In this article, you will learn everything you need to know about the Email Security module. The Email Security engines scan for the most intrusive method cybercriminals use to introduce malware and viruses into corporate systems. Lightweight, easy to deploy, and highly responsive, our Email Security anti-malware and anti-spam filter can be scaled to any number of endpoints within your organization. Its MX record-based analysis vectors keep all malicious emails out of your inbox, automatically removing malware-laced attachments, and filtering emails coming from malicious IPs or domains, or those containing malicious URLs.
1. Description
2. How does Email Security work?
3. Email Security setup guide
4. Email Security view
5. Email Security personal/individual console
6. Email Security settings
DESCRIPTION
Our Email Security uses market-leading spam detection and filtering engines that go beyond simple spam definitions. It proactively prevents even the most sophisticated email exploits that seek to harm your organization by bypassing regular spam filters and antivirus solutions. The Email Security features include anti-spam protection, botnet protection, Advanced Malware Filtering, Protection against DNS hijacking, Phishing protection, threat tracing & full audit log, social security number leakage detection (DK), personal quarantine report, 90-day email retention, deep attachment scanner, and deep content inspection.
The Email Security infrastructure is hosted on Microsoft's Azure cloud platform (West Europe - Amsterdam, North Europe - Ireland, South India, East US - Virginia). As a security provider, HEIMDAL understands the importance of complying with security standards, and that is why Email Security comes with DNSSEC and DANE/TLSA support for inbound SMTP services:
HOW DOES EMAIL SECURITY WORK?
Email Security protects both inbound and outbound mail flows by acting like the man-in-the-middle, between the Internet and your organization's email server (in case of the Inbound Mail Flow) or vice-versa (in case of the Outbound Mail Flow). Below you have the diagram of the Email Security module:
On the Inbound flow, emails that come from the Internet reach the organization's domain (example.com) and are forwarded to the HEIMDAL Security MX Records found on the domain's DNS (example: eu-esec-01.heimdalsecurity.com or eu-esec-02.heimdalsecurity.com for the Europe region). Once they reach the HEIMDAL servers, Email Security goes through the following flow:
- Allowlist & Blocklist (Allowlist has priority over everything. Anything in the Allowlist is skipped from the Blocklist check);
- Greylist check
- IP Reputation check (only if Spam scanning is enabled)
- SPF/DMARC scanning
- Non-TLS check
- Virus scanning
- EFP check
- Spam scanning
- Attachment scanning
- Newsletter scanning
- Advanced Threat Protection
If emails pass these checks, they are delivered to the organization's inbound Mail Server (configured in the HEIMDAL Dashboard - Network settings) to reach the recipient's inbox, but if the emails fail the checks, they can be tagged, quarantined, or rejected (depending on the settings configured in the HEIMDAL Dashboard - Network settings) before reaching the recipient's inbox. In the case of quarantined emails, the HEIMDAL Dashboard Admin can allow users to release the quarantined emails they have received, or they can release them themselves.
IMPORTANT
In the interest of timely email delivery, emails that include an attachment with a size above 0.7 MB will be scanned by only one of our Antispam engines. The rest of the emails are scanned by both our Antispam engines.
On the Outbound flow, emails are sent from the organization's Outbound server using a forwarding rule/connector to reach the HEIMDAL Security smarthost (eu-esec-outbound.heimdalsecurity.com), where the Email Security engines perform the following operation:
- Spam scanning
- Virus scanning
- Attachment scanning
- Advanced Threat Protection
If emails pass these checks, they are delivered by the Email Security servers to the recipients, but if the emails fail the checks, they will be rejected or undelivered.
EMAIL SECURITY setup guide
To set up Email Security without disrupting the email flow in your organization, you need to follow the steps below for each of the flows you are configuring.
A. MX RECORD SETUP
Setting up the Inbound Mail Flow
A. Adding your domain to the HEIMDAL Dashboard
1. Log in to the HEIMDAL Dashboard and navigate to the Network Settings.
2. Click the Email Protection tab and make sure the Email Security module is enabled.
3. To add a new domain to be filtered by the Email Security engines, click Add Domain.
4. Insert your Domain Name and your Inbound Mail Server (Domain or Public IP Address), and Save Changes.
5. Additionally, you can configure the rest of the settings or leave them for a later time.
6. After having all the settings configured, press the Update Network Settings button.
B. Adding the Email Security MX Records to your domain's DNS Settings
1. Log in to the portal where you manage your domain's DNS Settings (your registrar's portal or your hosting company's portal | example: GoDaddy, HostGator, or others) and go to the DNS Settings. In case your domain's DNS hosting provider is Microsoft, note the fact that Microsoft 365 prefers Exchange Online Protection as the primary Mail Server service, and that is why you will see that on the MX Records configuration, Microsoft expects the Office 365 MX Record (example-com.mail.protection.outlook.com) and does not validate the MX Records of a 3rd-party spam filter as primary MX Records. Although the Email Security doesn't validate, the email flow will work just fine, having them set with priority 0 and 1.
2. Change your MX Records to point to the Email Security MX Records (make sure you use the MX Records corresponding to the region your customer account is stored):
- au-esec-01.heimdalsecurity.com (for customers stored in the Australian region).
- au-esec-02.heimdalsecurity.com (for customers stored in the Australian region).
- eu-esec-01.heimdalsecurity.com (for customers stored in the Europe region).
- eu-esec-02.heimdalsecurity.com (for customers stored in the Europe region).
- us-esec-01.heimdalsecurity.com (for customers stored in the United States region).
- us-esec-02.heimdalsecurity.com (for customers stored in the United States region).
- uk-esec-01.heimdalsecurity.com (for customers stored in the United Kingdom region).
- uk-esec-02.heimdalsecurity.com (for customers stored in the United Kingdom region).
- uae-esec-01.heimdalsecurity.com (for customers stored in the United Arab Emirates region).
- uae-esec-02.heimdalsecurity.com (for customers stored in the United Arab Emirates region).
