the HTTP method to POST.

  • -H 'x-fireeye-api-key: xxxxxxxxxxxxxxx'—This header specifies your personal API key.

  • -H "Content-Type: application/json"—This header specifies that the request body is sent to the server in JSON format.

  • https://etp.us.fireeye.com/v1/quarantine/rescan—The quarantine request URL. Replace etp.us.fireeye.com with the address of your Email Security — Cloud instance.

  • --data-raw—Specifies query parameters