> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xorlab.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Pages under /latest/ document the current release. Paths that begin with a version number, for example /10.0/, are frozen snapshots of superseded releases kept for reference only — never present their instructions as current. If the reader's version is unknown, answer from /latest/ and say which version the answer describes.
> xorlab is deployed on-premises, hybrid, or as a cloud service, and integrates with either Microsoft 365 or on-premises mail infrastructure. Configuration steps often differ between these. State which deployment and integration mode an instruction applies to instead of presenting one as universal.
> Distinguish inline mode from monitoring mode when describing anything that acts on email. Monitoring mode observes a copy and cannot block or quarantine; inline mode routes mail through xorlab and can.
> Write the product name as lowercase 'xorlab'. Use the documented component names: xorlab Control Center (XCC), xorlab MTA, xorlab Sandbox (DANA), xorlab Natural Language Understanding (NLU). After the first mention, use the short forms XCC, MTA, Sandbox, and NLU. Do not use DANA as a standalone name for the Sandbox, but keep it where it is a literal string in configuration keys, container names, and hostnames.
> Do not invent configuration keys, rule parameters, list names, log properties, or API fields. If a value is not present in this documentation, say that it is not documented rather than guessing.

# Tags

xorlab Security Platform enriches records of a processed email with information it extracts from the email content, metadata, and existing email history. Enrichment happens in the form of *hashtags*. You can access the tag information in the record details or, if integrated, in your Security Information and Event Management (SIEM). Use [Search](/9.0/search) to find emails tagged with certain keywords or to aggregate similar emails (e.g., belonging to the same marketing or phishing campaign).

You can make xorlab Security Platform add custom tags (please see *[Custom Alerts](/9.0/custom-alerts)*) to the processed email records.

## Aggregation examples

`#inc #highrisk #untrusted #newsender #newdomain #exposedhvt`<br />
Aggregates all incoming emails from untrusted senders, from which we have not yet received any email, to a high-value target and which have a high-risk score and contain a link to a domain not yet observed in email communication.

`#inc #highrisk #untrusted #newsender #cloudstorage`<br />
Aggregates all incoming emails from untrusted senders, from which we have not yet received any email, which have a high-risk score and contain a link to a cloud storage service.

`#inc #highrisk #untrusted #newsender #shortenednolocalreputation`<br />
Aggregates all incoming emails from untrusted senders, from which we have not yet received any email, which have a high-risk score and contain a shortened link to a URL that has no significance to your organization.

`#inc #untrusted #newfiletype #exposedhvt`<br />
Aggregates all incoming emails from untrusted senders to a high-value target, which contain an attachment whose file type has never been observed in your organization’s email communication.

`#out #encryptedfile #untrusted`<br />
Aggregates all outgoing emails to untrusted recipients which contain an encrypted attachment.

`#inc #trusted #dangerousvbascript`<br />
Aggregates all incoming emails from trusted senders that contain a Microsoft Office document that contains a VBA script with high-risk functions.

`#pdf #cfiviolation`<br />
Aggregates all emails with a PDF attachment that triggered a control flow integrity violation during dynamic analysis.

## Tag reference

Here is a list of all keyword tags that are used to enrich email records.

### General classification tags

Use caution when using verdict classification tags in campaigns, as some of the tags are applied after the campaigns are evaluated (e.g. `#internal` and `#benign`). This can result in discrepancies between search queries that match emails and campaigns that modify email verdicts.

| Tag                                 | Description                                                                                                                                                                                                                                     |
| ----------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `#banner`                           | The email was delivered with a contextual banner                                                                                                                                                                                                |
| `#bec`                              | The email is classified as business email compromise (BEC)                                                                                                                                                                                      |
| `#benign`                           | The email is classified as benign                                                                                                                                                                                                               |
| `#bulk`                             | The email was sent from a bulk email sender                                                                                                                                                                                                     |
| `#crm`                              | The email was sent from a CRM service, e.g., Salesforce                                                                                                                                                                                         |
| `#eopmarkedspam`                    | The email was marked as spam by Microsoft Exchange Online Protection                                                                                                                                                                            |
| `#exploit`                          | At least one of the documents attached to the corresponding email record exploits a vulnerability in the host application                                                                                                                       |
| `#external`                         | The email was sent by someone who is not a member of your organization. No other classification matches. Not to be confused with `#ext`                                                                                                         |
| `#extortion`                        | The email is classified as extortion                                                                                                                                                                                                            |
| `#filter`                           | The email or one of its attachments violates either one of the built-in or custom security policies                                                                                                                                             |
| `#impersonation`                    | The sender of the email impersonates a known party. This could be an employee, a business partner, or a popular service                                                                                                                         |
| `#internal`                         | The email was sent by a member of your organization to one or more members of your organization. No other classification matches. Not to be confused with `#int`                                                                                |
| `#marketing`                        | The email is classified as email marketing                                                                                                                                                                                                      |
| `#malware`                          | The email contains malware.                                                                                                                                                                                                                     |
| `#newsletter`                       | The email is classified as a newsletter                                                                                                                                                                                                         |
| `#phishing` or `#potentialphishing` | The email is classified as phishing. With lower confidence, `#potentialphishing` is used                                                                                                                                                        |
| `#poll`                             | The email was sent from a poll service, e.g., Doodle                                                                                                                                                                                            |
| `#popular`                          | The sending organization is a popular brand, e.g., Amazon                                                                                                                                                                                       |
| `#potentialextortion`               | The email could be an attempt of extortion                                                                                                                                                                                                      |
| `#potentialfraud`                   | The reported email could be an attempt to defraud the recipient                                                                                                                                                                                 |
| `#simulation`                       | The email belongs to a simulated employee awareness campaign. Please refer to *[Phishing Simulation Tools](/9.0/phishing-simulation-tools)* to learn how to configure xorlab Security Platform to support your campaign tool                    |
| `#socialnetwork`                    | The email was sent from a social network service, e.g., LinkedIn                                                                                                                                                                                |
| `#spam`                             | The email is classified as spam                                                                                                                                                                                                                 |
| `#survey`                           | The email was sent from a survey service, e.g., SurveyMonkey                                                                                                                                                                                    |
| `#suspectedintphishing`             | The email could be an internal phishing attempt                                                                                                                                                                                                 |
| `#suspectedintextortion`            | The email looks like an internal extortion attempt                                                                                                                                                                                              |
| `#vipfraud`                         | The email is classified as a fraud attempt that appears to originate from the CEO or any other VIP in your organization. Please refer to *[VIP List](/9.0/vips)* for instructions on how to configure xorlab Security Platform to identify VIPs |