Once the configuration of the MX Records has been completed and the settings propagated, emails should be displayed and filtered by the Email Security module in the HEIMDAL Dashboard, under the Email Security view (Inbound view).
IMPORTANT
In case you are setting up Email Security to work with Office 365, make sure you go through the steps described in this article to prevent the bypass of Email Security and also to configure the bypass of the EOP spam filtering: https://support.heimdalsecurity.com/hc/en-us/articles/22421112073501-Email-Security-and-Exchange-Online-Office-365-setup-of-the-inbound-flow
Setting up the Outbound Mail Flow
A. Adding your Outbound Mail Server(s) in the HEIMDAL Dashboard
1. Log in to the HEIMDAL Dashboard and navigate to the Network Settings.
2. Click the Email Protection tab and make sure the Email Security module is enabled.
3. Click the Edit button (the pencil icon) to edit the domain you have created.
4. Add your Outbound Mail Server (Domain or Public IP Address) by clicking the Add button, and Save Changes.
5. After having all the settings configured, press the Update Network Settings button.
B. Adding the Email Security SPF, DMARC, DKIM records to your domain's DNS Settings
1. Log in to the portal where you manage your domain's DNS Settings (your registrar's portal or your hosting company's portal | example: GoDaddy, HostGator, Office 365, or others) and go to the DNS Settings.
2. Edit your SPF Records to include the Email Security SPF Records:
- include:spf-esec.heimdalsecurity.com (for customers stored in the Europe region).
- include:spf-esec-au.heimdalsecurity.com (for customers stored in the Australian region).
- include:spf-esec-us.heimdalsecurity.com (for customers stored in the United States region).
- include:spf-esec-uk.heimdalsecurity.com (for customers stored in the United Kingdom region).
-
include:spf-esec-uae.heimdalsecurity.com (for customers stored in the United Arab Emirates region).
Example:v=spf1 include:spf.protection.outlook.com include:spf-esec.heimdalsecurity.com -all
Make sure you don't remove any 3rd Party SPF Records that are already set up on your SPF Records. After adding the Email Security SPF Records, do an SPF Record Lookup to make sure the SPF Records are validating correctly (you can use mxtoolbox.com or any other online tool to check).
3. Add a DMARC Record:
- Type: TXT
- Host: _dmarc
- Value: v=DMARC1; p=quarantine; rua=mailto:gcafy1yi@ag.dmarcian-eu.com, mailto:test1@example.com; ruf=mailto:gcafy1yi@fr.dmarcian-eu.com, mailto:test1@example.com;
- TTL: 1/2 Hour
4. Additionally, you can add a DKIM Signature to make sure the emails you send are DKIM-signed.
C. Adding a rule/connector on your Mail Server to relay emails to the Email Security smarthost
1. Go to your Outbound Mail Server settings and create a rule/connector to relay all the outbound emails through the Email Security smarthost:
- au-esec-outbound.heimdalsecurity.com with ports 25, 587, 2525 (for customers stored in the Australian region).
- eu-esec-outbound.heimdalsecurity.com with ports 25, 587, 2525 (for customers stored in the Europe region).
- us-esec-outbound.heimdalsecurity.com with ports 25, 587, 2525 (for customers stored in the United States region).
- uk-esec-outbound.heimdalsecurity.com with ports 25, 587, 2525 (for customers stored in the United Kingdom region).
- uae-esec-outbound.heimdalsecurity.com with ports 25, 587, 2525 (for customers stored in the United Arab Emirates region).
Once the configuration of the smarthost has been completed, emails should be displayed and filtered by the Email Security module in the HEIMDAL Dashboard, under the Email Security view (Outbound view).
B. M365 EXCHANGE CONNECTOR SETUP
The M365 Exchange Connector setup requires the following conditions:
- Azure/Entra tenant ID for the Entra ID enterprise app.
- Your domain's MX records must point to the Office 365 MX records.
- Your SPF records must be configured in the domain's DNS settings.
To be able to configure connectors and mail transport rules in Exchange Online Protection, HEIMDAL creates an Entra ID enterprise app in Entra ID to handle everything through the Microsoft Graph. To set it up, follow the steps below:
1. In the HEIMDAL Dashboard, go to Guide -> Customer settings -> Login Setup -> Azure Login and insert your Azure/Entra tenant ID.
2. After setting your Azure/Entra tenant ID, navigate to the Network Settings -> Email Protection, enable Email Security (if not already enabled), and press the Grant consent link.
3. You will be prompted to insert your M365 credentials (make sure you use a Global Administrator user account).
4. Press the Accept button to grant permissions to the Entra ID enterprise app:
5. After accepting permissions, a new enterprise app (called Heimdal Security ESEC All) will be created in Entra ID.
Now, adding a new domain is pretty simple with the following steps:
1. In the Email Protection tab, click the Add Domain button.
2. Type in your domain's name, select M365 Exchange Connector setup, insert your Inbound Mail Server (provided by Microsoft 365) and your Outbound IP/Provider (select the Office365 option from the dropdown), and press Save changes.
A validation operation takes place, and if all conditions are met, the Exchange Online connectors and rules are created. The following 3 connectors will be automatically created to handle the flow:
The following 4 rules will handle the routing of the email flows.
IMPORTANT
In order for Email Security to work, you need to make sure that the Email Security IP Addresses are not blocklisted/greylisted by your environment or by your hosting company. Verify your firewall settings and allow SMTP from these IP Addresses.
