Skip to main content
With the mandatory configuration done, we can now focus on additional configuration aspects that allow tuning xorlab Security Platform according to your needs.

Actions, rules and profiles

If you would like to change anything in the default behavior of Inbound Email Security or Abuse Mailbox Automation, have a look at Actions, Rules and Profiles. Common use cases are:
  • Tune xorlab Security Platform to be more (or less) aggressive with incoming malicious emails.
  • Enable or disable feedback emails.
  • Enable more auto-handling of reported emails.

Event logging

The logging support of xorlab Security Platform allows you to send logs of specific events to remote systems. As an example, you can write a JSON email summary to a remote destination whenever XSP processed an email. Or, you can write audit logs whenever a user changes configuration. If you want to activate certain logging now, please go to Logging. It will guide you through the process and provide some common logging configurations in the Common examples section.

User authentication

xorlab Security Platform comes with a predefined local user through which you can access the Control Center GUI. If you would like to:
  • add more local users, change their password or change their roles,
  • integrate LDAP for user authentication or
  • integrate SAML2 for user authentication with SSO,
you can have a look at the Authentication guide for more details and instructions. For a list of all possible user roles and permissions, visit Users, Roles, and Permissions.

Email addresses

Optionally, you can adjust the sender email address that xorlab Security Platform will use to send the following emails:
  • Feedback or acknowledgment emails.
  • Quarantine notification
  • Bounce messages.
To change the default values, follow the instructions in xorlab Security Platform Email Addresses.

Attachment Airlock and Request Release

You can further improve the SSQ (Self-Service Quarantine) by:
  • Enable Attachment Airlock for a safe analysis of password-protected attachments.
  • Enable Request Release to allow end-users to request emails to be released from their quarantine.

VirusTotal integration

If you want to enable VirusTotal integration, all you need to do is add your VirusTotal API key to the xcc.yml config as follows:
Please note: