Skip to main content
Version: Spectra Analyze 9.9.0

Email Quarantine

The Email Quarantine feature lets analysts review emails that were blocked by the Spectra Detect SMTP Connector and, when appropriate, release them so they are delivered to their original recipients.

When Spectra Detect runs the SMTP Connector in in-line relay mode, emails that are classified as a threat are not delivered. Instead, the blocked email is uploaded to a Spectra Analyze appliance that acts as the quarantine, where it is stored as an .eml sample. From Spectra Analyze, an analyst can inspect the email and its analysis results, and then release it if it is determined to be safe.

note

Availability: The SMTP In-Line Relay feature is available in Spectra Detect 6.1 and later.

The Email Quarantine feature requires backend configuration on the Spectra Analyze appliance, including the outbound mail server used to deliver released emails. To enable this feature, contact ReversingLabs Support.

Identifying quarantined emails

Quarantined emails are .eml samples acquired through the Spectra Detect SMTP Connector. Each quarantined sample carries an automatically added comment explaining why it was quarantined, for example:

Sample quarantined because of classification.

The comment is visible in the Comments section of the Sample Details Summary page and in the Expanded Details on the Search & Submissions page.

Releasing an email from quarantine

You can release a quarantined email from either of the following places:

  • On the Sample Details Summary page of the .eml sample, select the Release from Quarantine button.
  • On the Search & Submissions page, open the actions menu (☰) for the .eml sample and select Release from Quarantine.

When an email is released:

  • The quarantined .eml is sent to the configured outbound mail server, which delivers it to the original recipient(s).

  • An automatically generated comment is added to the sample, recording the user who released it and the time of release (in UTC), for example:

    Released from quarantine by nonadmin on 2026-03-17 09:58:38 UTC. (auto-generated message)

  • A released-from-quarantine tag is applied to the sample.

An email cannot be released from quarantine more than once.

Finding quarantined and released emails

Every released email is tagged with the released-from-quarantine System Tag. To find all previously released emails, filter by this tag:

  • Select the released-from-quarantine tag wherever it appears on a sample, or
  • Use the tag keyword in Advanced Search, for example tag:released-from-quarantine.

See System and User Tags for more information on searching by tag.

Cross-product workflow

Email quarantine is a joint Spectra Detect and Spectra Analyze workflow:

  1. Spectra Detect (configured in the Spectra Detect Manager): The SMTP Connector runs in in-line relay mode and is configured with the address and access token of the Spectra Analyze appliance that acts as the quarantine. Blocked emails are uploaded there as .eml samples.
  2. Spectra Analyze (enabled by ReversingLabs Support): The Email Quarantine feature and the outbound mail server are configured on the appliance.
  3. Day-to-day use (analyst): The analyst reviews quarantined emails in Spectra Analyze and selects Release from Quarantine for emails determined to be safe. The email is delivered to its original recipient(s), and the release is recorded in the sample's comments and tags.