- 20.213.125.208 (au-esec-01.heimdalsecurity.com / au-esec-02.heimdalsecurity.com)
- 20.213.125.209 (au-esec-01.heimdalsecurity.com / au-esec-02.heimdalsecurity.com)
- 20.213.125.210 (au-esec-outbound.heimdalsecurity.com)
- 20.213.125.211 (au-esec-outbound.heimdalsecurity.com)
- 20.50.183.144 (eu-esec-01.heimdalsecurity.com)
- 20.50.183.146 (eu-esec-01.heimdalsecurity.com)
- 20.50.183.145 (eu-esec-02.heimdalsecurity.com)
- 20.50.183.147 (eu-esec-02.heimdalsecurity.com)
- 20.50.183.148 (eu-esec-outbound.heimdalsecurity.com)
- 20.50.183.149 (eu-esec-outbound.heimdalsecurity.com)
- 20.50.183.150 (eu-esec-backup.heimdalsecurity.com)
- 20.50.183.151 (eu-esec-backup.heimdalsecurity.com)
- 20.88.177.217 (us-esec-01.heimdalsecurity.com / us-esec-02.heimdalsecurity.com)
- 20.88.177.218 (us-esec-01.heimdalsecurity.com / us-esec-02.heimdalsecurity.com)
- 20.88.177.208 (us-esec-outbound.heimdalsecurity.com)
- 20.88.177.209 (us-esec-outbound.heimdalsecurity.com)
- 172.166.114.48 (uk-esec-01.heimdalsecurity.com / uk-esec-02.heimdalsecurity.com)
- 172.166.114.49 (uk-esec-01.heimdalsecurity.com / uk-esec-02.heimdalsecurity.com)
- 172.166.114.50 (uk-esec-outbound.heimdalsecurity.com)
- 172.166.114.51 (uk-esec-outbound.heimdalsecurity.com)
- 20.233.55.176 (uae-esec-01.heimdalsecurity.com / uae-esec-02.heimdalsecurity.com)
- 20.233.55.177 (uae-esec-01.heimdalsecurity.com / uae-esec-02.heimdalsecurity.com)
- 20.233.55.178 (uae-esec-outbound.heimdalsecurity.com)
- 20.233.55.179 (uae-esec-outbound.heimdalsecurity.com)
In case your firewall includes special rules for inbound & outbound traffic, make sure you whitelist the following:
- 20.213.125.208, 20.213.125.209, 20.213.125.210, 20.213.125.211
- 20.50.183.133/29 (port 25 for Inbound traffic)
- 20.88.177.217, 20.88.177.218, 172.166.114.48, 172.166.114.49
- 20.50.183.144/29 (all ports for Outbound traffic)
- 20.88.177.208, 20.88.177.209,172.166.114.50,172.166.114.51
- 20.233.55.176, 20.233.55.177, 20.233.55.178, 20.233.55.179
- 172.166.114.48, 172.166.114.49, 172.166.114.50, 172.166.114.51
EMAIL SECURITY view
The Email Security page displays 2 views: the Homepage (which showcases relevant data from the Email Security product) and the Details (for in-depth data analysis).
Homepage
The Homepage displays several stats and graphs that provide a streamlined understanding of the usage and activity of the email addresses and domains:
- Summary Report - brief info about the total number of malicious, inbound, and outbound emails over the last 90 days. These are further broken down by Status and expressed in percentiles.
- User Anomalies - shows, sorted in descending order, the top 8 email addresses on which outliers have been detected (SPAM, Virus, and ATP); each entry (email address) will have 3 bars, displaying the number of emails from this category, over the last month, 2, and 3 months ago (from the current date). For more details regarding a certain email address, the dashboard user can click on the bar chart section, and a detailed linear graph is displayed below.
- Domain status - lists all the email domains, with their corresponding TAC risk score and their MX, SPF, and DMARC authentication methods’ statuses.
-
The bottom row tiles display a month-to-month comparison of Quarantined, Rejected, Spam, Virus, and ATP emails. The stats are computed by comparing the past 30 days from the current date vs. the previous 30 days. Each tile displays the increase/decrease in the number of emails (both as a number and as a percentage) and a chart presenting the activity for each interval.
After clicking on the hovered point in the chart tile, the timeframe interval of the redirected Details page is automatically set to one of the hovered data points.
Moreover, this action also sets, in the Advanced filter, the Type or Status field to whatever Type or Status from the graph style from which the selected data point was clicked. Depending on the graph tile clicked, the following actions occur: clicking on the Rejected and Quarantined tiles automatically sets the Status of the Advanced filter, while clicking on the Spam, Virus, and ATP graph tiles automatically sets the Type field from the Advanced filter.If there is no recorded data when hovering over the chart data points and attempting to click on them, a toast notification will be shown to the dashboard user with the message "No data for the specific timeframe."
Details
The Details view displays all the information regarding the Inbound Mail Flow, Outbound Mail Flow, Domain Status, and M365 Users in your organization.
On the top, you see a statistic regarding the number of Scanned Emails, the number of Spam Emails, the number of Virus detections, and the number of detected Advanced Threats.
Inbound/Outbound
The Inbound view and Outbound view display all the emails that are being filtered by the Email Security engines:
The Advanced Filter allows you to filter your searches by Domain, To, From, Header From, Type, Status, Spam Classification, Minimum Spam Score, Maximum Spam Score, EFP Rule Category, AI Outlier and Delete Type.
The Type submenu has the following types:
- All
- Normal
- Botnet
- Spam
- Virus
- Encrypted
- ATP
- SPF Block
- DMARC
- Blocklisted
- Allowed
- Attachment Block
- Released to ATP
- Non-TLS block
- Newsletter
- EFP
The EFP Rule category submenu has the following categories:
- Targeted Spear Phishing
- Targeted Fraud
- Spear Phishing
- Phraseology attempt or General Fraud
- Modified or Malicious attachment
The AI Outlier category has the following categories: AI outlier detected, AI outlier not detected.
The Delete Type category has the following categories:
- All – displays all emails, regardless of deletion action
- Inbox Delete – shows emails removed from user inboxes
- Permanent Delete – displays emails permanently removed from mailboxes
In the Inbound view, you can see a list of all inbound emails, the recipient, the sender, the timestamp, the email subject, the type, the email status, and the details of each email (the Inbound view refreshes in real-time). Selecting one or more emails pops up a dropdown menu where you can select one of the following actions:
- Release - this action will release the selected email in case it has been quarantined and you think it is safe.
- Resend - this action will resend the selected email (this action works only for delivered emails).
- Report - this action will automatically mark the selected email as Spam, and an email notification will be sent to the Heimdal Security Team.
- Deny email release - this action will block the regular end users' ability to release quarantined emails from their QER report.
- Delete from Inbox – moves the email to Deleted Items and email remains preserved in cold storage (Grant Consent should be given for this action to be visible).
- Permanently Delete from Inbox – completely removes the email from Inbox, but preserves it in the cold storage (Grant Consent should be given for this action to be visible).
- Delete from ESEC / Delete from EFP repository – deletes the email from the ESEC/ EFP grid/ repository. The email is not deleted from the user's mailbox (Grant Consent should be given for this action to be visible).
In the Outbound view, you can see a list of all outbound emails, the recipient, the sender, the timestamp, the email subject, the type, the email status, and the details of each email (the Outbound view refreshes in real-time). Selecting one or more emails pops up a dropdown menu where you can select one of the following actions:
- Release - this action will release the selected email in case it has been quarantined and you think it is safe.
- Resend - this action will resend the selected email (this action works only for delivered emails).
- Report - this action will automatically mark the selected email as Spam, and an email notification will be sent to the Heimdal Security Team.
The Details button will display a pop-up with various email details (Main, Advanced, Header, Body and Audit Logs). In the Main tab, you can use the Choose a domain dropdown field to take actions for the specified domains.
- Add Sender to Blocklist - adds the sender (the one who sends the email) to the blocklist of the selected domain(s).
- Add Sender to Allowlist - adds the sender (the one who sends the email) to the allowlist of the selected domain(s).
- Add Domain to Blocklist - adds the sender's domain (the one who sends the email) to the blocklist of the selected domain(s).
- Add Domain to Allowlist - adds the sender's domain (the one who sends the email) to the allowlist of the selected domain(s).
- Add Email based on subject to Allowlist - adds the sender's email to the allowlist of the selected subject(s). Unchecking the SPF/DMARC scanning will still perform an SPF/DMARC check to increase security.
- Add Email based on subject to Blocklist- adds the sender's email to the blocklist of the selected subject(s).
Dashboard users have the option to create Allowlist/Blocklist rules either at a personal or global (domain) level.
If the dashboard user selects the “Personal” option, a new End User Console rule will be created (and also displayed in the End Users Allowlist & Blocklist table, which can be found in the Blocklist, Allowlist & Greylist section in Network Settings - Email Protection).
In the Advanced Status tab, you can use the Choose a domain dropdown field to take more actions for the specified domains.
- Add Source IP to Blocklist - adds the Source IP Address (the source IP Address of the sending server) to the blocklist of the selected domain.
- Add Destination IP to Blocklist - adds the Destination IP Address (the destination IP Address where the email is sent to) to the blocklist of the selected domain.
- Add Source IP to Allowlist - adds the Source IP Address (the source IP Address of the sending server) to the allowlist of the selected domain.
- Add Destination IP to Allowlist - adds the Destination IP Address (the destination IP Address where the email is sent to) to the allowlist of the selected domain.
In the Header tab, you see information about the Envelope-From the Header-From:
The Body and the Attachments tabs preview the body and the files that are attached to the email, whether the email has been quarantined, delivered, undelivered, or rejected. These options are available only if the domain has enabled the Email Archiving options feature in the Additional Domain Settings tab. In the Body tab, you can also download the email in EML format. To preview the Body and the Attachments tab, the HEIMDAL Dashboard user needs appropriate Access Control (View Email Security Data and View Email Security Sensitive claims enabled).
IMPORTANT
The email's body and attachments must not exceed 25 MB. If the total size exceeds this limit, the Body tab section will be disabled and appear grayed out. Just the size of the body should not exceed 1 MB. If that happens, the Body tab will be grayed out.
The Audit Logs tab records:
- the user who initiated the delete action (visible only for Inbound emails)
- the delete type performed (Inbox Delete or Permanent Delete, visible only for Inbound emails)
- the exact timestamp of the action execution (visible only for Inbound emails)
- released by
- initial status
- initial responses from server
Domain Status
The Domain Status view displays all the domains registered in the HEIMDAL Dashboard (under Email Security) with their validation status (including SPF and DMARC checks).
M365 Users View
The M365 Users View delivers clear visibility into Microsoft 365 users, enabling accurate automated license tracking and billing. This helps organizations align Heimdal license consumption with actual mail-enabled M365 user activity in the configured Microsoft Entra (Azure AD) tenant.
The M365 Users view is available only when both of the following conditions are met:
- A valid Microsoft Entra Tenant ID is configured.
- Grant Consent Billing has been successfully provided under Network Settings -> Email Protection -> Email Security -> Grant Consent Billing.
Note: if the aforementioned conditions are not met, the view remains disabled, and a tooltip text is displayed on hover to inform the user of the missing requirements.
The M365 Users view presents a searchable and sortable grid containing the following columns:
- M365 User – displays the Microsoft 365 user identity (userprincipalname or UPN).
- Last Seen – indicates the timestamp of the user's most recent sign-in activity.
Note: only users who meet both of the following criteria are included in the grid:
- are Members in the Microsoft 365 organization.
- have an active Exchange Online service plan.
Data in the M365 Users view is automatically refreshed every week.
EMAIL SECURITY personal/individual console
The Email Security personal/individual console is available to end users if the End user console option (within the Network Settings -> Email Security -> Quarantine Settings) is enabled. This portal is accessible through the following URL: https://dashboard.heimdalsecurity.com/emailspamfilterlogs/index, through an authentication token (valid for 24 hours from the moment it was generated) that is being sent via email (if the email address is valid).
The Email Security personal/individual console can be accessed from the Quarantine Report link at the bottom of the report.
