Warning Banners

For suspected (low confidence) email detections, the administrator can choose to allow the email to be delivered to the inbox. In such cases, Email Security allows to embed a warning banner in the email explaining the nature and potential risk to the end-users.

Note:

Warning banners are available only in Prevent (Inline) and Detect and Remediate modes.

Warning banners are generated based on these detection attributes:

  • Suspected phishing: This email contains elements that may indicate "Phishing" intent - aimed at tricking you to disclose private/financial information or even your credentials.

  • Encrypted Attachments: Be careful when opening this email. It is carrying an encrypted attachment - often used for evading virus scans. Make sure you trust this email before opening the attachment.

  • Password Protected Attachments: The email contains an attachment which is protected with a password. The user must provide password for the Anti-Malware engine to scan the attachment for malicious content.

To configure warning banners:

  1. Navigate to Policy.
  2. Open Threat Detection policy for the required SaaS.
  3. Select the workflow for which the banner has to be configured.
  4. To customize the banner (text, background color etc.), click the gear icon next to the workflow.
  5. Click Save and Apply.