Skip to main content
Removed attachments can be replaced with a text file.
Use SSQ insteadIn general, we recommend to enable the SSQ instead of attachment removal. It provides a safer environment and no attachments are lost.
Attachment removal can be activated in different ways:
  • Verdict based: Remove all attachments from emails classified as Malware or Filter/Policy.
  • File based: Remove attachments that match certain file criteria (e.g. extension)
  • Custom rule based: Remove attachments based on arbitrary custom rules - contact support@xorlab.com for this
After an attachment was replaced or removed, the original attachment is deleted and cannot be recovered anymore.
To enable attachment removal or replacement:
  1. Open the activeguard/core/rule_sets/90_local/params/local.properties file in Expert Editor and add:
    local.properties
  2. Specify the email direction on which attachment removal is activated:
    local.properties
  3. For verdict based attachment removal, use the following configuration:
    local.properties
  4. For file based attachment removal, use the following configuration:
    local.properties
    1. Attachment removal based on blacklists only works if the quarantine action for blacklist matches is disabled. If you need help adjusting this setting, contact support@xorlab.com.
  5. For every use case above, you can specify the text in the replacement file with the following properties:
    local.properties
  6. Click Publish. The rule-set configuration becomes active within about one minute.