Configure allowed Mailbox Exchange attachment extensions
Define the normal allow-list.
Exact navigationAdmin Area → Mailbox Exchange → Settings
What this guide covers
Define the normal allow-list. The workflow below follows the supported application or module flow and does not invent a menu or bypass validation.
Exact step-by-step process
- Open the exact navigation path shown above.
- Select the authorised mailbox, message or configuration record.
- Complete the fields or action described in this guide.
- Save or submit once, then verify the resulting status and related record.
Fields, choices and supported possibilities
- Comma-separated extensions
Code-backed validations and workflow rules
- Input is lowercased and spaces are removed.
- Blank restores pdf,jpg,jpeg,png,doc,docx,xls,xlsx,txt,zip.
- The separate security deny-list still blocks executable/script/web/configuration types.
Expected result and verification
- The requested Mailbox Exchange record is updated through the supported controller and remains attributable to the acting staff member.
Security, audit and troubleshooting checks
- Use the exact authorised account, role and record before saving or sending.
- Verify the saved status and downstream record; a browser success message alone is not sufficient evidence.
- Never expose passwords, API keys, access tokens, protected attachments or raw server paths in support tickets.
- Do not edit module or core database records directly to bypass validation, permissions, migrations or state rules.
