That is correct. Specifically to below list of servers
443
TCP
Out
serviceconfig.talos.cisco.com
grpc.talos.cisco.com
email-sender-ip-rep-grpc.talos.cisco.com
For IP -based firewall:
146.112.62.0/24
146.112.63.0/24
146.112.255.0/24
146.112.59.0/2...
Is this what you were looking for - https://www.cisco.com/c/en/us/td/docs/security/esa/esa15-0/user_guide/b_ESA_Admin_Guide_15-0/b_ESA_Admin_Guide_12_1_chapter_01010.html#con_1146269
This was from 15.0 user guide.
I am assuming this is a notification template if yes, then u can use $header followed the by the string or name of the header.
For e.g. Reply To: $header['Reply-to']
User guide reference - https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/us...
If you are not using a proxy, ensure ESA can resolve and connect to these URL(s) on port 443.
prod-register-api.uce.cmd.cisco.com
prodap-retro-api.uce.cmd.cisco.com
prodeu-retro-api.uce.cmd.cisco.com
produs-retro-api.uce.cmd.cisco.com
While manual whitelisting is possible, you additionally submit the email samples to Cisco to request re-classification as described in https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/214133-how-to-submit-email-messages-to...