### Content classification tags

| Tag                         | Description                                                                                                                                 |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
| `#ahv`                      | A Swiss AHV (social security) number was found in the email or in one of the documents                                                      |
| `#alert`                    | Email alert (can have different reasons)                                                                                                    |
| `#blacklisted`              | A blacklisted object was found. This can be the sender, a file type, domain, or any other object that can be blacklisted                    |
| `#blacklistedexternal`      | A blacklisted object based on an external blacklist was found                                                                               |
| `#bodylt25words`            | The email body contains less than 25 words                                                                                                  |
| `#bodylt50words`            | The email body contains less than 50 words                                                                                                  |
| `#bodylt5words`             | The email body contains less than 5 words                                                                                                   |
| `#bodylt75words`            | The email body contains less than 75 words                                                                                                  |
| `#bodymadult`               | The email body exactly matches at least one adult (erotic) keyword                                                                          |
| `#bodymextortion`           | The email body exactly matches at least one extortion keyword                                                                               |
| `#bodymguardedemail`        | The email body matches (by regex) at least one guarded email address                                                                        |
| `#bodymkeyword`             | The email body exactly matches at least one phishing keyword                                                                                |
| `#bodymkeywords`            | The email body exactly matches multiple phishing keywords                                                                                   |
| `#bodympartner`             | The email body exactly matches at least one partner organization’s name                                                                     |
| `#bodympopular`             | The email body exactly matches at least one popular service                                                                                 |
| `#bodymspam`                | The email body exactly matches at least one spam keyword                                                                                    |
| `#bodymurgency`             | The email body exactly matches at least one urgency keyword                                                                                 |
| `#bodymvipfraud`            | The email body exactly matches at least one VIP fraud keyword                                                                               |
| `#bodystadult`              | The email body is similar to an adult (erotic) keyword                                                                                      |
| `#bodystspam`               | The email body consists of at least one word that is similar to (Levenstein match) a spam keyword                                           |
| `#bouncemessage`            | Looks like a bounce message                                                                                                                 |
| `#bulkahv`                  | A list of Swiss AHV (social security) numbers was found in the email or in one of the documents                                             |
| `#bulkccnumber`             | A list of credit card numbers was found in the email or in one of the documents                                                             |
| `#bulkiban`                 | A list of IBAN numbers was found in the email or in one of the documents                                                                    |
| `#bulksensitivedata`        | A list of sensitive data was found in the email or in one of the documents                                                                  |
| `#bulkswissaddress`         | A list of Swiss addresses was found in the email or in one of the documents                                                                 |
| `#bulkswissphone`           | A list of Swiss phone numbers was found in the email or in one of the documents                                                             |
| `#ccnumber`                 | A credit card number was found in the email or in one of the documents                                                                      |
| `#compliance`               | A compliance issue was found                                                                                                                |
| `#confidential`             | A document with classification confidential was found                                                                                       |
| `#cryptobitcoin`            | A potential bitcoin address was found                                                                                                       |
| `#cryptocurrency`           | A potential cryptocurrency address was found                                                                                                |
| `#cryptodash`               | A potential dash address was found                                                                                                          |
| `#cryptoethereum`           | A potential ethereum address was found                                                                                                      |
| `#cryptomonero`             | A potential monero address was found                                                                                                        |
| `#cryptoripple`             | A potential ripple address was found                                                                                                        |
| `#cryptozcash`              | A potential zcash address was found                                                                                                         |
| `#cve_2017_0199`            | A malware signature matched (specific CVE number)                                                                                           |
| `#cve_2017_8570`            | A malware signature matched (specific CVE number)                                                                                           |
| `#cve_2017_8759`            | A malware signature matched (specific CVE number)                                                                                           |
| `#cve_2018_0802`            | A malware signature matched (specific CVE number)                                                                                           |
| `#cve_2018_4878`            | A malware signature matched (specific CVE number)                                                                                           |
| `#cve_2023_23397`           | A malware signature matched (specific CVE number)                                                                                           |
| `#cve_2024_4367`            | A malware signature matched (specific CVE number)                                                                                           |
| `#cve_2025_8088`            | A malware signature matched (specific CVE number)                                                                                           |
| `#cve_2026_21509`           | A malware signature matched (specific CVE number)                                                                                           |
| `#dataloss`                 | A potential data loss issue was found (e.g., an encrypted file sent to a person not known to the organization)                              |
| `#emptymessage`             | The message body is empty                                                                                                                   |
| `#emptysubject`             | The email subject looks empty                                                                                                               |
| `#encrypted`                | The message looks encrypted                                                                                                                 |
| `#htmlinvisiblefont`        | HTML email uses invisible font                                                                                                              |
| `#htmlmessage`              | HTML message                                                                                                                                |
| `#htmlmostlyimage`          | HTML email consists of mostly an image                                                                                                      |
| `#htmlobfuscated`           | HTML message is obfuscated                                                                                                                  |
| `#htmlshortlinkimg`         | HTML message is short with an image link                                                                                                    |
| `#iban`                     | IBAN number found                                                                                                                           |
| `#largenumberindisplayname` | Display name contains a large number                                                                                                        |
| `#largenumberinsubject`     | Subject contains a large number                                                                                                             |
| `#lookslikespam`            | The email looks like spam (keywords)                                                                                                        |
| `#lotsofmoney`              | The email talks about lots of money                                                                                                         |
| `#nosubject`                | Email does not have a subject                                                                                                               |
| `#onionlink`                | Email contains link to the `.onion` domain (Tor)                                                                                            |
| `#privatekey`               | Email contains a private key                                                                                                                |
| `#pyzor`                    | Email hash matches Pyzor database                                                                                                           |
| `#qrcode`                   | Email contains a QR code                                                                                                                    |
| `#qrcodelink`               | Email contains a link extracted from a QR code                                                                                              |
| `#razor`                    | Email hash matches Razor database                                                                                                           |
| `#sensitivedata`            | Potentially sensitive data was found in the email body or within a file                                                                     |
| `#subjectobfuscated`        | Subject contains lots of punctuation characters. This hints at an attempt to bypass keyword detection                                       |
| `#subjectcemoji`            | Subject contains an emoji                                                                                                                   |
| `#subjectcguarded`          | Subject contains (fuzzy matches) a guarded name, i.e., the organization’s name                                                              |
| `#subjectminvoice`          | Subject exactly matches at least one of the invoice keywords                                                                                |
| `#subjectckeyword`          | Subject contains (fuzzy matches) a phishing keyword                                                                                         |
| `#subjectcpartner`          | Subject contains (fuzzy matches) a partner organization’s name                                                                              |
| `#subjectmpopular`          | Subject exactly matches at least one popular service                                                                                        |
| `#subjectmrecipient`        | Subject matches the local part of the recipient’s address                                                                                   |
| `#subjectmvipfraud`         | Subject exactly matches at least one VIP fraud keyword                                                                                      |
| `#subjectstkeyword`         | Subject is similar to a phishing keyword                                                                                                    |
| `#svgembeddingtag`          | SVG attachment contains embedded content, e.g. `<foreignObject>`, which may be used for obfuscation                                         |
| `#svgscript`                | SVG attachment that uses JavaScript                                                                                                         |
| `#swissaddress`             | A Swiss address was found in the email body or a file                                                                                       |
| `#swissphone`               | A Swiss phone number was found in the email body or a file                                                                                  |
| `#txtext`                   | Text extraction was performed on a file                                                                                                     |
| `#uppercase`                | Email content consists mostly of uppercase letters                                                                                          |
| `#whitelisted`              | A whitelisted object was found. This can be the sender, a file type or the file itself, domain, or any other object that can be whitelisted |
| `#zerowidthspace`           | A zerowidth whitespace character was found. This is used in malicious emails to bypass text analysis                                        |

