Introduction
This document describes how to troubleshoot winmail.dat attachments on Cisco Email Security Appliance (ESA).
Background Information
This document also describes how either an Exchange Server administrator or end users can prevent the winmail.dat attachment from being sent to users on the internet when using the Microsoft Exchange Internet Mail Connector (IMC). Cisco ESA can classify this file as unscannable during antivirus scanning.
Microsoft Support explains that when a user sends email from Microsoft Exchange or Outlook in Rich Text Format (RTF), a winmail.dat attachment can be added for recipients whose email clients do not support that format. The file contains RTF message data and is not useful to recipients outside Microsoft Exchange environments.
Recipients who do not use Microsoft Outlook or another client that supports RTF can receive the winmail.dat file as an attachment because it carries the formatting information for the original message.
For more background information, see this Microsoft Support article:
Emails Sent from Outlook Arrive as 'winmail.dat' Attachment
Troubleshooting winmail.dat Attachments
The winmail.dat attachment is not useful to non-exchange clients. During antivirus scanning, Cisco ESA and Sophos can classify this file as unscannable. This behavior is not an error in ESA or Sophos. The file is marked as unscannable because of its original creation and encoding.
In order to prevent the winmail.dat attachment from being sent to users on the Internet, review this Microsoft Support article:
How message format affects email messages
For additional information about winmail.dat behavior and related scanning limitations, review this Sophos resource:
TNEF-encoded attachments cannot be decrypted
Related Information
Refer to these Cisco resources for additional product and support information: