Attachment filtering allows you to scan files attached to email messages. When filtering attachments, Kaspersky Security searches for files that meet the specified filtering criteria. Attachment filtering is available if the Anti-Virus for the Hub Transport role component is installed on Microsoft Exchange Server.
Attachment filtering criteria include the following settings:
The application recognizes the format of a file by its structure, that is, by the way it is stored or displayed on the screen. This allows you to filter attachments even if the extension of an attached file does not match the actual type of the file (for example, if the extension has been changed intentionally).
You can specify full file names or use file name masks.
The application can perform any of the following actions on attachments that have been filtered out:
Kaspersky Security can record events related to attachment filtering to Windows Event Log. You can configure event recording to Windows Event Log in the Notifications node.
Kaspersky Security deletes messages and attachments without any option of restoration. It is recommended that you save copies of messages in Backup to avoid data losses. You can enable this feature in the filtering settings.
Kaspersky Security can notify you of actions performed during attachment filtering by email. You can configure delivery of automatic notifications in the Notifications node.
The attachment filtering statistics are displayed in the <Server name> node and added to reports for the Hub Transport role.
Exclusions from attachment filtering
You can toughen the attachment filtering criteria by excluding messages from filtering. You can exclude messages from scanning as follows:
The application will not scan attachments in messages from the specified senders.
The application will not scan attachments in messages sent to the specified recipients.
The application will not scan attached files that match the specified names or name masks.
Features of attachment filtering in Kaspersky Security
The following Anti-Virus settings affect attachment filtering:
Containers and archives that have been excluded from Anti-Virus scanning by a file name or file name mask, will also be excluded from attachment filtering as follows:
Containers and archives with multiple embedded levels are scanned in accordance with the attachment scan settings of Anti-Virus. If attachment scanning is disabled in the Anti-Virus settings, the application scans containers and archives down to the second embedded level during attachment filtering.
You can use the Advanced Anti-Virus settings tab to configure exclusion of files by mask or scan depth when scanning attachments in containers and archives.
About preventing message detainment during attachment filtering
In exceptional cases, failures in the anti-virus kernel operation may lead to increased times of attachment filtering in messages. In such cases, the Attachment Filtering module temporarily switches to the restricted scan mode in order to prevent message detainment. In this mode, some messages can be skipped without undergoing attachment filtering.