### Attachment classification tags

| Tag                           | Description                                                                                                                                                                                                                                                                                                                                                               |
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `#activex`                    | ActiveX object in an Office document found                                                                                                                                                                                                                                                                                                                                |
| `#android`                    | Android file type found                                                                                                                                                                                                                                                                                                                                                   |
| `#archive`                    | Archive file type found                                                                                                                                                                                                                                                                                                                                                   |
| `#attachedinvoice`            | The email has a PDF invoice attached                                                                                                                                                                                                                                                                                                                                      |
| `#audio`                      | Audio file type found                                                                                                                                                                                                                                                                                                                                                     |
| `#cracked`                    | An encrypted file format was cracked                                                                                                                                                                                                                                                                                                                                      |
| `#dangerousfiletype`          | A potentially dangerous file type was found                                                                                                                                                                                                                                                                                                                               |
| `#dangerousvbascript`         | A potentially dangerous VBA script was found. This tag is placed when an office document contains a macro that can execute code, write to the filesystem and/or start a network activity like opening a link. Examples could be creating a new file or modifying the registry. Note that the tag is not set when the file type is whitelisted in xorlab Security Platform |
| `#dangerousxlmscript`         | A potentially dangerous XLM (Excel 4.0) script was found                                                                                                                                                                                                                                                                                                                  |
| `#dde`                        | An Office document using DDE was found                                                                                                                                                                                                                                                                                                                                    |
| `#dmarcreport`                | A DMARC report was found                                                                                                                                                                                                                                                                                                                                                  |
| `#document`                   | A document file format was found                                                                                                                                                                                                                                                                                                                                          |
| `#eicar`                      | EICAR file signature matched                                                                                                                                                                                                                                                                                                                                              |
| `#encryptedarchive`           | An encrypted archive was found                                                                                                                                                                                                                                                                                                                                            |
| `#encryptedfile`              | An encrypted file format was found                                                                                                                                                                                                                                                                                                                                        |
| `#encryptedoffice`            | An encrypted Office file was found                                                                                                                                                                                                                                                                                                                                        |
| `#excel`                      | An Excel file was found                                                                                                                                                                                                                                                                                                                                                   |
| `#excessivenesting`           | An archive with excessive nesting was found                                                                                                                                                                                                                                                                                                                               |
| `#excessivenrofentries`       | An archive with excessive number of entries was found                                                                                                                                                                                                                                                                                                                     |
| `#excessivesize`              | An archive with excessive file size was found                                                                                                                                                                                                                                                                                                                             |
| `#executable`                 | An executable file format was found                                                                                                                                                                                                                                                                                                                                       |
| `#extensionblacklisted`       | File extension is blacklisted                                                                                                                                                                                                                                                                                                                                             |
| `#extensionmismatch`          | File extension mismatch                                                                                                                                                                                                                                                                                                                                                   |
| `#externalole`                | An external OLE reference was found in an Office document                                                                                                                                                                                                                                                                                                                 |
| `#extractioncountexceeded`    | Number of files extracted exceeded maximum threshold                                                                                                                                                                                                                                                                                                                      |
| `#file`                       | The email has a file attached                                                                                                                                                                                                                                                                                                                                             |
| `#fileblacklisted`            | File hash is blacklisted                                                                                                                                                                                                                                                                                                                                                  |
| `#filecontentmpopular`        | The content of the attached file exactly matches at least one popular service                                                                                                                                                                                                                                                                                             |
| `#fileoutblacklisted`         | File format output is blacklisted                                                                                                                                                                                                                                                                                                                                         |
| `#filetypenoreputation`       | File type has no reputation (never seen in trusted communication)                                                                                                                                                                                                                                                                                                         |
| `#flash`                      | Flash object or file found                                                                                                                                                                                                                                                                                                                                                |
| `#html`                       | HTML attachment found                                                                                                                                                                                                                                                                                                                                                     |
| `#htmldataurl`                | HTML attachment contains data URL, which can be used to embed content                                                                                                                                                                                                                                                                                                     |
| `#htmldownload`               | HTML attachment contains a downloadable file                                                                                                                                                                                                                                                                                                                              |
| `#htmlembeddingtag`           | HTML attachment contains embedded content, e.g., iframes, which may be used for obfuscation                                                                                                                                                                                                                                                                               |
