To Enable Zombie/Spyware protection we need to have "Email Anti-Virus Comprehensive" licensed on the Email security. For this configuration, all the outbound email traffic must be routed through the SonicWall Email security.
1. Login to the Email security as an admin.
2. Go to Manage | Security Services | Anti-virus | Outbound | Zombie Protection Settings
Unauthorized software running on a user's computer sending out junk email messages (spam, phishing attacks, virus or other unauthorized content) is called a Zombie or Spyware. SonicWall's Zombie and Spyware Protection technology brings the same high standard of threat protection available on the inbound email path to email messages leaving your organization by the outbound path.

Zombie Protection Settings
Enable Zombie and Spyware Protection to prevent potentially affected machines within your organization from sending spam, viruses, phishing attacks, spyware and other malicious content outside your organization (through your outbound email path).
Monitoring for Zombie and Spyware Activity
You can alert the administrator of potential zombie messages. Alerts are sent if these settings are defined:
Action Settings
If messages are being sent outside of your organization that are identified as spam, phishing attacks, virus, or another threat, select the action you want to take:
If messages are being sent outside of your organization but the sender is not listed in your LDAP server, select the action you want to take:
Enable the Outbound Safe Mode if you want to block all emails with potentially dangerous attachments from leaving your organization by checking the box for Safe Mode is on.
When Outbound Safe Mode is on, administrators are alerted every 60 minutes that it is on.
To set the action to take for dangerous attachments while in Safe Mode, select one of the following:
If you want to automatically turn on Outbound Safe Mode, set the parameters for turning it on:
Miscellaneous
You can manually add senders to a list so that the system will not flag messages sent from those email addresses. You can add any email addresses that are not in LDAP and any valid email addresses that are expected to send a high volume of legitimate email. Enter the addresses that should not trigger alerts or actions in the text box provided. Separate multiple addresses with a comma.
NOTE: If the navigation or the screenshot looks different from the one mentioned above , you may be in an older firmware version and would require a firmware upgrade. Please refer the link below to upgrade the firmware to latest version.
https://www.sonicwall.com/en-us/support/knowledge-base/170504270079039