Hey all.
As an admin for our GWFE, I occasionally get notifications of email that ends up in our quarantine.
Today I got one that I wanted to look a bit closer at - so I head to the Quarantine area in our Dashboard.
I'm looking at the email in question and it looks fairly legit. I do also see that it has a PFD attached.
What I don't see is a real explanation as to WHY is was quarantined.
The only rule/quarantine we have setup is the default one. When I click to "edit" that quarantine, there's really not much there other than settings to send a reject message or not.
Looking at the email from the quarantine, under the "matched rules" heading it simply says "Rule description" - which I assume is because the description is blank for the default quarantine.
So I assume my answer lies somewhere else.
Where do I see WHY a message was sent to quarantine? Surely if the sender/attachment or some other item was suspicious/infected there'd be a more clear indication of that, correct?
My only options are to allow or reject it - but I don't feel like I want to take action on it without further details about WHY it was quarantined in the first place.