cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2766
Views
3
Helpful
7
Replies

Incoming Mail Policy Matching only Envelope From but not Reply-To or From header

Tony Kilbarger
Level 1
Level 1

We are a cloud CES customer.  I believe last night we were upgraded from 11.1.0-135 to 11.1.2-023. 

 

Today we have reports of incoming email not matching an incoming policy that it previously did.  The policy matches specific sender addresses.  What we think we are seeing is that it is now only matching on the Envelope Sender address but not the Reply-To: header or the From: header.  For example we have a policy that uses "Following Senders" abc@mydomain.com.  If that is the Envelope Sender it matches.  If the envelope sender is something else that does not match a policy but the reply-to: or the from: is abc@mydomain.com, it will not match the policy.  From the documentation it should match based on this sequence:

 

  Matching Users to a Mail Policy

    • Envelope Sender (RFC821 MAIL FROM address)
    • Address found in the RFC822 From: header
    • Address found in the RFC822 Reply-To: header

Wondering if others are seeing this or are aware of it.  My co-worker is opening a case with TAC as I type.

 

7 Replies 7

I'm seeing that on 12.x on prem...




Tony/Ken
Try this:
Navigate webui to > Mail Policie > Mail Policy Settings > click the name of the “headers” clickable link. > add checks for the desired header fields

Well, duh...

Thanks guys.






munbali
Cisco Employee
Cisco Employee

Hi Tony,

 

starting with 11.1.x versions, there is a change where the mail policy matching is now configurable:

https://www.cisco.com/c/en/us/support/docs/security/cloud-email-security/212808-configure-flexible-mail-policy-match-fea.html

 

if you clicked the mail policies tab , you will see a new option under the incoming and outgoing mail policies and filters called mail policy settings 

 

from it you should see that the envelope sender is the only method added, you can edit it to include the from header and/or the reply to as well

 

Best Regards,

Muna Bali

Yes, working with support this was our issue.  We had two CES clusters, one was upgraded, one was not so I could test.  When you went to the Mail Policy Settings on either version, it had just Envelope Sender P1.  The older version still matched on all 4, the new version did not. 

 

We made it go back to matching on all of the fields by deleting the entry on this screen.  This is different than checking all 4 fields and setting a priority P1 to P4 for them.  With no entries there, it will check all 4 fields in order for each the first policy, then if no match move on to the next policy and check all 4 and so on through all policies to default.  If instead you select all 4 and make them P1, P2, P3, P4, it will check the field you have set as P1 for each policy to try to match, then it will check the field marked P2 in each policy and so on.  Hope that makes sense.

 

Tony

So in 11.1.0, the option was set but seemed to have no effect, it still matched Env Sender, From, Reply-To even though it was set ( assume as a default ) to Envelope Sender only. With the upgrade to 11.1.2, it began working as documented.

So, no entries is probably equal to checking all 4 as priority 1???
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: