That is correct. Specifically to below list of servers
For IP -based firewall:
Is this what you were looking for - https://www.cisco.com/c/en/us/td/docs/security/esa/esa15-0/user_guide/b_ESA_Admin_Guide_15-0/b_ESA_Admin_Guide_12_1_chapter_01010.html#con_1146269
This was from 15.0 user guide.
I am assuming this is a notification template if yes, then u can use $header followed the by the string or name of the header.
For e.g. Reply To: $header['Reply-to']
User guide reference - https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/us...
If you are not using a proxy, ensure ESA can resolve and connect to these URL(s) on port 443.
While manual whitelisting is possible, you additionally submit the email samples to Cisco to request re-classification as described in https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/214133-how-to-submit-email-messages-to...