Once authenticated in the Email Security personal/individual console, the end user can see all the details related to the email flows concerning their email address: the Inbound Mail Flow, the Outbound Mail Flow, the Blocklist, and the Allowlist. The collected information refers to emails that are DELIVERED, QUARANTINED, QUEUED, UNDELIVERED, or REJECTED.
On top of that, you will see statistics regarding the number of scanned emails, spam emails, virus detections, and advanced threats.
The Inbound view and Outbound view display all the emails that are being filtered by the Email Security engines, while the Blocklist and the Allowlist display the entries specific to each list. The Advanced Filter allows you to filter your searches by From/To, Header From, Type, Status, Spam Classification, Minimum Spam Score, and Maximum Spam Score.
Quarantined emails can be released from the Email Security personal/individual console by selecting the email and choosing the Release action from the top dropdown menu or the Details modal.
IT admins can block the end users' ability to release quarantined emails using the Deny email release action.
The emails that have been denied will have a warning icon in the Status field, and hovering the mouse over the status will display the message "Email is denied for release for end users. IT admins can still release the email from the dashboard".
After applying this action to an email, the Release button will be disabled for the end users, and placing the mouse over the button will display the message: "This action is not allowed by your IT admin."The Details modal allows the end user to add items to the Allowlist and/or Blocklist. The blocklisted items are added with the default action from the HEIMDAL Dashboard -> Reject, and the end user cannot select a different action (due to security reasons). Once the items are added to the end user's Allowlist/Blocklist, they are displayed in the corresponding view (Allowlist/Blocklist).
Add Sender to Blocklist - add the sender's email address (FROM) to the Blocklist.
Add Sender to Allowlist - add the sender's email address (FROM) to the Allowlist.
Add Domain to Blocklist - add the sender's domain to the Blocklist.
Add Domain to Allowlist - add the sender's domain to the Allowlist.
Add Header Sender to Allowlist - add the sender's HEADER FROM email address to the Allowlist,
Add Header Domain to Allowlist - add the sender's HEADER FROM email address to the Allowlist.
Add Email based on subject to Blocklist - add the subject to the Blocklist.
Add Email based on subject to Allowlist - add the subject to the Allowlist.
Release - releases the quarantined email.
When using the Show details button from the Email Security Inbound and Outbound views, users will be able to visualize details related to EFP-detected emails in a dedicated new tab called EFP.Note: The EFP tab is available (not faded) only if the Advanced Filter selection on Type is made for EFP-type emails.
The only action the end user can perform in the Allowlist/Blocklist views is the Delete action (deleting the entry/ entries from the table).
IMPORTANT
1. The settings are applied only to the mailbox of the end user and have priority over the general domain settings set up in the HEIMDAL Dashboard.
Example: if test@domain.com is blocklisted in the domain settings, but added to the end user’s personal Allowlist (in the Email Security personal/individual console), the end user will receive emails from the mentioned whitelisted email address while, all the other users will not (unless they performed whitelist actions, on the same mailbox, in their Email Security personal/individual console) as the email will be blocklisted by the HEIMDAL Dashboard domain settings.
2. Another thing to mention is that end users have the default ability to add to the Allowlist/Blocklist a sender's email address/domain, even if the email was marked Normal. The reason behind this is that the Normal type is not included as a type in the Advanced Threat Protection list.
3 When adding an entry to the Email Security personal/individual Allowlist, the whitelist is performed on all engines, except the Virus scanning engine and the SPF/DMARC check engine.
EMAIL SECURITY settings
To set up Email Protection - Email Security in the HEIMDAL Dashboard, you have to log in and access the Network Settings section:Email Security - enables the Email Security module.
Authorize and install the Email Security Entra application - allows you to connect the Heimdal Email Security to O365 / Azure tenant by installing the Heimdal Security ESEC enterprise application in Entra to allow the HEIMDAL Dashboard to get mailbox count from the Microsoft Graph/Office 365 API.
Configuration
Add Domain - allows you to add the domain that will be filtered by the Email Security engine.
Domain name - allows you to add a domain name (e.g., heimdalsecurity.com).
Inbound Traffic - allows you to set your Inbound Mail Server Domain/Public IP, your Port, and to choose a TLS option (e.g., heimdalsecurity-com.mail.protection.outlook.com:25);
Outbound Traffic - allows you to set the Outbound SMTP Server by selecting one from the dropdown or adding the Public IP Address of the SMTP Server in the Public IP field.
Archiving - Allows you to select the desired e-mail archiving period and implicitly the timeframe corresponding to the resend option.
Authentication & Filtering
General Settings
Temporary inbound email delivery pause - With this option, you can put email delivery on pause. The system will check every 15 minutes if the pause was removed.
Authentication
SPF verification - checks if the incoming email comes from a host that the domain's administrators authorize to send on behalf of the domain.
SPF Softfail verification - while this option is enabled, inbound emails from a domain on which the SPF Records are set with SoftFail will be quarantined for failing the SPF check. When the option is disabled, inbound emails from a non-authorized sender will fail (no matter if the SPF Records are set with SoftFail or HardFail).
Sender Rewriting Scheme (SRS) - allows the Email Security engine to rewrite the Envelope From address for all Inbound emails. The Header From field will remain unchanged. This feature bypasses the requirement to allow the HEIMDAL Email Security IP Addresses on your organization's Mail Server. This feature is recommended only in case of not being able to allowlist the HEIMDAL Email Security IP Addresses.
DMARC Verification - checks if the incoming email comes from a sender that is authorized to send emails on behalf of the sending domain and that the email has not been modified in the delivery process.
Recipient verification - this option allows the Email Security servers to verify if a recipient's email address exists before sending them an email. If a user does not exist, Email Security will block the email before it reaches the mail server. Recipient verification helps improve the spam block rate by using resources more efficiently. Enabling it will tell Email Security to do recipient verification on port 2525 (just like Exchange does it for receipt validation) instead of port 25 (which is configured on the domain. When it's disabled, recipient verification is done on the configured port (25 or any other port). (This feature is visible and can be configured only by the Support Team.)
