An email quarantine policy is the set of written rules that decides which inbound messages are held back, at what risk threshold, who may review and release them, how long they are kept and how each decision is recorded. Quarantine itself is the restricted holding area; the policy is what makes it a control rather than a dumping ground.
Why quarantine so often fails
In many companies quarantine is either a black hole, where customer orders, e-invoice notifications and tender replies pile up unseen, or a formality that lets almost everything through. Once staff discover the black hole, they ask IT to "just release everything addressed to me", and the control quietly disappears.
In the loose version, a targeted phishing email or a supplier impersonation goes straight to the finance team. Both failures share a root cause: a technical setting with no policy or owner behind it. If every user can release their own quarantined mail, the attacker only ever has to convince the recipient.
DMARC quarantine is not inbound quarantine
The two are easily confused. The p=quarantine tag in your DMARC record tells other people's mail servers what to do with messages that claim to come from your domain but fail authentication; it protects your reputation and your contacts. We cover that side in our SPF, DKIM and DMARC guide. This article is about the opposite direction: which messages arriving at your organisation you hold back, on what grounds and under whose control.
The cost of running quarantine without a policy
Quarantine is often where email-borne attacks are first stopped, and what filters hold back is far more than nuisance spam. According to the Verizon 2026 Data Breach Investigations Report, of the attacks blocked by email security gateways, 80% were plain phishing, 10% carried malware, 5% tried to get the victim to phone the attacker and 3% were BEC-style attempts to get a bank account updated before a wire transfer. Releasing one of those without a reason undoes the filter's work in a single click.
How widespread the threat is gives another reason quarantine cannot be managed ad hoc:
According to ENISA's Threat Landscape 2025, phishing, including vishing, malspam and malvertising, was the leading initial intrusion vector in the incidents analysed in Europe, at about 60%. (ENISA Threat Landscape 2025)
Smaller businesses are not spared. The UK government's Cyber Security Breaches Survey 2025/2026 found that 43% of businesses had experienced a breach or attack in the previous 12 months, with phishing by far the most common type at 38%. In the FBI IC3 2025 Internet Crime Report, phishing and spoofing was the most-reported crime type, with 191,561 complaints.
The other cost is quieter: legitimate mail wrongly held. A lost tender reply triggers no alarm, but it is lost revenue all the same; a good policy manages both risks together. Do not confuse this with your own outgoing mail landing in other people's junk folders; that is a deliverability problem, covered in our guide to emails going to spam.
What an email quarantine policy should cover
The policy does not need to be long, but it must answer five questions clearly: what we hold, at what threshold, who can see and release it, how long it stays, and where decisions are recorded. The decision table below is a sensible starting point for most organisations.
| Message type | Typical signal | Recommended action | Who may release it |
|---|---|---|---|
| Spoofing your own domain | SPF/DKIM/DMARC fail, looks like an internal sender | Quarantine | Security lead only, with a written reason |
| Sender made to look like a known contact | Lookalike domain, international characters, display-name impersonation | Quarantine | Security lead, after out-of-band confirmation |
| Risky attachment | Macro-enabled document, executable, password-protected archive | Quarantine | IT only; end users cannot release |
| Payment or bank detail change | Reply-To mismatch, urgency, new account details | Quarantine or deliver with warning | Line manager, after a callback |
| Bulk marketing and newsletters | Bulk sending, unsubscribe link | Deliver to a separate folder | Not needed |
| Known contact, all checks clean | Authentication passes, prior correspondence | Deliver | Not needed |
Quarantine is a decision queue, not a bin. Marketing mail clogs the queue and hides real threats; it belongs in a separate folder via classification, as explained in our piece on AI email classification and triage.
The lookalike-sender and payment-change rows deserve particular care, because such messages often pass authentication. How attackers choose their domains is covered in lookalike domain attacks, and the payment diversion scenario in bank detail change email fraud.
Setting up your email quarantine policy in seven steps
- Take stock. Count what has landed in quarantine and junk over the past few weeks, by type. List who released what, and which legitimate senders are most often caught by mistake.
- Define categories and a threshold. Adapt the table above to your own suppliers and customers. Before changing a threshold, check how many messages it would affect; blind tuning is how you end up with a black hole or a formality.
