By specifying "Replace infected/suspicious body or attachment(s)" it allows the body of the email to be delivered to the intended recipient without the malicious attachments,so it will remove the infected attachment with a replacement message.
It is a prebuild feature in Fortimail that cannot be removed. It can only be edited. I checked the CLI reference under customized-messages and there is no delete command. I tested it also in different firmware versions.
Thank you for your informations, gfleming. The CDR attachment setting document says 'Attachment handling for deferred email'. What's exactly mean 'deferred email' ? Is a email that was queued by network or any troubles? Or, is a email which was queued by spam or virus outbreak? And, Is it able to be triggered by 'Content Monitor and Filtering'?
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.