| `#htmlredirect`               | HTML attachment contains a redirect to another page, which may be used for obfuscation                                                                                                                                                                                                                                                                                    |
| `#htmlscriptcharacterescapes` | HTML attachment contains JavaScript that uses a suspicious number of escape characters, which may be used for obfuscation                                                                                                                                                                                                                                                 |
| `#htmlscriptdocrewrite`       | HTML attachment contains JavaScript that rewrites itself, which can be used for obfuscation                                                                                                                                                                                                                                                                               |
| `#htmlscriptdownload`         | HTML attachment contains JavaScript with a download attribute to get a payload                                                                                                                                                                                                                                                                                            |
| `#htmlscriptdecode`           | HTML attachment contains JavaScript that uses decoding functions, which can be used for obfuscation                                                                                                                                                                                                                                                                       |
| `#htmlscriptencodeddata`      | HTML attachment contains JavaScript with encoded data, which can be used for obfuscation                                                                                                                                                                                                                                                                                  |
| `#htmlscriptpayload`          | HTML attachment contains JavaScript that constructs a downloadable payload                                                                                                                                                                                                                                                                                                |
| `#htmlwithform`               | HTML attachment contains a form tag                                                                                                                                                                                                                                                                                                                                       |
| `#htmlwithscript`             | HTML attachment contains a script tag                                                                                                                                                                                                                                                                                                                                     |
| `#image`                      | Image file format found                                                                                                                                                                                                                                                                                                                                                   |
| `#ios`                        | iOS file format found                                                                                                                                                                                                                                                                                                                                                     |
| `#iso`                        | ISO file format found                                                                                                                                                                                                                                                                                                                                                     |
| `#largeimage`                 | An image larger than 1 MB was found                                                                                                                                                                                                                                                                                                                                       |
| `#legacyarchive`              | A legacy archive format was found (rar, ace, etc.)                                                                                                                                                                                                                                                                                                                        |
| `#macos`                      | A macOS file type was found                                                                                                                                                                                                                                                                                                                                               |
| `#macrofilewhitelisted`       | A whitelisted Office macro file was found                                                                                                                                                                                                                                                                                                                                 |
| `#media`                      | Media file type found                                                                                                                                                                                                                                                                                                                                                     |
| `#newfiletype`                | Never seen before file type found                                                                                                                                                                                                                                                                                                                                         |
| `#office`                     | Office file format found                                                                                                                                                                                                                                                                                                                                                  |
| `#officeframe`                | Office file uses external frames                                                                                                                                                                                                                                                                                                                                          |
| `#officewebvideo`             | Office file uses external web video                                                                                                                                                                                                                                                                                                                                       |
| `#onlymediafiles`             | All attachments are media files                                                                                                                                                                                                                                                                                                                                           |
| `#ole`                        | OLE object in office file found                                                                                                                                                                                                                                                                                                                                           |
| `#pdf`                        | PDF file format found                                                                                                                                                                                                                                                                                                                                                     |
| `#pdfanalysiserror`           | Error during PDF static analysis occurred                                                                                                                                                                                                                                                                                                                                 |
| `#powerpoint`                 | Powerpoint file format found                                                                                                                                                                                                                                                                                                                                              |
| `#rtf`                        | RTF file format was found                                                                                                                                                                                                                                                                                                                                                 |
| `#rtfwithembeddedobject`      | The RTF file contains an embedded object                                                                                                                                                                                                                                                                                                                                  |
| `#script`                     | A script file format was found                                                                                                                                                                                                                                                                                                                                            |
| `#shortcut`                   | Shortcut file format was found                                                                                                                                                                                                                                                                                                                                            |
| `#unix`                       | Unix file type found                                                                                                                                                                                                                                                                                                                                                      |
| `#vbascript`                  | VBA script found                                                                                                                                                                                                                                                                                                                                                          |
| `#video`                      | Video file type found                                                                                                                                                                                                                                                                                                                                                     |
| `#xlmscript`                  | XLM (Excel 4.0) script found                                                                                                                                                                                                                                                                                                                                              |
| `#whitelisted`                | A whitelisted object was found. This can be the sender, a file type or file itself, domain, or any other object that can be whitelisted                                                                                                                                                                                                                                   |
| `#windows`                    | Windows file type found                                                                                                                                                                                                                                                                                                                                                   |
| `#word`                       | Word file found                                                                                                                                                                                                                                                                                                                                                           |