Anti-Spam
The Anti-Spam settings allow you to change the aggressiveness of the spam filter and to choose what actions to take on emails based on five different classification levels and scores between -0.1 and 100.
Anti-Spam detection - enables or disables the anti-spam filtering engine on the selected domain.CLASSIFICATION - Each email that is being filtered by the HEIMDAL Email Security module gets a classification from one of the anti-spam engines. The emails can be classified as Confirmed Spam, High Possible Spam, Possible Spam, Suspected Spam, and All other Emails.
SCORE LEVEL - allows you to customize a value between -0.1 and 100 that will serve as a limit for the action that will be taken on each email; a lower number/score will make the Anti Spam engine detect emails that are less likely to be spam, and a higher number will make the Anti Spam engine detect emails that are likely to be spam.
PREVIEW - redirects you to the Email Security view and applies the search filters according to the Classification, Score Level, and configured domain.
ACTION - allows you to choose an action for every type of classification (Reject, Quarantine, Tag Subject, None).
- Reject will reject the email without storing it on the HEIMDAL servers.
- Quarantine will quarantine the emails and will store them for 90 days on the HEIMDAL servers.
- Tag will add a tag to the email’s existing subject: # Warning: Possible Spam or Fraud! #.
- None will make the emails pass unaltered through the Email Security engine.
Examples:
- If the Score level is set to >= 3, emails that get a score level of 2 will not be flagged (they will be DELIVERED), while emails that get a score level of 3 or higher will be flagged as SPAM (they will be Tagged, Quarantined, Rejected, or No Action, depending on the set Action).
- If the classification for Possible SPAMs has a set Score Level of 2 and an action of Quarantine, all emails that are tagged as "Possible SPAM" and have a Score Level equal to or higher than 2 will be quarantined and flagged as SPAM in the Email Security view (within the HEIMDAL Dashboard).
Presets - allow you to use the recommended presets for Anti-Spam settings: Moderate (relaxed settings), Default (regular settings), Aggressive (restrictive settings).
Email Fraud Prevention
Email Fraud Prevention - enables or disables the Email Fraud Prevention filtering engine on the selected domain.
Action on detection - allows you to choose an action for every type of classification (None, Quarantine, Tag Subject, Reject).
- Reject will reject the email without storing it on the HEIMDAL Servers;
- Quarantine will quarantine the emails and will store them for 90 days on the HEIMDAL Servers.
- Tag Subject will add a tag to the email’s existing subject: # Warning: Possible Spam or Fraud! #.
- None will make the emails pass unaltered through the Email Fraud Prevention engine.
Antivirus
Antivirus detection - allows you to activate or deactivate the malware & virus detection engines. This can be used to diagnose against false positives, if Email Security detects legitimate emails and/or attachments as harmful or containing malware.
Action on detection - allows you to choose an action for every type of classification (None, Quarantine, Tag Subject, Reject).
- Reject will reject the email without storing it on the HEIMDAL Servers;
- Quarantine will quarantine the emails and will store them for 90 days on the HEIMDAL Servers.
- Tag Subject will add a tag to the email’s existing subject: # Warning: Possible Spam or Fraud! #.
- None will make the emails pass unaltered through the Email Fraud Prevention engine.
Advanced Threat Protection
Advanced Threat Protection (this feature is included in the Email Security Advanced licensing option) - allows you to activate or deactivate the detection systems against advanced threats. This can be used to diagnose false positives, in the event of legitimate emails and/or attachments that are harmful or contain advanced threats.
Macro Analyzer - allows you to execute macros and scripts within emails in a sandboxed environment for analysis & detection.
PDF Analyzer - executes PDF files and other container files within emails in a sandboxed environment for analysis & detection.
SHA256 Analyzer - this feature quickly checks the email blocked by Email Security Advanced Threat Protection against online malware analysis services Virustotal and Payload Security. This can be of use in gaining more information on a specific malware sample. Email Security generates a SHA256 hash checksum for each file detected as suspicious/bad/harmful/malicious. You can run the search or even download email parts through the Messaging Logs interface. To search & locate any email blocked by Email Security Advanced Threat Protection in Messaging Logs, you have to left-click the email and select Attachments. Here, you will have the option to check the attachments' checksum directly at VirusTotal or Hybrid Sandbox. You can download the full attachment for further investigation and analysis, but please be aware that downloading the full attachment can be a security risk (which will also be communicated via a dialogue box before potential download).
Phishing Protection - enable or disable the detection systems against phishing emails. This can be used to diagnose against false positives, if Email Security detects legitimate emails as phishing emails.
Post-release ATP scan - allow the email to be scanned by the ATP Email Security engines after being released from quarantine (due to previously having been detected by the Antivirus, Anti-Malware, and Anti-Spam engines). An email that is not confirmed malicious by the Advanced Threat Protection will be delivered, but it will be flagged as Released to ATP. If Advanced Threat Protection confirms that the email is malicious, the email will be quarantined and the type will be changed from Released to ATP into ATP.
Action on Detection - allows you to configure the actions that will be taken by Email Security on emails containing threats, categorized by malware, ATP, and Phishing (None, Quarantine, Tag Subject, Reject).
Non-TLS mail policy
Non-TLS mail policy- allows you to tag, quarantine, and reject emails that are not transmitted through TLS. the quarantine will store the emails for 90 days, while the reject will not store them in any way.
Action on detection - allows you to choose an action for every type of classification (None, Quarantine, Tag Subject, Reject).
- Reject will reject the email without storing it on the HEIMDAL Servers;
- Quarantine will quarantine the emails and will store them for 90 days on the HEIMDAL Servers.
- Tag Subject will add a tag to the email’s existing subject: # Warning: Possible Spam or Fraud! #.
- None will make the emails pass unaltered through the Email Fraud Prevention engine.
Newsletter mail policy
Newsletter mail policy - will scan for emails that are newsletters or look like newsletters.
