Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Can you block all outbound e-mails from a certain adress?

    God day everyone. We have a certain e-mail address that we're 100% sure has been infected by a virus. The virus makes the address send spam mails constantly. And while they are being sent to quarantine before they are delivered, the load is still…
  • Benachrichtigungen werden nicht versendet - Email has been accepted by device and queued for scanning

    Hallo, ich habe die Benachrichtigungseinstellungen konfiguriert. Egal ob ich den integrierten Mailserver oder meinen externen Mailserver benutze bekomme ich die oben genannte Meldung und es kommt nichts an. Ich habe bereits in dem englischen Forum…
  • block or check simple phishing links in emails

    Hello all, I have the Sophos XG solution in the company. But it seems that with the new firewall it is not possible to block or check simple phishing links in emails how can this be? That would be an incredible step forward. Many greetings Si…
  • XGS firewall and mail protection settings

    I had a SG210, running UTM 9 and was using it as a mail gateway for multiple domains to filter spam mail before the mails be re-directed to respective mail hosts. The SG210 is set in transparent mode. I replaced the SG210 with XGS2300, also in transparent…
  • Sophos XG acting as Open Relay

    Hey Community, I´ve got a probleme which I don´t know how to fix, maybe some of u can help me! I´ve created a MTA on my Sophos XG 18 which receive and send Mails for my Exchange 2016. Now I have checked my mail flow and to my suprise mxtoolbox said…
  • Sophos XG Mail Protection

    Hello Folks, honestly, I'm pretty disappointed with XG in the matter of its mail protection. The implementation is so rudimentary that I just wonder if we are the only partner on this planet dumb enough to sell mail protection licenses to our customers…
  • XG 18.5.2 howto Skip TLS negotiation and verify?

    Hi, i need to Skip TLS negotiation for a email adress/domain. I already tried to add a FQDN-Host Entry like smtp.recipient.de and the IP-Host with the corresponding MX IP-Adress here. It´s still not working. What would be the correct setup? …
  • Firewall in MTA mode not sending out mails

    hi all, since about a day, my firewall Home edition 18.5.2 is not sending out any mails anymore. It seems it cannot connect to the smtp servers of the domains it tries to send to. Oddly enough, I can telnet from the firewall advanced console into…
  • enable/disable MTA SMTP debug at XG 18.5.2

    Hi, i found some information on enabling smtpd debuging. I want to know the command to enable debuging and disabling debuing for a XG 18.5.2 running in MTA mode. I have one mail receipient, where we can´t send any mails and i want to get more debug…
  • Bounced emails on our mail?

    Hi, I'm using our Sophos SFV4C6 (SFOS 18.5.1 MR-1-Build326). Everything works fine except for an bounce mails from/to our mail (supporto@.....) This emails is bouncing but I don't really know why..... Does anyone have a suggestion for me? thanks…
  • MTA outgoing IP

    Hello, With MTA enabled, SMTP policy and net rule to scan SMTP, Sophos uses default IP gateway. I would like define an outgoing ip. If possible a different on for domain. I can do that If I disable the scan SMTP in net rule and set an SNAT rule…
  • Blocking TLD in XG firewall Email

    Hi I came across several discussions that have been locked but not answered. How do you block a TLD in the XG firewall as you could do it in the UTM without any issues?
  • SMTP Data Time out message abandoned

    mails from xx.xxx.58.4 / 123@123.de to me Sophos XG 330 192.168.xx.xx bigger than ~5 MB will be failed. 2022-01-24 11:43:38.584 [4663] SMTP connection from [xx.xxx.58.4]:11902 I=[192.168.xx.xx]:25 (TCP/IP connection count = 1) 2022-01-24 11:43…
  • SendGrid as smarthost - failed in server_plain_authentication

    Hi All! My ISP recently decided to block outgoing port 25. I've always used O365 as smarthost to relay e-mail, the downside is that O365 only supports port 25 for relaying to external recipients hence I am in need for a different solution. I've reverted…
  • All email in Mail spool failed with "no route to host" using O365 as smarthost in MTA mode

    Hi everyone! In my home lab running Sophos XG Home I've configured Email running as MTA using O365 as smarthost. (I'm using the MX endpoint as smarthost FQDN per this description ). This setup has worked for years, somehow it broke and I'm unable to…
  • 2 questions with MTA mode email protection

    Hi All, I have 2 questions with MTA mode email protection. Inbound email protection need SMTP route & scan policy to route incoming mails to the internal mail server. And outbound email protection need SMTP route & scan policy to encrypt mail with…
  • Disabling TLS 1.1 within SMTP TLS configuration

    Hi, We've a XG230 running SFOS 18.5.2 MR-2-Build380 During a recent external pen test it's been reported our externally available SMTP service is supporting TLS 1.1 which is a risk because Numerous vulnerabilities have been found in TLS Version 1…
  • Sophos XG Home with mailbox.org / smtps / imaps - sending, receiving and scanning

    Hello there, first of all, let me short introduce myself: i am a sophos XG Home User since the weekend. I believe the Sophos XG is a fine solution for every home user. i even would pay for it, even for support. i am using a simple micro-system with…
  • MTA Backup Mail Server to Internal Email Server over RED Tunnel

    I have had a site-site VPN link to/from my inlaws for simple NAS backups and running backup email MTA for about 5 years now. both XG firewalls have just been updated to SFVH (SFOS 18.5.2 MR-2-Build380), however since the update the SSL Site-Site VPN…
  • Close port 25 for MTA

    I've got a customer with an XG310 firmware 18.5.1. They have the MTA fully in use but they like to have there mail delivered on port 587. So i changed the auto added firewall rule, and that is working well. Mail is coming from there antispam provider…
  • Problem with SPF; some mails not blocked; only Return-Path checked and not From-Field?

    It looks like SPF check is working only on the return-path. Proved by: I can see external messages in the email log, which a blocked via spf (faking our domain as sender). However, there are other messages, which have our domain in the from field (mail…
  • Bounced message errors, where are they, why are they unavailable

    I am very disappointed in the error reporting functionality of the XG v18 firewall. Actually, the error reporting just isn't useful at all. Today I have a bounced message due to certificate issue on the recipient end. But the only way I know that is a…
  • Mailscanner process uses 100% CPU (stuck emails in spool)

    Hello, We use a Sophox XG210 with firmware SFOS 18.5.1 MR-1-Build326 (no update available when checked) For a week now I have regular warnings from Sophos Central that our CPU is pegged at 100% I have 3 mails stuck in spool that I am unable…
  • Sophos XG - delete all quarantined file

    Hello, I can't see a soulution in https://community.sophos.com/sophos-xg-firewall/f/discussions/129765/sophos-xg---delete-all-quarantined-file/476812#476812 We also have so much mails to delete. To show only 20 per page and delete them, will…
  • any way to monitor sophos xgs mailspool length ?

    Hello, is there a way to monitor xgs mailspool externaly for using in checkmk or nagios or similar ? i checked the web api, but there is nothing for displaying stats , seems to be only for setting things https://docs.sophos.com/nsg/sophos-firewall…