Phone: 0 (552) 380 25 25  |  Weekdays 10:00–18:00 · Technical support 24/7

🇹🇷 TR

Digital Bridge Blog

Business Email & Documents

Email Quarantine Policy: Who Reviews Suspicious Mail, Who Can Release It, and How Every Decision Is Logged

An email quarantine policy sets which messages are held, who may release them and how each decision is logged. A decision table and seven steps to set it up.

9 min read  · Digital Bridge Engineering Team
Email Quarantine Policy: Who Reviews Suspicious Mail, Who Can Release It, and How Every Decision Is Logged

An email quarantine policy is the set of written rules that decides which inbound messages are held back, at what risk threshold, who may review and release them, how long they are kept and how each decision is recorded. Quarantine itself is the restricted holding area; the policy is what makes it a control rather than a dumping ground.

Why quarantine so often fails

In many companies quarantine is either a black hole, where customer orders, e-invoice notifications and tender replies pile up unseen, or a formality that lets almost everything through. Once staff discover the black hole, they ask IT to "just release everything addressed to me", and the control quietly disappears.

In the loose version, a targeted phishing email or a supplier impersonation goes straight to the finance team. Both failures share a root cause: a technical setting with no policy or owner behind it. If every user can release their own quarantined mail, the attacker only ever has to convince the recipient.

DMARC quarantine is not inbound quarantine

The two are easily confused. The p=quarantine tag in your DMARC record tells other people's mail servers what to do with messages that claim to come from your domain but fail authentication; it protects your reputation and your contacts. We cover that side in our SPF, DKIM and DMARC guide. This article is about the opposite direction: which messages arriving at your organisation you hold back, on what grounds and under whose control.

The cost of running quarantine without a policy

Quarantine is often where email-borne attacks are first stopped, and what filters hold back is far more than nuisance spam. According to the Verizon 2026 Data Breach Investigations Report, of the attacks blocked by email security gateways, 80% were plain phishing, 10% carried malware, 5% tried to get the victim to phone the attacker and 3% were BEC-style attempts to get a bank account updated before a wire transfer. Releasing one of those without a reason undoes the filter's work in a single click.

How widespread the threat is gives another reason quarantine cannot be managed ad hoc:

According to ENISA's Threat Landscape 2025, phishing, including vishing, malspam and malvertising, was the leading initial intrusion vector in the incidents analysed in Europe, at about 60%. (ENISA Threat Landscape 2025)

Smaller businesses are not spared. The UK government's Cyber Security Breaches Survey 2025/2026 found that 43% of businesses had experienced a breach or attack in the previous 12 months, with phishing by far the most common type at 38%. In the FBI IC3 2025 Internet Crime Report, phishing and spoofing was the most-reported crime type, with 191,561 complaints.

The other cost is quieter: legitimate mail wrongly held. A lost tender reply triggers no alarm, but it is lost revenue all the same; a good policy manages both risks together. Do not confuse this with your own outgoing mail landing in other people's junk folders; that is a deliverability problem, covered in our guide to emails going to spam.

What an email quarantine policy should cover

The policy does not need to be long, but it must answer five questions clearly: what we hold, at what threshold, who can see and release it, how long it stays, and where decisions are recorded. The decision table below is a sensible starting point for most organisations.

Message typeTypical signalRecommended actionWho may release it
Spoofing your own domainSPF/DKIM/DMARC fail, looks like an internal senderQuarantineSecurity lead only, with a written reason
Sender made to look like a known contactLookalike domain, international characters, display-name impersonationQuarantineSecurity lead, after out-of-band confirmation
Risky attachmentMacro-enabled document, executable, password-protected archiveQuarantineIT only; end users cannot release
Payment or bank detail changeReply-To mismatch, urgency, new account detailsQuarantine or deliver with warningLine manager, after a callback
Bulk marketing and newslettersBulk sending, unsubscribe linkDeliver to a separate folderNot needed
Known contact, all checks cleanAuthentication passes, prior correspondenceDeliverNot needed

Quarantine is a decision queue, not a bin. Marketing mail clogs the queue and hides real threats; it belongs in a separate folder via classification, as explained in our piece on AI email classification and triage.

The lookalike-sender and payment-change rows deserve particular care, because such messages often pass authentication. How attackers choose their domains is covered in lookalike domain attacks, and the payment diversion scenario in bank detail change email fraud.

Setting up your email quarantine policy in seven steps

  1. Take stock. Count what has landed in quarantine and junk over the past few weeks, by type. List who released what, and which legitimate senders are most often caught by mistake.
  2. Define categories and a threshold. Adapt the table above to your own suppliers and customers. Before changing a threshold, check how many messages it would affect; blind tuning is how you end up with a black hole or a formality.
  3. Separate the roles. Grant viewing, releasing and deleting as distinct permissions. On shared mailboxes, quarantine rights should sit with named people only; the permission model for team addresses is set out in our guide to shared mailbox management, and delegated access to personal mailboxes in mailbox permissions and delegation.
  4. Write a release rule. No message is released without a recorded reason. Where the sender is a business contact, confirm through a channel independent of the email, such as a phone number already on file, and make adding someone to a "trusted sender" list a separate approval.
  5. Set retention and notifications. Decide how long quarantined mail is kept and what happens at the end of that period, in line with your archiving and personal data retention rules. Tell users in plain language which message was held and why.
  6. Link it to incident response. If a released message later proves malicious, it should already be clear who is told, how other mail from the same sender is found and, where personal data is involved, how the 72-hour breach notification under Turkey's KVKK is assessed. KVKK is Turkey's personal data protection law, broadly comparable in spirit to the GDPR.
  7. Review monthly. Look at the number of legitimate messages wrongly held, the suspicious ones that reached inboxes, and the reasons given for releases. Adjust thresholds and categories on that evidence; a policy is not written once and shelved.