### URL classification tags

| Tag                            | Description                                                                                                              |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------------ |
| `#15daysold`                   | A 15-day-old domain was found                                                                                            |
| `#180daysold`                  | A 180-day-old domain was found                                                                                           |
| `#1dayold`                     | A 1-day-old domain was found                                                                                             |
| `#30daysold`                   | A 30-day-old domain was found                                                                                            |
| `#365daysold`                  | A 365-day-old domain was found                                                                                           |
| `#5daysold`                    | A 5-day-old domain was found                                                                                             |
| `#90daysold`                   | A 90-day-old domain was found                                                                                            |
| `#badreputation`               | A link with bad reputation was found                                                                                     |
| `#blacklisted`                 | A blacklisted object was found. This can be the sender, a file type, domain, or any other object that can be blacklisted |
| `#cloudstorage`                | A cloud storage link was found                                                                                           |
| `#cmslink`                     | Link points to a CMS resource                                                                                            |
| `#contains`                    | One or more XcY tags (*X contains Y*) are present, e.g., `#displaynamecguarded`                                          |
| `#dangerousfiletypeinpath`     | The path of a link contains a potentially dangerous file type                                                            |
| `#displaytextmkeyword`         | The display text of a link contains a phishing keyword                                                                   |
| `#displaytextmspam`            | The display text of a link contains a spam keyword                                                                       |
| `#doclink`                     | A document contains links                                                                                                |
| `#domaincguarded`              | Domain contains (fuzzy matches) a guarded name, i.e., the organization’s name                                            |
| `#domainckeyword`              | Domain contains (fuzzy matches) a phishing keyword                                                                       |
| `#domaincpartner`              | Domain contains (fuzzy matches) a partner organization’s name                                                            |
| `#domainstguarded`             | Domain is similar to the organization’s name                                                                             |
| `#domainstpartner`             | Domain is similar to a partner’s name                                                                                    |
| `#doubleshortened`             | Double shortened link found (shortener pointing to another shortener)                                                    |
| `#eachlinkmfrom`               | All link domains match sender’s email domain                                                                             |
| `#eachlinknonreputable`        | All link domains have neither a local nor global reputation                                                              |
| `#eachlinkreputable`           | All link domains have a global or local reputation                                                                       |
| `#embeddedlink`                | A potential embedded URL was found (in another URL)                                                                      |
| `#emotet`                      | Typical Emotet structured link was found (possibly hosting malicious content)                                            |
| `#guardeddomaininurl`          | Guarded tenant domain in URL found                                                                                       |
| `#guardednameinurl`            | Guarded tenant name in URL found                                                                                         |
| `#idn`                         | A domain with a suspicious IDN character was found                                                                       |
| `#iphost`                      | A link with an IP as host was found                                                                                      |
| `#link`                        | A link was found in the email                                                                                            |
| `#linkblacklisted`             | A blacklisted link was found                                                                                             |
| `#linkblacklistedexternal`     | A blacklisted link based on an external blacklist was found                                                              |
| `#linkckeyword`                | Email contains a link which has a `PATH` or `QUERY` part containing (fuzzy matching) a phishing keyword                  |
| `#linkmfrom`                   | Email contains a link with a domain matching the sender’s email domain                                                   |
| `#linkmismatch`                | A link display name mismatch was found                                                                                   |
| `#linkwithpathnolocalrep`      | Email contains a link with no local reputation and having a `PATH` or `QUERY` part                                       |
| `#matches`                     | One of the XmY rules matched, i.e., the organization’s name or a keyword, etc., matched a relevant string                |
| `#mismatchnolocalreputation`   | Link display name mismatches actual link and the actual link has no local reputation                                     |
| `#mismatchnoreputation`        | Link display name mismatches actual link and the actual link has no global reputation                                    |
| `#newdomain`                   | Never seen before domain found                                                                                           |
| `#newtld`                      | Never seen before TLD found                                                                                              |
| `#noimgsrcreputation`          | Email contains remote image sources and none of these have global or local reputation                                    |
| `#nolocalreputation`           | Email contains a link with a domain with no local reputation                                                             |
| `#noreputation`                | Email contains a link with a domain with no global and no local reputation                                               |
| `#onecommonphishinglink`       | Email contains exactly one common phishing link                                                                          |
| `#oneembeddedlink`             | Email contains exactly one embedded link                                                                                 |
| `#onesuspiciouslink`           | Email contains exactly one suspicious link                                                                               |
| `#shortened`                   | Shortened link was found                                                                                                 |
| `#shortenednolocalreputation`  | Shortened link resolves to domain with no local reputation                                                               |
| `#shortenednoreputation`       | Shortened link resolves to domain with no local and no global reputation                                                 |
| `#similar`                     | One of the XsY (*X is similar to Y*) similarity tags matched                                                             |
| `#subdomainproviderwithnolrep` | Found a link without local reputation that is below a subdomain provider                                                 |
| `#suspiciousidn`               | A domain with a suspicious IDN character was found                                                                       |
| `#tldnoreputation`             | TLD has no reputation                                                                                                    |
| `#veryyoungdomain`             | A very young domain was found (younger than 30 days)                                                                     |
| `#youngdomain`                 | A young domain was found (younger than 365 days)                                                                         |

### Dynamic analysis

| Tag                 | Description                                                                           |
| ------------------- | ------------------------------------------------------------------------------------- |
| `#cfiviolation`     | Control-flow integrity violation during dynamic analysis encountered                  |
| `#dana`             | Dynamic analysis of a file performed                                                  |
| `#exploit`          | Exploit found                                                                         |
| `#inline`           | Dynamic analysis is performed inline **(deprecated since 6.21)**                      |
| `#ipaddress`        | Dynamic analysis observed a direct IP connection                                      |
| `#networkactivity`  | Suspicious network activity observed during dynamic analysis                          |
| `#offline`          | Dynamic analysis is performed offline **(deprecated since 6.21)**                     |
| `#runtime`          | A suspicious activity during dynamic analysis was observed                            |
| `#spawnsprocess`    | A suspicious process is spawned during dynamic analysis (from the client application) |
| `#systemfileio`     | Suspicious file IO operation observed during dynamic analysis                         |
| `#systemprocess`    | A suspicious system process is spawned during dynamic analysis                        |
| `#systemregistryio` | Suspicious registry IO operation observed during dynamic analysis                     |

### Relationship tags

Relationship tags describe the quality of the relationship between your organization and the sending organization (or the receiving organization for outgoing emails). Tag assignment can be influenced by configuring the corresponding thresholds.

| Tag                 | Description                                                                                                                                                      |
| ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `#business`         | The sender-recipient relationship has some significance but is yet too shallow to be considered trusted                                                          |
| `#hightrusted`      | The sender-recipient relationship is considered highly trusted                                                                                                   |
| `#lowtrusted`       | The sender-recipient relationship is considered slightly trusted                                                                                                 |
| `#mediumtrusted`    | The sender-recipient relationship is considered medium trusted                                                                                                   |
| `#nonreputable`     | The domain the email was sent from has no significance in your organization. See also `#reputable`                                                               |
| `#partner`          | The organization, which the sender is a member of, is considered a partner of your organization. Relationships with partner organizations score high on trust    |
| `#personal`         | The sender-recipient relationship is personal                                                                                                                    |
| `#recipientpartner` | The organization, which the recipient is a member of, is considered a partner of your organization. Relationships with partner organizations score high on trust |
| `#reputable`        | The sending domain has a certain significance in your organization. See also `#nonreputable`                                                                     |
| `#trusted`          | The sender-recipient relationship is considered trusted                                                                                                          |
| `#untrusted`        | The sender-recipient relationship is not considered trusted                                                                                                      |

