Question : I have noticed that there doesn’t seem to be a ‘deny’ action on the filter inbound or outbound. So the only action is to quarantine. Is there a way to ‘deny’ that I am overlooking?
Answer: That is correct. The equivalent of the ‘Deny’ function in Sentinel Messaging V2 is to ‘Quarantine’ then ‘Hide from Log’ or ‘Hide from logs for non-admin users’. This is Sentinel Messaging effectively removing all access to that quarantined mail. Sentinel Messaging will drop/deny connections at the PDR (reputation) level – Sentinel Messaging do not process email for filtering until it successfully passes this first check, so there wouldn’t be anything to show in the logs anyway at that point.