Mail Security is the filtering service that sits in front of the mail server. Open it from Tools, under Email.
It is a separate console from Mail Admin on purpose. In a real environment the filter and the mail server are different products, and working out which one holds the answer is part of the diagnosis.
Use it
- Pick a mailbox.
- Select Review.
You get two lists.
Quarantine
Messages the filter held back before they reached the mailbox. Empty state: No quarantined messages.
Release delivers a message to the mailbox.
This is the answer to a common shape of ticket: a message the sender swears they sent, that never arrived, and that Message Trace in Mail Admin cannot fully account for. If the filter caught it, it is here.
Blocked senders
Addresses and domains that are blocked from reaching the mailbox. Empty state: No blocked senders.
Remove takes a sender off the blocklist.
Worth checking when a user says they stopped receiving mail from one particular company, which is a very different problem from not receiving mail at all.
Undo
Both actions offer Undo straight afterwards, and confirm with Released or Removed.
Think before you release
Quarantine exists for a reason. A message being held is not automatically a mistake, and releasing a genuine phishing message into somebody’s inbox is a worse outcome than the user waiting. Read what was quarantined and who sent it before you release it.
If the message looks like a real attack rather than a false positive, that is a security ticket, not a mail ticket.