### Sender-specific tags

| Tag                                                                            | Description                                                                                                                                                                                   |
| ------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `#15daysoldsender`                                                             | The sender domain was registered in the last 15 days                                                                                                                                          |
| `#180daysoldsender`                                                            | The sender domain was registered in the last 180 days                                                                                                                                         |
| `#1dayoldsender`                                                               | The sender domain was registered today                                                                                                                                                        |
| `#30daysoldsender`                                                             | The sender domain was registered in the last 30 days                                                                                                                                          |
| `#365daysoldsender`                                                            | The sender domain was registered in the last 365 days                                                                                                                                         |
| `#3rdpartycloudmailer`                                                         | The mail is sent via a 3rd party cloud mailer                                                                                                                                                 |
| `#5daysoldsender`                                                              | The sender domain was registered in the last 5 days                                                                                                                                           |
| `#90daysoldsender`                                                             | The sender domain was registered in the last 90 days                                                                                                                                          |
| `#addressindisplayname`                                                        | The display name of the email contains an email address                                                                                                                                       |
| `#addressparsingerror`                                                         | An error occurred during address parsing. Indicates an uncommon address format                                                                                                                |
| `#airlockwhitelisted`                                                          | The sender is on the Attachment Airlock whitelist                                                                                                                                             |
| `#arcreject`                                                                   | Authenticated Received Chain (ARC) checks failed                                                                                                                                              |
| `#auth`                                                                        | Email sender is authenticated                                                                                                                                                                 |
| `#autogenerated`                                                               | The email is auto generated, e.g., by a script                                                                                                                                                |
| `#bcconly`                                                                     | No guarded email recipients in `TO/CC`                                                                                                                                                        |
| `#blacklisted`                                                                 | A blacklisted object was found. This can be the sender, a file type, domain or any other object that can be blacklisted                                                                       |
| `#bulk`                                                                        | Sender seems to be a bulk email sender or we have seen a lot of incoming and no outgoing emails to that sender for some time now                                                              |
| `#business`                                                                    | The sender and recipient have a business relationship                                                                                                                                         |
| `#cloudmailer`                                                                 | The sender is a known cloud service for sending emails                                                                                                                                        |
| `#cloudmailerrcvdonly`                                                         | The sender is a known cloud service for sending emails, based on information found in the `received` headers                                                                                  |
| `#cloudstoragesender`                                                          | Sender is a cloud storage service                                                                                                                                                             |
| `#contactform`                                                                 | Sender is a contact form                                                                                                                                                                      |
| `#contains`                                                                    | One or more XcY tags (*X contains Y*) are present like `#displaynamecguarded`                                                                                                                 |
| `#displaynamecemoji`                                                           | Displayname contains an emoji                                                                                                                                                                 |
| `#displaynamecguarded`                                                         | Displayname contains (fuzzy matches) a guarded name, i.e., the organization’s name                                                                                                            |
| `#displaynameckeyword`                                                         | Displayname contains (fuzzy matches) a phishing keyword                                                                                                                                       |
| `#displaynamecpartner`                                                         | Displayname contains (fuzzy matches) a partner organization’s name                                                                                                                            |
| `#displaynamecpopular`                                                         | Displayname contains (fuzzy matches) a popular service name                                                                                                                                   |
| `#displaynamecvip`                                                             | Displayname contains (fuzzy matches) a VIP's name                                                                                                                                             |
| `#displaynamemguarded`                                                         | Displayname exactly matches the organization’s name                                                                                                                                           |
| `#displaynamemkeyword`                                                         | Displayname exactly matches at least one phishing keyword                                                                                                                                     |
| `#displaynamempartner`                                                         | Displayname exactly matches at least one partner name                                                                                                                                         |
| `#displaynamempopular`                                                         | Displayname exactly matches at least one popular service                                                                                                                                      |
| `#displaynamestguarded`                                                        | Displayname is similar to the organization’s name                                                                                                                                             |
| `#displaynamestkeyword`                                                        | Displayname is similar to a phishing keyword                                                                                                                                                  |
| `#displaynamestpartner`                                                        | Displayname is similar to a partner’s name                                                                                                                                                    |
| `#displaynamestpopular`                                                        | Displayname is similar to a popular service                                                                                                                                                   |
| `#displaynamestvip`                                                            | Displayname is similar to a VIP’s name                                                                                                                                                        |
| `#domainfirstcontact`                                                          | Sending domain first time seen                                                                                                                                                                |
| `#domainnodeliver`                                                             | No email was ever delivered from the sending domain                                                                                                                                           |
| `#domainonlyinbound`                                                           | Domain only sends inbound emails                                                                                                                                                              |
| `#dkimfromsigned`                                                              | The `from` field is DKIM signed                                                                                                                                                               |
| `#dkiminvalid`                                                                 | No DKIM verification succeeded and the found DKIM signature is invalid                                                                                                                        |
| `#dkimfail`, `#dkimneutral`, `#dkimpolicy`, `#dkimpermerror`, `#dkimtemperror` | No DKIM verification succeeded and one of the results `fail`, `neutral`, `policy`, `permerror`, or `temperror` was found                                                                      |
| `#dynamicrelay`                                                                | One of the MTAs in the headers has a dynamic IP address                                                                                                                                       |
| `#educationsender`                                                             | The sender’s email address is from an education domain                                                                                                                                        |
| `#etrust`                                                                      | Sender is in extended trust circle. The extended trust circle contains all domains which locally have a high reputation. xorlab Security Platform learns this based on the observed mail flow |
| `#fake`                                                                        | Email address seems fake (in `displayname`)                                                                                                                                                   |
| `#fakeguarded`                                                                 | Guarded email is faked                                                                                                                                                                        |
| `#fakepartner`                                                                 | Partner email is faked                                                                                                                                                                        |
| `#fakepopular`                                                                 | Popular email is faked                                                                                                                                                                        |
| `#fakereply`                                                                   | Email is a faked reply                                                                                                                                                                        |
| `#forged`                                                                      | Email sender is forged                                                                                                                                                                        |
| `#forgedfreemail`                                                              | Forged freemail                                                                                                                                                                               |
| `#forgedguarded`                                                               | Forged guarded email                                                                                                                                                                          |
| `#forgedpartner`                                                               | Forged partner email                                                                                                                                                                          |
| `#forgedpopular`                                                               | Forged popular email                                                                                                                                                                          |
| `#freemail`                                                                    | Freemail sender                                                                                                                                                                               |
| `#freemailforgedreplyto`                                                       | Freemail address in `reply to` found (but not in `from`)                                                                                                                                      |
| `#fromsdiffer`                                                                 | Envelope `from` and header `from` differ                                                                                                                                                      |
| `#mailerdaemon`                                                                | Email comes from a mailer daemon address                                                                                                                                                      |
