Dispositions and attributes
Area 1 uses a variety of factors to determine whether a given email message, domain, URL, or packet is part of a phishing campaign. These small pattern assessments are dynamic in nature and — in many cases — no single pattern will determine the final verdict.
Based on these patterns, Area 1 may add
X-Headers to each email message that passes through our system.
Any traffic that flows through Area 1 is given a final Disposition, which represents our evaluation of that specific message. Each message will only receive one disposition header so your organization can take clear and specific actions on different message types.
You can use disposition values when creating your quarantine policy or setting up auto-retract.
|Traffic invoked multiple phishing verdict triggers, met thresholds for bad behavior, and is associated with active campaigns.||Block|
|Traffic associated with phishing campaigns (and is under further analysis by our automated systems).||Research these messages internally to evaluate legitimacy.|
|Traffic associated with phishing campaigns that is either non-compliant with your email authentication policies (SPF, DKIM, DMARC) or has mismatching |
Envelope From and
Header From values.
|Block after investigating (can be triggered by third-party mail services).|
|Traffic associated with non-malicious, commercial campaigns.||Route to existing Spam quarantine folder.|
BULK (dashboard only)
|Traffic associated with Graymail, that fall in between the definitions of |
SUSPICIOUS. For example, a marketing email that intentionally obscures its unsubscribe link.
|Monitor or tag|
When Area 1 adds a disposition header to an email message, that header matches the following format:
Note that emails with a disposition of
SPAM will be tagged with
UCE (unsolicited commercial emails) in their headers:
Traffic that flows through Area 1 can also receive one or more Attributes, which indicate that a specific condition has been met.
|This message matches a value you have defined in your custom block list.|
|Alerts to mail from a newly registered domain. Formatted as yyyy-MM-dd HH:mm:ss ZZZ.|
|Alerts to mail with links pointing out to a newly registered domain. Formatted as yyyy-MM-dd HH:mm:ss ZZZ.|
|Email message is encrypted.|
|Email message contains an executable file.|
|Indicates that email address was contained in your business email compromise (BEC) list. Associated with |
When Area 1 adds a disposition header to an email message, that header matches the following format.