I am creating email security policy as per email security policy guideline of my organization. while creating policy we needs to understand needs of organization, current workflow and exceptional cases like if any hacker sends attachment from genuine domain like from gmail then email will not be blocked as gmail ip source and domain status is genuine, in this case email can be scanned by attachment file type and message body contains. Social Media emails,advertisements emails, sign petition emails etc are strictly prohibited so policy needs to be created to blocked these sorts of junk emails. Hence below are email security policy i have created on Barracuda Email Security Gateway and Advanced Threat Protection following theory,principle and recommendation from NIST Guidelines on Electronic Mail Security. Attachment Filtering Go to BLOCK/ACCEPT Menu > Click on Attachment Filtering - For inbound mail, add the attachment filename patterns you want to block, quarantine or ...