1. Zen IT Technologies
  2. Technical notes
  3. Quarantine is a queue, not custody

Quarantine is a queue, not custody

Jonny Flaks, Founder & Principal Architect

Technical note in Email Security

A DLP or mail-security rule is configured to hold a message for review. The interface offers an obvious action: Quarantine.

It sounds like exactly what is needed. Maybe it is. But a quarantine designed for suspicious inbound mail is not automatically a suitable custody and review system for sensitive business communication.

Before using it that way, find out what the word hold actually means.

Holding a message creates responsibility

Once a system deliberately interrupts delivery, somebody owns a decision. That decision may be:

  • Release it.
  • Block it.
  • Escalate it.
  • Ask somebody who understands the content.
  • Or do nothing.

The last option is still a decision if the platform eventually deletes the message. A useful review workflow therefore needs more than a queue. You need to know how long the message survives, who can act on it, what gets logged, what the user sees and what happens when the message leaves the queue.

Quarantine is not an archive

Most quarantine systems have retention limits. Those limits vary by product, policy and message type. The important point is not whether the number is 15 days, 30 days or something configurable.

It is that a quarantine is usually temporary storage. If the retention period ends, the message may be permanently removed rather than preserved as a business record.

That can be completely appropriate for spam. It deserves more thought when the message was held because it contained sensitive company information. Before relying on quarantine as custody, know what expiry means.

Find out what “review” really provides

Products expose very different review models.

  • Can the original recipient release the message?
  • Can they only request release?
  • Does an administrator approve the request?
  • Can another reviewer verify a decision?
  • Can the security team see why the message was held?
  • Are the actions recorded in an audit log?
  • Can the decision be reversed?

There is no universal right answer. There should be a known answer.

A review process where every message is immediately released unread is not meaningfully safer than delivery. It just adds a queue.

Check what the sender thinks happened

Outbound holds add another problem. The user's experience may not clearly communicate that delivery was interrupted. Depending on the product and mail path, the message may appear to have been sent normally from the user's point of view even though it is waiting elsewhere.

That creates a dangerous gap: The sender thinks the recipient has the message. The recipient has nothing.

This is not something to infer from the administrator interface. Test it from the sender's mailbox.

Release is another mail-flow event

In a simple architecture, releasing a message may be straightforward. In a more complex design involving routing rules, DLP services or external gateways, you need to know where the released message re-enters the delivery path.

  • Could the routing rule see it again?
  • Could it return to the inspection service?
  • Does the inspection product mark the message so it bypasses another pass?
  • Does release happen before or after a particular control?

These behaviors vary. That is why release needs a real end-to-end test rather than an assumption.

Choose the hold point deliberately

Sometimes the native mail platform is the right place to hold a message. Sometimes the inspection or DLP platform has the stronger incident and review workflow. Compare them based on actual capabilities:

  • Retention.
  • Audit history.
  • Reviewer roles.
  • User notifications.
  • Approval options.
  • Evidence available to the reviewer.
  • Release behavior.
  • Failure behavior.

The button called Quarantine should not make the architecture decision for you.

Monitor mode is sometimes the safer first step

During a new DLP rollout, blocking is not always the correct first action. Where the risk allows it, detecting and recording policy hits while mail continues can give you the evidence needed to understand false positives and real business behavior.

Once the rule is understood, enforcement can become deliberate. A badly understood quarantine does not become safe because it feels more cautious than monitor mode.

The check worth running

Create one synthetic message that deliberately triggers the rule. Then follow it all the way through.

  • Check what the sender sees.
  • Check who receives the alert.
  • Check who can release it.
  • Check how long it will remain there.
  • Release it and verify where it goes.

If you cannot explain every step, you do not yet have a review workflow. You have a queue.

Explore this expertise: Email Security

All technical notes