Acting on Phishing Events
When a user reports a phishing email, the reported email is moved to the Deleted folder in the user's mailbox. If the phishing report is later declined, the email remains in the Deleted folder.
To review and investigate the phishing event:
-
To see reasons for the detection of an event as phishing, under Security Stack, click More Info for Anti-Phishing.
-
To investigate the header of the raw email, under Email Profile, click Show for Header from raw email.
-
To investigate the body of the raw email, under Email Profile, click Show for Show body from raw email.
-
To download the raw email, under Email Profile, click Download for Download this email.
-
To send the original email to the end-user, under Email Profile, click Send for Send Original Email.
Note:This option appears only when there are links that were re-written by the Click-Time Protection security engine.
-
To recheck the email for phishing, under Email Profile, click Recheck for Recheck email.
Filter emails similar to the event generated
To filter emails similar to the event generated:
Under Security Stack, select Similar Emails / Create Rules.
Under Filters, define the criteria for filtering the emails.
Click Search.
After filtering the emails, you can create Anti-Phishing Allow-List and Block-List. See Anti-Phishing Exceptions.
Report mis-classification of an event
To report mis-classification of an event:
-
Under Security Stack in the event profile, click Report mis-classification for Anti-Phishing.
-
Under Report this email as, select how you want to classify the event.
Legit Marketing Email
Clean Email
Spam
Phishing
-
Under How confident are you, select how confident you are about the classification you selected.
Not so sure
Medium confidence
High confidence
-
Click OK.