Verification of Email Before Decryption

This article describes how to turn on digest validity check which applies to email body and which limitations do apply.

About this task

For this, the eperi sEcure Platform stores a hash of message body and compares it with the outbound message to be decrypted via Milter and its creation date. If either is out of range (can be adjusted via Advanced Settings), the message is not decrypted and delivery will eventually fail.

Procedure

Switch on Use message digest for mails under Settings for eperi sEcure Platform (platform).
Note: Limitations: RTF mails are not supported (RTF emails should be disabled organization-wide. If they should be processed nonetheless, please activate manually under Settings for eperi sEcure Platform (platform) -> Disable message digest for HTML mails converted from RTF)
Note: If mail cannot be sent after two days, delivery will consequently fail for the rest of the time as the digest loses its validity after this time frame -> can be adjusted under Settings for eperi sEcure Platform (platform): Message digest validity period

Warning: If the feature is activated, an outbound mail will not be sent, if the message digest over the mail body can not be verified. The message digest is generated over encrypted parts of incoming/created mails. If a mail server like Exchange Online modifies the mail, it may happen in rare cases, that a valid mail body can not be verfied and therefore will not be sent. Alternatively it's configurable that only a log message is written and the mail is sent even on verification error:

Switch on Send outbound mail if message digest for mail body can not be verified under Settings for eperi sEcure Platform (platform).

Results

You have successfully configured the verification of emails before encryption.