Attachment filtering lets you filter file attachments based on specific criteria, and scan text in email messages and message subjects for prohibited words. When filtering attachments, Kaspersky Security scans email messages for text and file attachments that meet the specified filtering criteria and applies the action configured by the administrator to those files: deletes the attached file, deletes the entire message, or ignores the message.
Attachments are filtered based on individually configured rules.
Kaspersky Security can record events related to attachment filtering to Windows Event Log. You can configure event logging to the Windows Event Log in the Notifications node.
Kaspersky Security deletes messages and attachments without any option of restoration. It is recommended that you save copies of messages in Backup to avoid data losses. You can enable this feature in the filtering settings.
Kaspersky Security can notify you of actions performed during attachment filtering by email. You can configure delivery of automatic notifications in the Notifications node.
The attachment filtering statistics are displayed in the <Server name> node and are added to reports for the Hub Transport role.
Attachment filtering is available if the Anti-Virus for the Hub Transport role component is installed on Microsoft Exchange Server.
About preventing message detainment during attachment filtering
In exceptional cases, failures in the anti-virus kernel operation may lead to increased times of attachment filtering in messages. In such cases, the Attachment Filtering module temporarily switches to the restricted scan mode in order to prevent message detainment. In this mode, some messages can be skipped without undergoing attachment filtering.