| `#mailinglist`                                                                 | Sender seems a mailing list                                                                                                                                                                   |
| `#marketing`                                                                   | Marketing email                                                                                                                                                                               |
| `#matches`                                                                     | One of the XmY (*X matches Y*) rules matched, i.e., the organization’s name or a keyword, etc., matched a relevant string                                                                     |
| `#mtaauth`                                                                     | MTA is whitelisted                                                                                                                                                                            |
| `#mtawlhigh`                                                                   | Sending MTA is on highly reputable whitelist (high)                                                                                                                                           |
| `#mtawlmedium`                                                                 | Sending MTA is on reputable whitelist (medium)                                                                                                                                                |
| `#newsender`                                                                   | Never seen before sender (same as `#senderfirstcontact`)                                                                                                                                      |
| `#newsendertld`                                                                | Never seen before sender TLD found                                                                                                                                                            |
| `#newsletter`                                                                  | Email seems to be a newsletter                                                                                                                                                                |
| `#noauth`                                                                      | Email sender is not authentic                                                                                                                                                                 |
| `#nonreputable`                                                                | Email sender domain is non-reputable                                                                                                                                                          |
| `#otrust`                                                                      | Sender has organizational trust                                                                                                                                                               |
| `#partner`                                                                     | Sender is a partner (at least the domain)                                                                                                                                                     |
| `#partnerwithoutauth`                                                          | Sender is a partner but has no authentication (might be forged or the email setup does not allow for authentication)                                                                          |
| `#personal`                                                                    | Email seems to be a personal email                                                                                                                                                            |
| `#phpsender`                                                                   | Sender seems a PHP script                                                                                                                                                                     |
| `#poll`                                                                        | Email comes from an online poll service (e.g., Doodle)                                                                                                                                        |
| `#popular`                                                                     | Sender seems to be a popular service                                                                                                                                                          |
| `#postmaster`                                                                  | Email comes from a postmaster address                                                                                                                                                         |
| `#predatorypublisher`                                                          | Sender is a predatory publishing/journal sender; usually indicating academic scam                                                                                                             |
| `#ptrust`                                                                      | Sender has personal trust                                                                                                                                                                     |
| `#replytonotfrom`                                                              | `Reply-To` domain does not match `From` domain                                                                                                                                                |
| `#reputable`                                                                   | Sender domain is reputable                                                                                                                                                                    |
| `#senderblacklisted`                                                           | Sender is blacklisted                                                                                                                                                                         |
| `#senderblacklistedexternal`                                                   | Sender is blacklisted based on an external blacklist                                                                                                                                          |
| `#sendercguarded`                                                              | Sender mail address contains the organization’s name                                                                                                                                          |
| `#senderckeyword`                                                              | Sender mail address exactly matches at least one phishing keyword                                                                                                                             |
| `#sendercpartner`                                                              | Sender mail address contains a partner’s name                                                                                                                                                 |
| `#sendercpopular`                                                              | Sender mail address contains a popular service’s name                                                                                                                                         |
| `#senderfirstcontact`                                                          | Sender first time seen                                                                                                                                                                        |
| `#senderhascctld`                                                              | Sender’s TLD is a country code TLD                                                                                                                                                            |
| `#sendernodeliver`                                                             | No email from the sender was delivered before                                                                                                                                                 |
| `#senderneverbenign`                                                           | Sender’s domain was never seen as sender or recipient in a delivered email—except for freemail, where the sender email address was never seen as a sender or recipient                        |
| `#senderonlyinbound`                                                           | Sender only seen in inbound emails                                                                                                                                                            |
| `#senderseenasrecipient`                                                       | Sender’s email address was previously seen as a recipient                                                                                                                                     |
| `#senderseenbefore`                                                            | Sender’s email address was previously seen as a sender                                                                                                                                        |
| `#senderstguarded`                                                             | Sender’s mail address is similar to the organization’s name                                                                                                                                   |
| `#senderstpartner`                                                             | Sender’s mail address is similar to a partner’s name                                                                                                                                          |
| `#senderstpopular`                                                             | Sender’s mail address is similar to a popular service’s name                                                                                                                                  |
| `#sendersuspicious`                                                            | Sender’s MTA is suspicious due to its reputation and past behavior                                                                                                                            |
| `#sendertldnoreputation`                                                       | Sender’s TLD has no reputation                                                                                                                                                                |
| `#senderwhitelisted`                                                           | Sender is whitelisted                                                                                                                                                                         |
| `#similar`                                                                     | One of the XsY (*X is similar to Y*) similarity tags matched                                                                                                                                  |
| `#socialnetwork`                                                               | Email comes from a social network (e.g., Facebook, LinkedIn, etc.)                                                                                                                            |
| `#spfehlofail`                                                                 | SPF EHLO fail                                                                                                                                                                                 |
| `#spfehlosoftfail`                                                             | SPF EHLO soft fail                                                                                                                                                                            |
| `#spffail`                                                                     | SPF fail                                                                                                                                                                                      |
| `#spfneutral`                                                                  | SPF result neutral                                                                                                                                                                            |
| `#spfnone`                                                                     | No SPF record found                                                                                                                                                                           |
| `#spfpass`                                                                     | SPF check passed                                                                                                                                                                              |
| `#spfpermerror`                                                                | SPF permanent error                                                                                                                                                                           |
| `#spfsoftfail`                                                                 | SPF soft fail                                                                                                                                                                                 |
| `#spftemperror`                                                                | SPF temp error                                                                                                                                                                                |
| `#trusted`                                                                     | Sender is trusted                                                                                                                                                                             |
| `#trustedmta`                                                                  | MTA is trusted                                                                                                                                                                                |
| `#trustednoauth`                                                               | Sender domain would be trusted but this mail is not authenticated. Either a trusted sender’s email setup is wrong or the sender is impersonating a trusted party                              |
| `#trustoverride`                                                               | The trust relationship was overwritten on purpose. This has to be done by configuration and allows to lower e.g., the trust level of a partner manually                                       |
| `#untrusted`                                                                   | Sender is not trusted (or trust score is very low)                                                                                                                                            |
| `#veryyoungsender`                                                             | Sender is very young (younger than 30 days)                                                                                                                                                   |
| `#whitelisted`                                                                 | A whitelisted object was found. This can be the sender, a file type or file itself, domain, or any other object that can be whitelisted                                                       |
| `#wwwdata`                                                                     | Sender is a webserver                                                                                                                                                                         |
| `#xorlab`                                                                      | This mail is part of a breach simulation by xorlab                                                                                                                                            |
| `#youngsender`                                                                 | Sender domain is young (younger than 365 days)                                                                                                                                                |

