Sophos Email customers using IP-based mailflow rule connectors must migrate to certificate-based configuration by March 31st. To see if you're affected Click Here.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Emails being deleted for Reason 'Customer Block List'. Where is this block list?

Hello all,

We should have been receiving emails from Sophos regarding an MTR incident, but we never did. I went into Email Gateway > Message Trace and looked for the email address on the dates expected and we can see entries for the missing emails that state:

'Last Status' > Deleted for user.user@domain.com | 'Reason' > Customer block list

The only place I would assume this would be is the Allow / Block list Settings entry in Email Gateway, but in said portal there's no such entry for any email address/domain that we were expecting the email to come from (mtr-ops@sophos.com). Curiously, the status suggesting it was 'Deleted for' as above would imply that it would only be deleted for that named person's mailbox, and yet there were a handful of us in the intended recipients.

Can someone please clarify for me what has happened here and how we can ensure this doesn't happen again?

Many Thanks!



Added tags
[edited by: Raphael Alganes at 8:12 AM (GMT -7) on 30 May 2023]
  • Hello Patrick,

    Thank you for contacting the Sophos Community.

    You might have been affected by XGE-20693, which basically would delete/quarantine (Depending on your settings) emails with file types that aren’t part of the DLP policy.

    This might have happened if you configured your own Use custom list and switched back to "Use Sophos recommended list".

    The workaround was to delete the DLP rule having "Use Sophos Recommended list" and create a new rule with "Use Sophos recommended list"

    However, this was fixed on Aug 12, I would recommend to run the Work Around, and monitor if the issue happens again, and if so open a case with support to have it investigated, mention the XGE-20693, or if you need a RCA you can also open once, requesting for the same, (if emails aren’t more than 14 days long)

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.