Customizing Retention Period of Emails and Auditing
Email Security allows you to customize the email retention period based on the verdict of the security engines.
Default Retention Period of Emails
| Verdict and Enforcement | Raw Email (Original email with attachments) | Email Meta Data (Attributes and data detected from the security scan) |
|---|---|---|
| Clean emails (Includes emails with re-written links in the email body) | 14 days | 14 days |
| Emails with modified attachments and emails that have cleaned (sanitized) attachments, removed as password-protected attachments, and re-written links | 14 days | 180 days |
| Emails containing threats but not quarantined (includes emails with phishing /spam / malware / DLP detection that are not quarantined) | 14 days | 180 days |
| Quarantined emails (includes manually quarantined emails) | 180 days | 180 days |
| Emails quarantined by Microsoft | 180 days | 180 days |
Custom Retention Periods
To configure custom retention periods for raw emails:
-
Go to System Settings > Customization.
-
Under Email Retention Settings, select Custom.
-
Based on the security engines' verdict and quarantine state, select the number of days you need to retain an email.
-
Click Save and Apply.
Note:-
Any changes to the retention period take effect within 24 hours and apply only to new emails.
-
Emails get deleted at the end of the day (UTC time zone) of each retention period. Sometimes, it may take extra time for the delete action to be completed.
-
For details about the actions available during and after the retention period, see Available Actions on Emails During and After the Retention Period.
Auditing
Email Security audits all the changes to the retention period and adds them to the System Logs (System Settings > System Logs).