- Separate the roles. Grant viewing, releasing and deleting as distinct permissions. On shared mailboxes, quarantine rights should sit with named people only; the permission model for team addresses is set out in our guide to shared mailbox management, and delegated access to personal mailboxes in mailbox permissions and delegation.
- Write a release rule. No message is released without a recorded reason. Where the sender is a business contact, confirm through a channel independent of the email, such as a phone number already on file, and make adding someone to a "trusted sender" list a separate approval.
- Set retention and notifications. Decide how long quarantined mail is kept and what happens at the end of that period, in line with your archiving and personal data retention rules. Tell users in plain language which message was held and why.
- Link it to incident response. If a released message later proves malicious, it should already be clear who is told, how other mail from the same sender is found and, where personal data is involved, how the 72-hour breach notification under Turkey's KVKK is assessed. KVKK is Turkey's personal data protection law, broadly comparable in spirit to the GDPR.
- Review monthly. Look at the number of legitimate messages wrongly held, the suspicious ones that reached inboxes, and the reasons given for releases. Adjust thresholds and categories on that evidence; a policy is not written once and shelved.
Add real quarantine examples to your security awareness training programme so staff learn to read "why is this held?". For controls beyond email, see our SME cyber security checklist.
Rules or scores?
There are two basic ways to make a quarantine decision: fixed rules (for example, "executable attachments are always held") and a confidence score built from several signals. Rules are predictable and easy to explain; a score catches signals that are weak on their own but telling in combination. A sound policy uses both, a balance we discuss more generally in AI versus rule-based automation.
How we handle this at Digital Bridge
We treat a quarantine policy as a business process, not a product setting:
- Discovery and needs analysis. As part of our cyber security consultancy, we review your current email platform, domain records, quarantine and junk behaviour, and the permission structure of shared mailboxes. We identify, with real examples, which legitimate senders are being caught and which risky messages are getting through.
- Writing the policy. We build the decision table with you around your own contacts, departments and approval chain. Retention and record-keeping rules are aligned with the work done under our data protection compliance service.
- Pilot. We trial the policy in a single department first, usually finance or purchasing, measure false positives and misses, and tune the threshold accordingly.
- Migration and integration. If you are moving to a new email platform, we plan the migration, DNS changes and cut-over through our cloud migration and infrastructure consultancy.
We do not recommend an approach that ties you to a single provider; the policy can be applied on your existing platform. If you are reviewing your provider anyway, add quarantine management to your business email selection criteria.
How quarantine works in SmartMail
SmartMail, the business email product in our own Smart360 family, provides the technical side of the policy above out of the box. Every inbound message is assessed against 12 signals: its own SPF/DKIM/DMARC and PTR checks, lookalike domains and international characters, display-name and brand impersonation, Reply-To and link mismatches, risky attachments, content assessment and comparison with known fraud techniques. The outcome is a report with written reasons, so whoever reviews a held message does not have to guess why it is there.
The organisation sets the quarantine threshold; the default confidence threshold is 70, and before you change it SmartMail shows how many messages the change would affect. That is step two's "no blind tuning" principle built into the product. Authentication and domain checks run in software and keep working even when the AI usage allowance is used up.
Each mailbox has nine separate permissions; quarantine management is one of them and, like delete, is off by default on new assignments. Access to a shared mailbox therefore does not mean the right to release its quarantine. Every message carries an action history, an audit log is kept, and access is removed automatically when someone leaves a department. Remote image protection also stops images from loading until they are allowed.
A concrete scenario: purchasing receives a "latest price list" with a macro-enabled attachment from a domain one letter away from a regular supplier's. The message is held, and the report cites the lookalike domain and the risky attachment. The purchasing lead, who holds quarantine rights, rings the supplier on the number on file; if the attachment is not genuine, the message is not released and the incident response process from step six begins.
Next step
The first step needs no software: list the messages released from quarantine in the past month, who released them and why. That list will show the gaps in your policy straight away. Then get in touch; we will draft your decision table with you and demonstrate SmartMail's quarantine report in an environment set up with your own domain. For more on email security, browse our Business Email & Documents hub.