Overview
The Policy module is responsible for processing policy specifications. The main service can be enabled or disabled by clicking the main button Enable/Disable at the top of the page. When disabled, all settings will be ignored.
How a quota decision is taken
Before going through the single tabs it helps to know in which order they are consulted. A message is evaluated by four levels, from the highest priority to the lowest, and each level is only reached when the one above it did not match.
Access Control comes first and decides whether the message is accepted at all.
Quotas Override holds the rules you write yourself, on a source and a destination. They always take precedence over anything the automatic engine decides.
Quota members are the senders you assigned to a level by hand, without writing a full rule for them.
Automatic quota levels are the base layer of the engine, where every message that reached the bottom of the chain is evaluated.
Quotas
The Quotas section defines the limits on message count and, optionally, cumulative size over time. These settings establish the baseline thresholds for all quota enforcement.
General Settings
- Period Defines whether quota tracking is calculated on a daily basis or on an hourly basis.
- Response Message Defines the message returned to the sender when the quota threshold is exceeded.
- Action When the automatic threshold is reached, then a defer action is applied.
Automatic Quota
Enables or disables the adaptive quota engine. When enabled, the appliance automatically promotes or demotes users between quota levels based on their observed sending patterns.
How does it work?
The system looks at how people usually send email and sets the quota of each user on its own, so that administrators do not have to configure every case by hand. Rather than applying fixed rules, it keeps observing what users do and adjusts their limits accordingly.
The system evaluates the average outbound mail volume over the previous [15] days and moves users between levels as follows:
- Move up the user is promoted to the next level when the average outbound volume goes past a set share of the current quota;
- Move down the user is demoted to the previous level when the average outbound volume stays well below the current quota.
This keeps each user on a quota that reflects their normal behaviour, which reduces false positives while still protecting against outbound bursts.
What the flag does not do
Disabling Automatic Quota stops users from being promoted and demoted, but the levels themselves remain the base layer of the engine. Traffic that matches none of your Quotas Override rules is still evaluated by them. To keep manual limits only, see Keeping manual quotas only further down.
Quota levels
There are five predefined quota levels. The specification defines the following default daily quotas, with corresponding optional hourly values:
| Quota Level | Daily limit | Hourly limit |
| Normal | 100 | 10 |
| Above-Average | 200 | 20 |
| High | 500 | 50 |
| Very-High | 2000 | 200 |
| Massive | 5000 | 500 |
If hourly mode is used, the default hourly threshold is one tenth of the daily threshold. Administrators may also define cumulative size limits per level; by default, message size is unlimited.
Quota Members
In the Quota Members tab, the system will populate the table with all the users and their assigned quota (Only users with a quota level higher than "Normal" will be displayed). Also, administrators can manually assign a specific email address to a selected quota level. This manual assignment overrides the adaptive classification for that user and is suitable when a sender has a known business need that differs from the automatic baseline.
Quota Tracking
In the Quota Tracking page, the system will display all the tracked users and show how many messages a specific user has been tracked. You can filter out the records by performing a Search.
Quotas Override
In the Quotas Override tab, administrators can create advanced rules based on sender and destination criteria, similarly to the previous quota model. This section is intended for granular control and special policy requirements.
Rules are evaluated by their priority value, where a lower value takes precedence, and a rule can be marked as last so that no further policy is applied after it.
Keeping manual quotas only
This applies when you do not want the automatic quota levels at all, for example after an upgrade from 5.5 where every limit was defined by hand.
As described above, turning Automatic Quota off is not enough on its own, because the levels stay at the bottom of the chain and catch everything your rules did not match. To close the chain, add a final rule here that matches all the remaining traffic with a limit that can never be reached. The rule blocks nothing: it exists only so that no message reaches the automatic levels.
| Field | Value |
| Priority | 99, so the rule is last and no further policy is applied after it |
| Tracker | Sender user@domain |
| Period | 60 minutes |
| Message count | 999999 |
| Verdict | Defer |
| Source | default |
| Destination | default |
You do not need this rule if you are using the automatic levels and only want a different behaviour for a few senders. In that case your rules already take precedence, and everything else is handled by the engine.
The full procedure, including how to rebuild your previous policies from the migration report, is described in Migrate ATP configuration to Esg 5.6.
Access Control
In this last tab you can set the Access Control policies. Access Control is used to limit access to the service, either by reject or discarding (silently drop) messages received in the matching Policy context. In the table are displayed all the existing Access Control directives for each policy. You can filter out the records by performing a Search.