Quarantine entry points
Log on to the postmaster administrator account. There are two ways to access the quarantine:
From the mail management console
When you activate a new domain on Alibaba Mail, the main quarantine switch is enabled by default. You can then configure specific rules for the organization or user quarantine.
You must assign mailbox quarantine permissions to sub-administrators to allow them to access the feature from the management console. For more information about how to assign permissions to sub-administrators, see How to create a sub-administrator?.

From the mailbox page
The quarantine option appears on the mailbox page only after an administrator enables the user quarantine.

The postmaster account can manage two types of quarantines. You can switch between them in the upper-right corner.
Access the user quarantine
Access the organization quarantine
User Isolation Area
For more information, see How to use the mailbox quarantine as an employee?

The features for managing emails in the user quarantine are the same for the postmaster account and other employee accounts.
Organization quarantine
You can manage the entire domain, quarantined emails for all mailboxes in the domain, and employee authorizations.
Quarantined emails
Email data is retained for only 30 days.
You can manage quarantined emails for employees.
The organization quarantine includes a Recipient field in the filter criteria and search results. Before performing an operation, confirm the target recipient to avoid affecting other users' emails.

Pending emails
Emails marked for quarantine by the anti-spam gateway are moved to this section. From here, you can perform actions such as releasing or discarding them.
Processed emails
This section temporarily stores processed emails and displays statistics, such as Total Processed, Delivered (AI 0, Manual 0), and Filtered (AI 0, Manual 0).
Authorization management
This section lets you manage authorizations between employees.
In authorization management, you can view and edit the quarantine permissions that employee accounts grant to others.
Find the target mailbox and click Authorization Management in the Actions column.

You can specify an authorized account for an employee.

Special scenarios
Other accounts can be authorized to manage the postmaster account. However, this authorization only applies to the user quarantine and does not grant permission to manage the organization quarantine.
When another account manages the postmaster account, the authorization management option is hidden.
Quarantine rules
Quarantine rules are part of the anti-spam system. If a sender is on the quarantine blacklist, the anti-spam rule automatically deletes the email. This rule takes precedence over other email filtering rules.
The quarantine blacklists and whitelists are separate from the domain management blacklists and whitelists. These lists are independent of each other. For example, if an email is whitelisted in the quarantine, it is delivered directly to the inbox, even if it is on the domain management blacklist.
Blacklist
Emails from a blacklisted address, domain name, or IP address are automatically deleted. After deletion, the email is no longer visible to other users who can access the quarantine and will not be delivered to the recipient.
Click Add to Blacklist. In the window that appears, select Email Address, Domain, IP, or IP Segment. Enter the corresponding information and click OK.
To delete an entry from the blacklist, search for it using the filter criteria. Then, select the checkbox next to the entry that you want to permanently delete and click Delete.
Filter criteria
Enter the content to query.
Returned data
Email Address/Domain Name/IP, Operation
Whitelist
Emails from a whitelisted address, domain name, or IP address are delivered directly to the recipient.

Custom rules
Four actions are supported: Quarantine, Release, Reject, and Discard. Rules are executed in order of priority, where a smaller number indicates a higher priority. Rule processing stops after the first match.

Available conditions:
Sender
Recipient
The email size range is
Contains keyword
Email contains attachment
Applies to all emails
You can add up to 10 conditions.
After a non-displayed, server-side anti-spam rule is triggered, the quarantine's custom rules are applied for filtering. These custom rules have a higher priority than domain management rules or user rules.
If a custom quarantine rule is triggered and the action is set to **Quarantine**, the email is moved to both the organization and user quarantines by default. If the AI scan feature is enabled, the final result is determined by the AI scan.

Actions to perform:
Quarantine: Move the email to the quarantine for administrator review.
Release: Allow the email to be delivered to the inbox.
Reject: Reject the email and send a bounce email notification.
Discard: Deletes the email. Unlike a manual discard, an email discarded by a rule does not appear in the processed emails list, and the sender does not receive a bounce email notification.

Quarantine log query
To check if an email has entered the quarantine, go to Behavior Query > Email Log Query > Inbound Email Query. Alternatively, you can go directly to the quarantine to check the quarantine records.
The time range for a single query is limited to 30 days. You can query data from the last 180 days.