Action on detection - allows you to choose an action for every type of classification (None, Quarantine, Tag Subject, Reject).
- Reject will reject the email without storing it on the HEIMDAL Servers;
- Quarantine will quarantine the emails and will store them for 90 days on the HEIMDAL Servers.
- Tag Subject will add a tag to the email’s existing subject: # Warning: Possible Spam or Fraud! #.
- None will make the emails pass unaltered through the Email Fraud Prevention engine.
File attachment policies
This feature will allow you to change the different settings for an email with attachments. The attachment filters can be enabled for specific file extensions. As an increasing number of threats are trying to bypass email filters by filename and/or file parser manipulation, Email Security also provides an advanced attachment filter, based on inspection and analysis of each attached file. The advanced attachment filter will also safeguard against users renaming or manipulating their files to bypass policies your organization has set up for allowable file types for email transmission. You also have the option to select specific actions on detection for different file extensions.
- Executable file attachment interception- allows you to intercept and take action on emails with attached executable files (EXE files);
- Dangerous file attachment interception - allows you to intercept and take action on emails with attached files with the following file extensions: .ac .air .apk .app .applescript .awk .bas .bat .cgi .chm .cmd .com .cpl .crt .csh .dld .dll .drv .elf .exe ._exe .fxp .hlp .hta .inf .ins .inx .isu .iqy .jar .js .jse .jsp .kix .ksh .lib .lnk .mcr .mem .mht .mpkg .mrc .ms .msc .msi .msp .mst .ocx .pas .pcd .pif .pkg .pl .prc .prg .py .pyc .pyo .reg .scpt .scr .sct .seed .sh .shb .shs .spr .sys .thm .tlb .udf .url .uue .vb .vbe .vbs .vdo .wcm .ws .wsc .wsf .wsh .xap .zlq .wmf;
- Password-Protected attachment interception - allows you to intercept and take action on emails with attached files that are password-protected (usually archives).
- Multiple file extension attachment interception - all the emails having attachments made of more than one extension will be handled based on the selected Action on Detection.
Action on detection - allows you to choose an action for every type of classification (None, Quarantine, Tag Subject, Reject).
- Reject will reject the email without storing it on the HEIMDAL Servers;
- Quarantine will quarantine the emails and will store them for 90 days on the HEIMDAL Servers.
- Tag Subject will add a tag to the email’s existing subject: # Warning: Possible Spam or Fraud! #.
- None will make the emails pass unaltered through the Email Fraud Prevention engine.
Custom file extension attachment interception - Add your own definitions of file extensions to be filtered by the Heimdal Email Security platform. Please note that Threats in attachments are often masked by a false & corrupted file extensions, when compared to real content of the attachment. Please input the file extension without "." (e.g.: exe)
Outbound Traffic
Outbound mail rate limiting - allows you to set a maximum limit per mailbox for outbound emails.
Block outbound emails containing a Danish CPR number only when no TLS is detected - this option will block outbound emails when a Danish CPR number is detected, even if the Force TLS (encrypted) transmission is enabled for any domains.
Block outbound emails containing a Danish CPR number - scans the email for any Danish CPR number and blocks it if it includes any Danish CPR Number.
DKIM** Signing - allows you to generate and configure a DKIM Signature that will be included in the outbound email header; to create a signature, type a selector, choose the Key Length, and hit Generate.
After generating it, the DKIM Signature needs to be added to the domain's DNS records. Once added, they can be validated within the Email Security settings (in the HEIMDAL Dashboard) by using the Check DNS button (it can take up to 48 hours until the changes on the domain's DNS records are propagated). After validation, the configured selector can be enabled (using the enable tickbox).
SMTP AUTH Users - This feature allows you to add an SMTP Authenticated User for a Printer or a Copy-Machine to send emails through Email Security. To use this feature, you need to specify a username, a password, and an IP Address:
- Username: smtp (or any other username)
- Password: <your-password>
- Confirm Password: <confirm-your-password>
- IP Address: <your-IP-Address>
Press Add, then Save changes and Update Network Settings.
To test the SMTP Auth feature, you can use the following command line in a PowerShell window or the script below:
Send-MailMessage -From 'smtp@yourdomain.com' -To 'recipient@otherdomain.com' -Subject 'Test Email' -Body 'Testing the SMTP Relay Service' -SmtpServer 'eu-esec-outbound.heimdalsecurity.com' -Usessl -Port 587 -Credential (Get-Credential)
You will be prompted to insert the credentials (smtp@yourdomain.com* and password) you added in the HEIMDAL Dashboard. Although in the Heimdal Dashboard, the username does not include the domain, in the authentication pop-up, you are required to specify the domain.
[Net.ServicePointManager]::SecurityProtocol =[Net.SecurityProtocolType]::Tls12 $username = 'test@yourdomain.com' $password = 'mypassword1234' $securepassword = ConvertTo-SecureString $password -AsPlainText -Force $mycreds = New-Object System.Management.Automation.PSCredential ($username, $securepassword) Send-MailMessage -From 'test@yourdomain.com' -To 'test@internet.com' -Subject 'Test Email' -Body 'Testing the SMTP Relay Service' -SmtpServer 'eu-esec-outbound.heimdalsecurity.com' -Usessl -Port 587 -Credential $mycreds
Make sure you use the Email Security outbound server corresponding to your region:
- eu-esec-outbound.heimdalsecurity.com with ports 25, 587, 2525 (for customers stored in the Europe region).
- us-esec-outbound.heimdalsecurity.com with ports 25, 587, 2525 (for customers stored in the United States region).
- uk-esec-outbound.heimdalsecurity.com with ports 25, 587, 2525 (for customers stored in the United Kingdom region).
- uae-esec-outbound.heimdalsecurity.com with ports 25, 587, 2525 (for customers stored in the United Kingdom region).
SEPO encryption
Inbound SEPO verification - allows you to use the SEPO encryption service and delivers the email to the SEPO Inbound Scan Server.
