Email Attachment Protection

Dangerous Attachments.Automatically Sanitized.Safely Delivered.

Content Disarm & Reconstruction (CDR) removes macros, embedded malware, and hidden threats from email attachments before they reach your network.

Email Attachment Protection with Content Disarm and Reconstruction

Traditional antivirus solutions only detect known threats. Conbool MailGuard uses CDR technology to proactively remove malicious content from file attachments without relying on signatures or heuristics. Every file is deconstructed, sanitized, and securely reconstructed.

Threats from Email Attachments

Malicious Macros

Macros in Office documents are one of the most common entry points for cyberattacks. Attackers use VBA macros to execute malicious code as soon as a document is opened, often without the recipient's knowledge.

Embedded Malware

Malware can be deeply embedded in file formats such as PDF, DOCX, or XLSX. These threats frequently bypass signature-based scanners and only become active when the file is opened on the target system.

Archive Bombs & Nested Archives

Compressed files with extreme nesting or enormous decompression sizes can overwhelm security systems. Attackers hide malware in ZIP-within-ZIP structures that many scanners cannot fully analyze.

Conbool MailGuard CDR Features

Comprehensive protection through file-based threat defense, from analysis to secure delivery.

CDR Engine

Our Content Disarm & Reconstruction engine deconstructs every file into its components, removes potentially harmful elements, and reconstructs a safe version without compromising file usability.

Deep File Inspection

In-depth analysis of file structures detects hidden threats, embedded objects, and anomalies that conventional scanners miss. Every layer of a document is examined.

Macro Removal

VBA macros, ActiveX controls, and embedded scripts are automatically removed from Office documents. The visible content of the document remains fully intact.

Clean File Delivery

After sanitization, a safe, functional version of the file is delivered to the recipient. Formatting, images, and text content remain unchanged. Only the threat is removed.

Multi-Format Support

Support for over 100 file formats: Office documents (DOCX, XLSX, PPTX), PDFs, images, archives (ZIP, RAR, 7z), and many more. Each format is analyzed and sanitized format-specifically.

Real-Time Processing

The entire CDR process runs in real time with no noticeable delay in email delivery. Employees receive sanitized attachments within seconds.

Why Antivirus Alone Is Not Enough

Signature-based scanners detect what is known. Sanitisation does not ask about being known: it removes the executable parts of a document, whether or not the payload is known.

Proactive Instead of Reactive

Sanitisation waits for no signature update. It applies to the formats it supports: Office in both generations, PDF, HTML and the contents of ZIP archives. A macro removed there runs nowhere any more, known or not.

No False Negatives

While signature-based scanners can miss new malware variants, CDR fundamentally removes all active content. What is not in the file cannot cause damage.

File Functionality Preserved

Unlike restrictive blocking rules, CDR delivers a usable file. Formatting, text, and images remain intact. Only potentially harmful elements are removed.

Protection Against Obfuscated Attacks

Attackers disguise malware through obfuscation, encryption, and nested archives. CDR deconstructs every file down to the component level and eliminates hidden threats.

FAQ

What is Content Disarm and Reconstruction (CDR)?
CDR deconstructs a file into its components, removes macros, embedded scripts and active content, and reassembles the file. The difference from signature scanning is the question asked: the scanner asks "do I know this?", sanitisation asks "can this be executed?". That is why it also covers unknown payloads. In exchange it only applies to the formats it supports, and it detects nothing: it removes.
Which file types does Conbool MailGuard CDR support?
Conbool MailGuard CDR supports over 100 file formats, including Microsoft Office (DOCX, XLSX, PPTX), PDFs, image files (JPG, PNG, BMP), archives (ZIP, RAR, 7z, TAR), and many more. Support is continuously expanded to cover new file formats.
Does CDR damage or alter sanitized files?
No. Conbool MailGuard's CDR technology is designed to remove only potentially harmful elements. The visible content, including text, formatting, images, and layouts, remains fully preserved. Recipients receive a functional, safe file.
How fast is CDR processing?
Processing occurs in real time and typically takes only a few seconds per file. Emails with attachments are delivered without noticeable delay, ensuring your employees' workflow is not disrupted.
Can CDR process encrypted or password-protected attachments?
Password-protected archives and encrypted files cannot be directly processed by CDR since the content is inaccessible. Conbool MailGuard offers configurable policies for such cases: files can be quarantined, blocked, or delivered to the recipient with a warning.
Does CDR replace our existing antivirus protection?
The two approaches answer different questions and therefore complement each other. The signature scanner detects known payloads in any file type. Sanitisation removes the executable parts of the formats it supports, including unknown payloads. What sits in an unsupported format and has no signature is caught by neither: there is no detection guarantee.

Secure your email attachments — with Conbool MailGuard

Protect your business from file-based threats. Try Content Disarm & Reconstruction for free and experience how CDR takes your email security to the next level.