The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure TIE settings to scan email attachments

Prev Next

Enable TIE reputation check for email attachments based on the file reputation category.

  1. From the product's interface, click Settings & Diagnostics → TIE Settings.

  2. Select one item from the Take actions at and below drop-down list.

    • Known Trusted — The reputation for the file is 99.

    • Most Likely Trusted — The reputation for the file is 85.

    • Might Be Trusted — The reputation for the file is 70.

    • Unknown — The reputation for the file is 50.

    • Might Be Malicious — The reputation for the file is 30.

      Note

      By default, Might Be Malicious is selected.

    • Most Likely Malicious — The reputation for the file is 15.

    • Known Malicious — The reputation for the file is 1.

  3. In Take the following action, define these settings as required.

    • Replace item with an alert — Replaces the item with an alert message and logs, quarantines, or notifies as defined in And also.

    • Delete embedded item — Deletes the attachment in the email and logs, quarantines, or notifies as defined in And also.

    • Delete the message — Deletes the email and logs, quarantines, or notifies as defined in And also.

  4. In And also, configure these settings as required.

    • Log

    • Quarantine

    • Forward Quarantined email

    • Notify administrator

    • Notify internal sender

    • Notify external sender

    • Notify internal recipient

    • Notify external recipient

  5. In Submit files to ATD at and below, select the category and the file size for Intelligent Sandbox reputation.