Add real quarantine examples to your security awareness training programme so staff learn to read "why is this held?". For controls beyond email, see our SME cyber security checklist.

Rules or scores?

There are two basic ways to make a quarantine decision: fixed rules (for example, "executable attachments are always held") and a confidence score built from several signals. Rules are predictable and easy to explain; a score catches signals that are weak on their own but telling in combination. A sound policy uses both, a balance we discuss more generally in AI versus rule-based automation.

How we handle this at Digital Bridge

We treat a quarantine policy as a business process, not a product setting:

  • Discovery and needs analysis. As part of our cyber security consultancy, we review your current email platform, domain records, quarantine and junk behaviour, and the permission structure of shared mailboxes. We identify, with real examples, which legitimate senders are being caught and which risky messages are getting through.
  • Writing the policy. We build the decision table with you around your own contacts, departments and approval chain. Retention and record-keeping rules are aligned with the work done under our data protection compliance service.
  • Pilot. We trial the policy in a single department first, usually finance or purchasing, measure false positives and misses, and tune the threshold accordingly.
  • Migration and integration. If you are moving to a new email platform, we plan the migration, DNS changes and cut-over through our cloud migration and infrastructure consultancy.

We do not recommend an approach that ties you to a single provider; the policy can be applied on your existing platform. If you are reviewing your provider anyway, add quarantine management to your business email selection criteria.

How quarantine works in SmartMail

SmartMail, the business email product in our own Smart360 family, provides the technical side of the policy above out of the box. Every inbound message is assessed against 12 signals: its own SPF/DKIM/DMARC and PTR checks, lookalike domains and international characters, display-name and brand impersonation, Reply-To and link mismatches, risky attachments, content assessment and comparison with known fraud techniques. The outcome is a report with written reasons, so whoever reviews a held message does not have to guess why it is there.

The organisation sets the quarantine threshold; the default confidence threshold is 70, and before you change it SmartMail shows how many messages the change would affect. That is step two's "no blind tuning" principle built into the product. Authentication and domain checks run in software and keep working even when the AI usage allowance is used up.

Each mailbox has nine separate permissions; quarantine management is one of them and, like delete, is off by default on new assignments. Access to a shared mailbox therefore does not mean the right to release its quarantine. Every message carries an action history, an audit log is kept, and access is removed automatically when someone leaves a department. Remote image protection also stops images from loading until they are allowed.

A concrete scenario: purchasing receives a "latest price list" with a macro-enabled attachment from a domain one letter away from a regular supplier's. The message is held, and the report cites the lookalike domain and the risky attachment. The purchasing lead, who holds quarantine rights, rings the supplier on the number on file; if the attachment is not genuine, the message is not released and the incident response process from step six begins.

Next step

The first step needs no software: list the messages released from quarantine in the past month, who released them and why. That list will show the gaps in your policy straight away. Then get in touch; we will draft your decision table with you and demonstrate SmartMail's quarantine report in an environment set up with your own domain. For more on email security, browse our Business Email & Documents hub.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25
Questions we hear most often

Frequently Asked Questions

What is the difference between email quarantine and the junk folder?

The junk folder holds unwanted but usually harmless messages inside the user's own mailbox, and the user can open it freely. Quarantine holds messages judged to carry a security risk before they are delivered, with restricted access and restricted release rights. The quarantine policy decides which messages go where and who is responsible for reviewing the quarantine.

Should staff be able to release their own quarantined email?

For low-risk categories such as bulk marketing, that can be reasonable. For spoofed senders, risky attachments or messages about changing payment details, release rights should stay with named people. Otherwise the attacker only has to persuade the recipient, and quarantine effectively stops working as a control.

How long should quarantined messages be kept?

There is no single correct period. It should give reviewers a reasonable window and must not conflict with your archiving and personal data retention rules. What matters is that the period is written down, everyone knows what happens when it expires, and messages linked to an ongoing incident investigation are preserved rather than deleted automatically.

How often should the quarantine threshold be changed?

Adjust it based on measurement, not the calendar. A monthly review looks at how many legitimate messages were wrongly held and how many suspicious ones reached inboxes. Checking how many messages a change would affect before applying it avoids surprises such as a suddenly empty inbox or a wave of threats getting through.

Does a DMARC p=quarantine setting protect my inbound email?

Not directly. A DMARC policy tells receiving servers how to treat forged messages sent in your domain's name, so it protects your reputation and your contacts. Whether mail arriving at your organisation is quarantined depends on your own email platform's assessment and your internal quarantine policy. The two complement each other; neither replaces the other.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.