Outbound SEPO verification - allows you to use the SEPO encryption service and checks CPR, Abnormal, and Forced TLS delivery.
SEPO Version - allows you to change the version used for the verification.
Quarantine Report
Quarantine Report Settings
Admin Quarantine Report - issues a complete spam report via email to define administrators of your company. The complete spam report contains an overview of blocked spam for all your company's users. Users are automatically defined by the email address of the intended receiver. You can define the frequency of how often your defined administrators will receive an Administrator Quarantine Report in this section. Your defined administrators can release blocked spam from the report. To avoid spam release conflicts, enabling the Administrator Quarantine Report, will disable User Quarantine Reports.
Personal Quarantine Report
User Quarantine Report by Email - allows you to enable the User Quarantine Report to be sent to recipients of quarantined emails. The users who do not receive any quarantined emails will not receive a User Quarantine Report. To avoid spam-releasing conflicts, enabling this feature will disable the Admin Quarantine Report.
Personal Console - allows end users to access their personal/individual dedicated Email Security portal that allows them to view the emails received on their email address, release quarantined emails, and add new entries in the Allowlist/Blocklist. The personal/individual dedicated Email Security portal can be accessed through the following URL: https://rc-dashboard.heimdalsecurity.com/emailspamfilterlogs/index, where the user needs to input their email address (it needs to be a valid email address) to get access through a temporary token that is valid for 24 hours (from the moment it was generated). This option is available only if User Quarantine Report by Email is enabled.
Customize the Quarantine Report interval - This option will allow your users to generate a Custom Quarantine Report based on the time interval selected. The Custom Quarantine Report can be generated using the "Get Report" button or directly in the General Quarantine Report email.
Quarantine Report Schedule
Allows you to schedule when the Quarantine reports are generated.
Quarantine Report Content
It allows you to define what type of quarantined emails should be included in the Quarantine Report (Spam, Malware, ATP, Attachment, SPF, Non-TLS, Newsletter, EFP) and to enable whether to Preview, Release, or Allow the Sender right from the quarantined email right from the Quarantine Report notification.
Allow Sender whitelist by 'Header From' in the Quarantine Report - Enable this functionality in case you want the allowlist entries to consider the header from info instead of the from info.
Allowlist, Blocklist & Greylist
These functionalities will allow you to add email addresses, domains, IP Addresses, or Email Subjects to the Blocklist or the Allowlist, thus regulating specific email senders your organization needs to always block or allow.
Allowlist
Allows you to allowlist an email address, a domain, or a sender IP Address that is sending emails to your domain, or to allowlist an email based on the email subject, and can be customized to bypass different scanning methods. Under normal circumstances, it is not advisable to allow sender IP Addresses, as this can provide open access for threats and spam in the event the sender's network or endpoints are compromised. If you want to edit an existing allow listing rule, you can click the Pencil button:
In the Allowlist editor, you can edit the allowlisting settings performed on the email matching the allowlist rule, and you can leave a note for any HEIMDAL Dashboard Administrator who will go through these settings.
- SPF/DMARC scanning - while unticked, the specified email address/domain/IP Address will be whitelisted for SPF/DMARC scanning.
- Spam scanning - while unticked, the specified email address/domain/IP Address will be whitelisted for Spam scanning.
- Virus scanning - while unticked, the specified email address/domain/IP Address will be whitelisted for Virus scanning.
- Attachment detection - while unticked, the specified email address/domain/IP Address will be whitelisted for attachment scanning.
- Advanced Threat Protection - while unticked, the specified email address/domain/IP Address will be whitelisted for Advanced Threat Protection scanning.
- Non-TLS block - while unticked, the specified email address/domain/IP Address will allow emails that are not sent with TLS.
- Check Header - while enabled, the header sender information will be checked. The SPF/DMARC scanning engine will not be whitelisted for security reasons.
The Allowlist takes precedence over the Blocklist, so if you allowlist the sender's email address (test@example.com) and blocklist the sender's domain (example.com), the email should be received by the recipient. Allowlisting an email based on the subject will NOT bypass the SPF/DMARC check, even if it's disabled in the allowlist.
The Import CSV functionality allows you to import a blocklist from a CSV file (you can download a sample by hovering the Allowlist info bubble.
Blocklist
Allows you to blocklist an email address, a domain, or a sender IP Address that is sending emails to your domain, or to blocklist an email based on the email subject and take action against it (Quarantined, Reject, Delete). If you want to edit an existing blocklisting rule, you can click the Pencil button:
In the Blocklist editor, you can edit the action that will be performed on the email matching the blocklist rule, and you can leave a note for any HEIMDAL Dashboard Administrator who will go through these settings.
The Allowlist takes precedence over the Blocklist, so if you allowlist the sender's email address (test@example.com) and blocklist the sender's domain (example.com), the email should be received by the recipient.
The Import CSV functionality allows you to import a blocklist from a CSV file (you can download a sample by hovering the Blocklist info bubble.
Greylist
Domain greylist threshold - allows you to enable and set the domain greylisting interval from 1 to 90 days. Domain Greylisting will collect and store data on sending domain names for the number of days set on the threshold slider. This feature works in conjunction with the Tag greylisted emails, which adds a tag (# Unknown domain: Possible spam/phishing mail #) in the Subject field of each email that is coming from a sender's domain name that has not been sending emails to your organization in the last 1 to 90 days (according to the value set on the Domain greylist threshold). We recommend having the Domain greylist threshold activated for at least 30 days before enabling the Tag greylisted emails option for better data collection. Also, know that the data collection on sending domain names will be done if all the above conditions are met:
- The recipient's domain is not the same as the sender's domain.
- The sender's domain is not in the list of common domains.
- The sender's domain was not whitelisted.
Tag greylisted emails - adds a tag (# Unknown domain: Possible spam/phishing mail #) in the Subject field of each email that is coming from a sender's domain name that has not been sending emails to your organization in the last 1 to 90 days (according to the value set on the Domain greylist threshold). Each email will be scanned in the background.