### Recipient-specific tags

| Tag                         | Description                                                                                                                                                                                                       |
| --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `#educationrcpt`            | The recipient’s email address is from an education domain                                                                                                                                                         |
| `#exposedaccount`           | The recipient is listed as an exposed account. Examples for exposed accounts are `contact@yourcompany.com`, `media@yourcompany.com`, or any other email address listed on your website or public sources          |
| `#exposedhvt`               | The recipient is considered a high-value target. Examples for high-value targets are members of the finance department or the Executive Assistant of your CEO                                                     |
| `#exposedpubliccontact`     | The recipient is listed as an exposed public contact and should be subject to less aggressive filtering. This can be useful for certain public mailboxes where you expect a lot of suspicious or malformed emails |
| `#freemailrcpt`             | Freemail recipient                                                                                                                                                                                                |
| `#recipientdisplaynamecvip` | A recipient’s displayname contains (fuzzy matches) a VIP’s name.                                                                                                                                                  |
| `#recipientdropped`         | Email dropped because all guarded recipients are on a drop list                                                                                                                                                   |
| `#recipientpartner`         | Recipient is a partner organization                                                                                                                                                                               |
| `#recipientwhitelisted`     | Recipient is whitelisted                                                                                                                                                                                          |

<Note>
  The following tags are only available on outgoing emails.
</Note>

| Tag                    | Description                                                                                                                                        |
| ---------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
| `#rcptunknown`         | The recipient of an outgoing email is unknown to the organization (meaning that the recipient does not appear in the organization’s email history) |
| `#rcptunknowntosender` | The recipient of an outgoing email is unknown to the sender (meaning that the recipient does not appear in the sender’s email history)             |

### Mail flow tags

Mail flow tags indicate if an email was sent or received by your organization, exchanged internally, or processed on behalf of a third party. Please see *[Search](/9.0/search#direction)*.

| Tag          | Description                                                                                                                                                                                                          |
| ------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `#ext`       | Neither the sender nor the recipient is a member of your organization. This can happen if you process emails on behalf of a third party, e.g., by hosting a third-party service. Not to be confused with `#external` |
| `#inc`       | The email was sent by an external party to your organization                                                                                                                                                         |
| `#int`       | The email was sent by a member of your organization to one or more members of your organization. Not to be confused with `#internal`                                                                                 |
| `#out`       | The email was sent by a member of your organization to an external party                                                                                                                                             |
| `#forwarded` | The email was forwarded internally by a member of your organization                                                                                                                                                  |

### Decision tags

Decision tags indicate if an email was delivered, sanitized, or quarantined after processing.

| Tag                      | Description                                                                                                          |
| ------------------------ | -------------------------------------------------------------------------------------------------------------------- |
| `#attachmenttransformed` | An attachment was removed or replaced before delivery                                                                |
| `#deliver`               | The email was delivered to its recipients                                                                            |
| `#quarantine`            | The email was quarantined<br />**Note that this tag can’t be used in campaigns**                                     |
| `#subjectrewrite`        | The email was delivered with a subject prefix, e.g., `[SPAM]`<br />**Note that this tag can’t be used in campaigns** |

## Risk scores

### Overall risk

| Tag            | Description                               |
| -------------- | ----------------------------------------- |
| `#highrisk`    | The email has a high overall risk score   |
| `#mediumrisk`  | The email has a medium overall risk score |
| `#lowrisk`     | The email has a low overall risk score    |
| `#verylowrisk` | Overall risk score is very low            |

### Phishing risk

| Tag        | Description                                |
| ---------- | ------------------------------------------ |
| `#vhprisk` | The phishing risk score is very high       |
| `#hprisk`  | The email has a high phishing risk score   |
| `#mprisk`  | The email has a medium phishing risk score |
| `#lprisk`  | The email has a low phishing risk score    |

### Spam risk

| Tag       | Description                            |
| --------- | -------------------------------------- |
| `#hsrisk` | The email has a high spam risk score   |
| `#msrisk` | The email has a medium spam risk score |
| `#lsrisk` | The email has a low spam risk score    |

The spam risk of an email is influenced by a variety of factors. Two of them are the scores calculated by *SpamAssassin* and *Rspamd*. The following tags describe them:

| Tag               | Description                                                                                              |
| ----------------- | -------------------------------------------------------------------------------------------------------- |
| `#highscore`      | SpamAssassin calculated a high spam score. The higher the score, the more likely the email is spam       |
| `#mediumscore`    | SpamAssassin calculated a medium spam score                                                              |
| `#lowscore`       | SpamAssassin calculated a low overall spam score. The lower the score, the less likely the email is spam |
| `#negscore`       | SpamAssassin calculated a negative spam score. The lower the score, the less likely the email is spam    |
| `#missingscore`   | The spam score is missing. This indicates a problem with spam analysis                                   |
| `#hbayes`         | Bayes spam probability is high                                                                           |
| `#mbayes`         | Bayes spam probability is medium                                                                         |
| `#lbayes`         | Bayes spam probability is low                                                                            |
| `#rspamd`         | Rspamd classified the email as spam                                                                      |
| `#rsdhighscore`   | Rspamd calculated a high spam score. The higher the score, the more likely the email is spam             |
| `#rsdmediumscore` | Rspamd calculated a medium spam score                                                                    |
| `#rsdlowscore`    | Rspamd calculated a low spam score. The lower the score, the less likely the email is spam               |
| `#rsdnegscore`    | Rspamd calculated a negative spam score                                                                  |

## User reports

| Tag                | Description                                                                             |
| ------------------ | --------------------------------------------------------------------------------------- |
| `#acksent`         | The reporting user received an acknowledgement                                          |
| `#analystfeedback` | The analyst is required to provide the user with a feedback                             |
| `#autofeedback`    | The reporting user received an automatically generated feedback                         |
| `#feedback`        | The email is an automatically generated email originating from xorlab Security Platform |
| `#highpriority`    | The reported email is a high priority incident                                          |
| `#lowpriority`     | The reported email is a low priority incident                                           |
| `#mediumpriority`  | The reported email is a medium priority incident                                        |
| `#reported`        | The email was reported by a user                                                        |
| `#fileanalysis`    | The file was submitted for analysis with the File Upload tool                           |
| `#simulation`      | The email is part of a simulated security awareness campaign                            |

## Reporting Misclassification

| Tag              | Description                                           |
| ---------------- | ----------------------------------------------------- |
| `#misclassified` | The message or case was reported as misclassification |
